首页> 外文会议>Annual CHI conference on human factors in computing systems >Of Passwords and People: Measuring the Effect of Password-Composition Policies
【24h】

Of Passwords and People: Measuring the Effect of Password-Composition Policies

机译:密码和人员:评估密码组成策略的效果

获取原文

摘要

Text-based passwords are the most common mechanism for authenticating humans to computer systems. To prevent users from picking passwords that are too easy for an adversary to guess, system administrators adopt password-composition policies (e.g., requiring passwords to contain symbols and numbers). Unfortunately, little is known about the relationship between password-composition policies and the strength of the resulting passwords, or about the behavior of users (e.g., writing down passwords) in response to different policies. We present a large-scale study that investigates password strength, user behavior, and user sentiment across four password-composition policies. We characterize the predictability of passwords by calculating their entropy, and find that a number of commonly held beliefs about password composition and strength are inaccurate. We correlate our results with user behavior and sentiment to produce several recommendations for password-composition policies that result in strong passwords without unduly burdening users.
机译:基于文本的密码是用于向计算机系统验证人员身份的最常见机制。为了防止用户选择对手难以猜到的密码,系统管理员采用了密码组成策略(例如,要求密码包含符号和数字)。不幸的是,关于密码组成策略与所得到的密码的强度之间的关系,或者对于用户响应不同策略的行为(例如,写下密码)知之甚少。我们提出了一项大规模研究,研究了四种密码组成策略中的密码强度,用户行为和用户情感。我们通过计算密码的熵来表征密码的可预测性,并发现许多关于密码组成和强度的普遍信念是不正确的。我们将结果与用户行为和情感相关联,以针对密码组成策略提出一些建议,这些建议可在不给用户造成过多负担的情况下提供强大的密码。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号