Password Strength Meters using Social Influence

نویسندگان

  • Takahiro Ohyama
  • Akira Kanaoka
چکیده

Millions of people now use password strength meter when the user starts to sign up a service. The impact on password strength meter has been evaluated for several aspects. However, it is believed that there are still ways to design more e ective password strength meters. Recently, Das et al shows that social in uence or social proof is e ective to adopt security features[1, 2, 3]. It seems that social in uence is also e ective for password strength meters. Actually, Egelman, et al partially shows its e ectiveness[4]. In this poster, we prepare ve types of password strength meters using social in uence and evaluate them. First one is bar-type password strength meters, which has 2 meters on screen showing user's password strength and similar users' score (Fig. 2). In this case, similar means users who have same attributes like age, job, etc. Second one is also bartype similar to First one. It has 2 meters on screen showing user's password strength and the average score of all users (Fig. 3). Third one shows score itself, which 2 values on screen showing the user's score and similar users' score (Fig. 4). Fourth one shows icons on bar-type meter. A running man shows the user's score and a ag shows similar users' score (Fig. 5). Fifth one is tachometer showing the user's score by a hand and area of similar users' score by dashed line (Fig. 6). We conduct user study to measure e ectiveness of proposed meters by using Japanese crowdsourcing service Lancers, which is a similar service to Amazon Mechanical Turk. 100 users are attended to each study. Totally 700 users are attended. 50 Japanese yen has been paid for a task. This user study is conducted from Dec. 30th, 2014 to Jan. 29th, 2015. We did not gather plain password itself, but score calculated by Javascript in the user's browser, length of password, number of digits in the password, number of upper cases in the password, number of lower cases in the password and number of symbols in the password. Table 1 shows the average score on each meter. The score is calculated using the way of scoring on Ur's paper [5]. Table 2 shows the construction of passwords on each meter. Table 3 shows P-value which is result of Kruscal-Wallis testing between basic password strength meter and each proposed meter. The results show stronger social in uence re ects stronger password strength.

برای دانلود رایگان متن کامل این مقاله و بیش از 32 میلیون مقاله دیگر ابتدا ثبت نام کنید

ثبت نام

اگر عضو سایت هستید لطفا وارد حساب کاربری خود شوید

منابع مشابه

Adaptive Password-Strength Meters from Markov Models

Measuring the strength of passwords is crucial to ensure the security of password-based authentication. However, current methods to measure password strength have limited accuracy, first, because they use rules that are too simple to capture the complexity of passwords, and second, because password frequencies widely differ from one application to another. In this paper, we present the concept ...

متن کامل

From Very Weak to Very Strong: Analyzing Password-Strength Meters

Millions of users are exposed to password-strength meters/checkers at highly popular web services that use userchosen passwords for authentication. Recent studies have found evidence that some meters actually guide users to choose better passwords—which is a rare bit of good news in password research. However, these meters are mostly based on ad-hoc design. At least, as we found, most vendors d...

متن کامل

How Does Your Password Measure Up? The Effect of Strength Meters on Password Creation

To help users create stronger text-based passwords, many web sites have deployed password meters that provide visual feedback on password strength. Although these meters are in wide use, their effects on the security and usability of passwords have not been well studied. We present a 2,931-subject study of password creation in the presence of 14 password meters. We found that meters with a vari...

متن کامل

A A Large-Scale Evaluation of High-Impact Password Strength Meters

Passwords are ubiquitous in our daily digital lives. They protect various types of assets ranging from a simple account on an online newspaper website to our health information on government websites. However, due to the inherent value they protect, attackers have developed insights into cracking/guessing passwords both offline and online. In many cases, users are forced to choose stronger pass...

متن کامل

Personalizing Password Policies and Strength Feedback

To make users pick stronger passwords, service providers utilize password policies and password creation feedback while the user types inside password fields. Those two techniques often fail to achieve this primary goal. In this position paper, we argue that a personalized version of polices and strength meters are worth investigating. Putting individuals into the center of attention rather tha...

متن کامل

ذخیره در منابع من


  با ذخیره ی این منبع در منابع من، دسترسی به آن را برای استفاده های بعدی آسان تر کنید

عنوان ژورنال:

دوره   شماره 

صفحات  -

تاریخ انتشار 2015