Back to Search
Start Over
Do Differences in Password Policies Prevent Password Reuse?
- Source :
- CHI Extended Abstracts
- Publication Year :
- 2017
- Publisher :
- ACM, 2017.
-
Abstract
- Password policies were originally designed to make users pick stronger passwords. However, research has shown that they often fail to achieve this goal. In a systematic audit of the top 100 web sites in Germany, we explore if diversity in current real-world password policies prevents password reuse. We found that this is not the case: we are the first to show that a single password could hypothetically fulfill 99% of the policies under consideration. This is especially problematic because password reuse exposes users to similar risks as weak passwords. We thus propose a new approach for policies that focuses on password reuse and respects other websites to determine if a password should be accepted. This re-design takes current user behavior into account and potentially boosts the usability and security of password-based authentication.
- Subjects :
- Zero-knowledge password proof
Software_OPERATINGSYSTEMS
Computer science
Internet privacy
02 engineering and technology
Computer security
computer.software_genre
One-time password
S/KEY
Password strength
020204 information systems
0202 electrical engineering, electronic engineering, information engineering
Key stretching
0501 psychology and cognitive sciences
Password psychology
050107 human factors
Password
Authentication
Password policy
Cognitive password
business.industry
05 social sciences
Passphrase
ComputingMilieux_MANAGEMENTOFCOMPUTINGANDINFORMATIONSYSTEMS
Challenge–response authentication
business
computer
Subjects
Details
- Database :
- OpenAIRE
- Journal :
- Proceedings of the 2017 CHI Conference Extended Abstracts on Human Factors in Computing Systems
- Accession number :
- edsair.doi...........0526f4db7745b68271db4c32d005ff5a