Back to Search Start Over

Do Differences in Password Policies Prevent Password Reuse?

Authors :
Tobias Seitz
Samuel Souque
Manuel Hartmann
Jakob Pfab
Source :
CHI Extended Abstracts
Publication Year :
2017
Publisher :
ACM, 2017.

Abstract

Password policies were originally designed to make users pick stronger passwords. However, research has shown that they often fail to achieve this goal. In a systematic audit of the top 100 web sites in Germany, we explore if diversity in current real-world password policies prevents password reuse. We found that this is not the case: we are the first to show that a single password could hypothetically fulfill 99% of the policies under consideration. This is especially problematic because password reuse exposes users to similar risks as weak passwords. We thus propose a new approach for policies that focuses on password reuse and respects other websites to determine if a password should be accepted. This re-design takes current user behavior into account and potentially boosts the usability and security of password-based authentication.

Details

Database :
OpenAIRE
Journal :
Proceedings of the 2017 CHI Conference Extended Abstracts on Human Factors in Computing Systems
Accession number :
edsair.doi...........0526f4db7745b68271db4c32d005ff5a