Passwords remain as a widespread authentication mechanism for online services. Users are required to adopt complex and unique passwords. Since human memory is limited, it is important to adapt the password complexity to the severity of an eventual account compromise. To the best of authors’ knowledge, this has not been addressed yet. Indeed, our analysis of 352M passwords from 25 online services reveals that users do not consider the service at stake. This paper proposes a service-aware password risk model and a meter that consider user-, password- and service-related features. It aims to (1) make users aware of the risk associated with their account compromise depending on the service features and (2) encourage them to choose passwords with appropriate robustness. Our approach is assessed by 31 cybersecurity experts and 284 regular users, confirming the effectiveness of the metric and its usefulness for the users.

错误:搜索内容不能为空,请输入英文关键词
错误:关键词超出字数限制,请精简
高级检索

Service-Aware Password Risk Meter – Helping Users to Choose Suitable Passwords in Services

  • Roi S. Serna,
  • Ana I. González-Tablas,
  • Lorena González-Manzano,
  • Jose María de Fuentes

摘要

Passwords remain as a widespread authentication mechanism for online services. Users are required to adopt complex and unique passwords. Since human memory is limited, it is important to adapt the password complexity to the severity of an eventual account compromise. To the best of authors’ knowledge, this has not been addressed yet. Indeed, our analysis of 352M passwords from 25 online services reveals that users do not consider the service at stake. This paper proposes a service-aware password risk model and a meter that consider user-, password- and service-related features. It aims to (1) make users aware of the risk associated with their account compromise depending on the service features and (2) encourage them to choose passwords with appropriate robustness. Our approach is assessed by 31 cybersecurity experts and 284 regular users, confirming the effectiveness of the metric and its usefulness for the users.