English
Related papers

Related papers: Prospects for Improving Password Selection

200 papers

A central challenge in password security is to characterize the attacker's guessing curve i.e., what is the probability that the attacker will crack a random user's password within the first $G$ guesses. A key challenge is that the guessing…

Cryptography and Security · Computer Science 2022-09-22 Jeremiah Blocki , Peiyuan Liu

Leaks from password datasets are a regular occurrence. An organization may defend a leak with reassurances that just a small subset of passwords were taken. In this paper we show that the leak of a relatively small number of text-based…

Cryptography and Security · Computer Science 2021-03-29 Hazel Murray , David Malone

Risk-based authentication (RBA) aims to protect users against attacks involving stolen passwords. RBA monitors features during login, and requests re-authentication when feature values widely differ from previously observed ones. It is…

Cryptography and Security · Computer Science 2022-11-11 Stephan Wiefling , Paul René Jørgensen , Sigurd Thunem , Luigi Lo Iacono

We develop an economic model of an offline password cracker which allows us to make quantitative predictions about the fraction of accounts that a rational password attacker would crack in the event of an authentication server breach. We…

Cryptography and Security · Computer Science 2020-06-11 Jeremiah Blocki , Ben Harsha , Samson Zhou

Leaked passwords from data breaches can pose a serious threat to users if the password is reused elsewhere. With more online services getting breached today, there is still a lack of large-scale quantitative understanding of the risks of…

Cryptography and Security · Computer Science 2017-06-09 Chun Wang , Steve T. K. Jan , Hang Hu , Gang Wang

Probabilistic password strength meters have been proved to be the most accurate tools to measure password strength. Unfortunately, by construction, they are limited to solely produce an opaque security estimation that fails to fully support…

Cryptography and Security · Computer Science 2021-05-13 Dario Pasquini , Giuseppe Ateniese , Massimo Bernaschi

Single-factor password-based authentication is generally the norm to access on-line Web-sites. While single-factor authentication is well known to be a weak form of authentication, a further concern arises when considering the possibility…

Cryptography and Security · Computer Science 2020-01-30 Simone Raponi , Roberto Di Pietro

It is critical to understand and model the behavior of individuals in a pandemic, as well as identify effective ways to guide people's behavior in order to better control the epidemic spread. However, current research fails to account for…

Social and Information Networks · Computer Science 2023-09-01 Wenxiang Dong , H. Vicky Zhao

Users often make security- and privacy-relevant decisions without a clear understanding of the rules that govern safe behavior. We introduce pedagogical friction, a design approach that inserts brief, instructional interactions at the…

Human-Computer Interaction · Computer Science 2026-04-08 Qian Ma , Yingfan Zhou , Shubhang Kaushik , Aamod Joshi , Aditya Majumdar , Noah Apthorpe , Yan Shvartzshnaider , Sarah Rajtmajer , Brett Frischmann

Vulnerabilities related to weak passwords are a pressing global economic and security issue. We report a novel, simple, and effective approach to address the weak password problem. Building upon chaotic dynamics, criticality at phase…

Cryptography and Security · Computer Science 2015-05-27 T. V. Laptyeva , S. Flach , K. Kladko

We introduce the concept of "universal password model" -- a password model that, once pre-trained, can automatically adapt its guessing strategy based on the target system. To achieve this, the model does not need to access any plaintext…

Cryptography and Security · Computer Science 2024-03-14 Dario Pasquini , Giuseppe Ateniese , Carmela Troncoso

Some protected password change protocols were proposed. However, the previous protocols were easily vulnerable to several attacks such as denial of service, password guessing, stolen-verifier and impersonation atacks etc. Recently, Chang et…

Cryptography and Security · Computer Science 2007-05-23 Ren-Chiun Wang , Chou-Chen Yang , Kun-Ru Mo

Password authentication is a common approach to the system security and it is also a very important procedure to gain access to user resources. In the conventional password authentication methods a server has to authenticate the legitimate…

Cryptography and Security · Computer Science 2011-10-10 ASN Chakravarthy , Prof. P S Avadhani

Phishing remains one of the most pervasive cybersecurity threats, shifting the focus from technological vulnerabilities to human cognitive and psychological factors. In coherence with the trend of studies on phishing to increasingly focus…

Cryptography and Security · Computer Science 2026-05-21 Valeria Formisano , Danilo Gentile , Gennaro Esposito Mocerino , Michela Ponticorvo , Luigi Gallo , Alessio Botta , Davide Marocco

Security properties are often focused on the technological side of the system. One implicitly assumes that the users will behave in the right way to preserve the property at hand. In real life, this cannot be taken for granted. In…

Multiagent Systems · Computer Science 2023-10-19 Wojciech Jamroga , Damian Kurpiewski , Vadim Malvone

Password managers (PMs) are considered highly effective tools for increasing security, and a recent study by Pearman et al. (SOUPS'19) highlighted the motivations and barriers to adopting PMs. We expand these findings by replicating Pearman…

Cryptography and Security · Computer Science 2020-10-06 Hirak Ray , Flynn Wolf , Ravi Kuber , Adam J. Aviv

Password managers are important tools that enable us to use stronger passwords, freeing us from the cognitive burden of remembering them. Despite this, there are still many users who do not fully trust password managers. In this paper, we…

Cryptography and Security · Computer Science 2021-06-22 Miguel Grilo , João F. Ferreira , José Bacelar Almeida

Protecting against cyber-threats is vital for every organization and can be done by investing in cybersecurity controls and purchasing cyber insurance. However, these are interlinked since insurance premiums could be reduced by investing…

Econometrics · Economics 2024-12-02 Chaitanya Joshi , Jinming Yang , Sergeja Slapnicar , Ryan K L Ko

Given the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. System-assigned passwords provide measurable security but suffer from poor memorability. To…

Human-Computer Interaction · Computer Science 2015-03-10 Mahdi Nasrullah Al-Ameen , Matthew Wright , Shannon Scielzo

Passwords, a first line of defense against unauthorized access, must be secure and memorable. However, people often struggle to create secure passwords they can recall. To address this problem, we design Password inspiration by eXploring…

Cryptography and Security · Computer Science 2025-05-01 Shengqian Wang , Amirali Salehi-Abari , Julie Thorpe