TeamUSEC

Better managed than memorized? Studying the Impact of Managers on Password Strength and Reuse

Sanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes and Sven Bugiel.
27th USENIX Security Symposium, USENIX Security 2018, Baltimore, MD, USA, August 15-17, 2018
PDF Abstract Cite URL

Abstract

Despite their well-known security problems, passwords are still the incumbent authentication method for virtually all online services. To remedy the situation, users are very often referred to password managers as a solution to the password reuse and weakness problems. However, to date the actual impact of password managers on password strength and reuse has not been studied systematically.

We provide the first large-scale study of the password managers’ influence on users’ real-life passwords. By combining qualitative data on users’ password creation and management strategies, collected from 476 participants of an online survey, with quantitative data (incl. password metrics and entry methods) collected in situ with a browser plugin from 170 users, we were able to gain a more complete picture of the factors that influence our participants’ password strength and reuse. Our approach allows us to quantify for the first time that password managers indeed influence the password security, however, whether this influence is beneficial or aggravating existing problems depends on the users’ strategies and how well the manager supports the users’ password management right from the time of password creation.

Given our results, we think research should further investigate how managers can better support users’ password strategies in order to improve password security as well as stop aggravating the existing problems.

Reference

@inproceedings{DBLP:conf/uss/LyastaniSF0B18,
 author = {Sanam Ghorbani Lyastani and
Michael Schilling and
Sascha Fahl and
Michael Backes and
Sven Bugiel},
 bibsource = {dblp computer science bibliography, https://dblp.org},
 biburl = {https://dblp.org/rec/conf/uss/LyastaniSF0B18.bib},
 booktitle = {27th USENIX Security Symposium, USENIX Security 2018, Baltimore,
MD, USA, August 15-17, 2018},
 editor = {William Enck and
Adrienne Porter Felt},
 pages = {203--220},
 publisher = {USENIX Association},
 title = {Better managed than memorized? Studying the Impact of Managers on
Password Strength and Reuse},
 url = {https://www.usenix.org/conference/usenixsecurity18/presentation/lyastani},
 year = {2018}
}