Open Sesame! On the Security and Memorability of Verbal Passwords
Eunsoo Kim, Kiho Lee, Doowon Kim, Hyoungshick Kim
Abstract
Despite extensive research on text passwords, the security and memorability of verbal passwords-spoken rather than typed-remain underexplored. Verbal passwords hold significant potential for scenarios where keyboard input is impractical (e.g., smart speakers, wearables, vehicles) or users have motor impairments that make typing difficult. Through two large-scale user studies, we assessed the viability of verbal passwords. In our first study (N = 2,085), freely chosen verbal passwords were found to have a limited guessing space, with 39.76% cracked within 109 guesses. However, in our second study (n = 600), applying word count and blocklist policies for verbal password creation significantly enhanced verbal password performance, achieving better memorability and security than traditional text passwords. Specifically, 65.6% of verbal password users (under the password creation policy using minimum word counts and a blocklist) successfully recalled their passwords in long-term tests, compared to 54.11% for text passwords. Additionally, verbal passwords with enforced policies exhibited a lower crack rate (6.5%) than text passwords (10.3%). These findings highlight verbal passwords as a practical and secure alternative for contexts where text passwords are infeasible, offering strong memorability with robust resistance to guessing attacks.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 382e1612-828b-44fd-b9f9-d9b4a9178299Builds on6
- Who is Real Bob? Adversarial Attacks on Speaker Recognition SystemsGuangke Chen, Sen Chen, Lingling Fan, Xiaoning Du et al.S&P 2021 · 239 citations
- Ask the Experts: What Should Be on an IoT Privacy and Security Label?Pardis Emami Naeini, Yuvraj Agarwal, Lorrie Faith Cranor, Hanan HibshiS&P 2020 · 195 citations
- SoK: Authentication in Augmented and Virtual RealitySophie Stephenson, Bijeeta Pal, Stephen Fan, Earlence Fernandes et al.S&P 2022 · 76 citations
- SysPal: System-Guided Pattern Locks for AndroidGeumhwan Cho, Jun Ho Huh, Junsung Cho, Seongyeol Oh et al.S&P 2017 · 54 citations
- Can I Hear Your Face? Pervasive Attack on Voice Authentication Systems with a Single Face ImageNan Jiang, Bangjie Sun, Terence Sim, Jun HanUSENIX Security 2024 · 7 citations
Related papers
- How Do We Create a Fantabulous Password?Simon S. WooWWW 2020 · 4 citations
- Understanding the Design Space of Embodied Passwords based on Muscle MemoryRosa van Koningsbruggen, Bart Hengeveld, Jason AlexanderCHI 2021 · 8 citations
- An Empirical Study of Mnemonic Sentence-based Password Generation StrategiesWeining Yang, Ninghui Li, Omar Chowdhury, Aiping Xiong et al.CCS 2016 · 48 citations
- Gesture Authentication for Smartphones: Evaluation of Gesture Password Selection PoliciesEunyong Cheon, Yonghwan Shin, Jun Ho Huh, Hyoungshick Kim et al.S&P 2020 · 17 citations
- GestureMeter: Design and Evaluation of a Gesture Password Strength MeterEunyong Cheon, Jun Ho Huh, Ian OakleyCHI 2023 · 5 citations
