Let's Go in for a Closer Look: Observing Passwords in Their Natural Habitat
Sarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Serge Egelman, Alain Forget
Abstract
Text passwords---a frequent vector for account compromise, yet still ubiquitous---have been studied for decades by researchers attempting to determine how to coerce users to create passwords that are hard for attackers to guess but still easy for users to type and memorize. Most studies examine one password or a small number of passwords per user, and studies often rely on passwords created solely for the purpose of the study or on passwords protecting low-value accounts. These limitations severely constrain our understanding of password security in practice, including the extent and nature of password reuse, password behaviors specific to categories of accounts (e.g., financial websites), and the effect of password managers and other privacy tools. In this paper we report on an in situ study of 154 participants over an average of 147 days each. Participants' computers were instrumented---with careful attention to privacy---to record detailed information about password characteristics and usage, as well as man other computing behaviors such as use of security and privacy web browser extensions. This data allows a more accurate analysis of password characteristics and behaviors across the full range of participants' web-based accounts. Examples of our findings are that the use of symbols and digits in passwords predicts increased likelihood of reuse, while increased password strength predicts decreased likelihood of reuse; that password reuse is more prevalent than previously believed, especially when partial reuse is taken into account; and that password managers may have no impact on password reuse or strength. We also observe that users can be grouped into a handful of behavioral clusters, representative of various password management strategies. Our findings suggest that once a user needs to manage a larger number of passwords, they cope by partially and exactly reusing passwords across most of their accounts.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Cited by top-tier papers47
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 100 citations
- Examining the Adoption and Abandonment of Security, Privacy, and Identity Theft Protection PracticesYixin Zou, Kevin A. Roundy, Acar Tamersoy, Saurabh Shintre et al.CHI 2020 · 73 citations
- "What was that site doing with my Facebook password?": Designing Password-Reuse NotificationsMaximilian Golla, Miranda Wei, Juliette Hainline, Lydia Filipe et al.CCS 2018 · 68 citations
Builds on1
Related papers
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes et al.USENIX Security 2018 · 63 citations
- Why Users (Don't) Use Password Managers at a Large Educational InstitutionPeter Mayer, Collins W. Munyendo, Michelle L. Mazurek, Adam J. AvivUSENIX Security 2022
- Phishing Attacks against Password Manager Browser ExtensionsClaudio Anliker, Daniele Lain, Srdjan CapkunUSENIX Security 2025
- "It Basically Started Using Me: " An Observational Study of Password Manager UsageSean Oesch, Scott Ruoti, James Simmons, Anuj GautamCHI 2022 · 21 citations
- Forgetting of Passwords: Ecological Theory and DataXianyi Gao, Yulong Yang, Can Liu, Christos Mitropoulos et al.USENIX Security 2018 · 31 citations
