USENIX Security2018Top-tier venue
Forgetting of Passwords: Ecological Theory and Data
Xianyi Gao, Yulong Yang, Can Liu, Christos Mitropoulos, Janne Lindqvist, Antti Oulasvirta
Abstract
It is well known that text-based passwords are hard to remember and that users prefer simple (and non-secure) passwords. However, despite extensive research on the topic, no principled account exists for explaining when a password will be forgotten. This paper contributes new data and a set of analyses building on the ecological theory of memory and forgetting. We propose that human memory naturally adapts according to an estimate of how often a password will be needed, such that often used, important passwords are less likely to be forgotten. We derive models for login duration and odds of recall as a function of rate of use and number of uses thus far. The models achieved a root-mean-square error (RMSE) of 1.8 seconds for login duration and 0.09 for recall odds for data collected in a month-long field experiment where frequency of password use was controlled. The theory and data shed new light on password management, account usage, password security and memorability.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8efdaa1f-c016-4640-ba29-bbaa36b4500aCited by top-tier papers7
- Computational Rationality as a Theory of InteractionAntti Oulasvirta, Jussi P. P. Jokinen, Andrew HowesCHI 2022 · 127 citations
- How to Attack and Generate HoneywordsDing Wang, Yunkai Zou, Qiying Dong, Yuanming Song et al.S&P 2022 · 45 citations
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
- "Get in Researchers; We're Measuring Reproducibility": A Reproducibility Study of Machine Learning Papers in Tier 1 Security ConferencesDaniel Olszewski, Allison Lu, Carson Stillman, Kevin Warren et al.CCS 2023 · 19 citations
- "I Can't Believe It's Not Custodial!": Usable Trustless Decentralized Key ManagementTanusree Sharma, Vivek C. Nair, Henry Wang, Yang Wang et al.CHI 2024 · 6 citations
Builds on2
- Fast, Lean, and Accurate: Modeling Password Guessability Using Neural NetworksWilliam Melicher, Blase Ur, Sean M. Segreti, Saranga Komanduri et al.USENIX Security 2016 · 331 citations
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
Related papers
- Choose From a List: A User Study of Random Password MemorabilityMichael Clark, Gregory L. Snow, Kent E. SeamonsCHI 2025 · 1 citation
- An Empirical Study of Mnemonic Sentence-based Password Generation StrategiesWeining Yang, Ninghui Li, Omar Chowdhury, Aiping Xiong et al.CCS 2016 · 48 citations
- Reinforcing System-Assigned Passphrases Through Implicit LearningZeinab Joudaki, Julie Thorpe, Miguel Vargas MartinCCS 2018 · 21 citations
- The Rewards and Costs of Stronger Passwords in a University: Linking Password Lifetime to StrengthIngolf Becker, Simon Parkin, M. Angela SasseUSENIX Security 2018 · 14 citations
- Why Users (Don't) Use Password Managers at a Large Educational InstitutionPeter Mayer, Collins W. Munyendo, Michelle L. Mazurek, Adam J. AvivUSENIX Security 2022
