Unmasking the Security and Usability of Password Masking
Yuqi Hu, Suood Alroomi, Sena Sahin, Frank Li
Abstract
Password masking, a practice where passwords are obscured during entry, is widely adopted for online authentication. However, its merits have been debated for over a decade, with questions about its security benefits and concerns about its usability impact. Yet to date, masking has received limited prior exploration. In this work, we empirically investigate the security and usability impact of password masking. We first assess the masking practices of popular browsers and websites, demonstrating masking's ubiquity as well as its design diversity. Guided by our real-world observations, we then conduct a mixed-method evaluation of masking for both mobile and PC devices, combining a survey of over 200 participants on their experiences with and perspectives on masking along with user experiments of 600 participants performing password logins under varying masking conditions. Through our study, we uncover misconceptions about masking, masking's usability and security impact, and user preferences on masking's use and its design. Ultimately, our study establishes empirical grounding on how this popular technique manifests in practice, providing recommendations for its use moving forward. CCS Concepts • Security and privacy → Usability in security and privacy; Authentication.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 8ff4821c-17ca-481b-8b1a-08d83d08b39eCited by top-tier papers2
- SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-FiS. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury et al.CHI 2025 · 2 citations
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 1 citation
Builds on7
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 243 citations
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer et al.USENIX Security 2017 · 177 citations
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 114 citations
- pASSWORD tYPOS and How to Correct Them SecurelyRahul Chatterjee, Anish Athayle, Devdatta Akhawe, Ari Juels et al.S&P 2016 · 68 citations
- Practical Recommendations for Stronger, More Usable Passwords Combining Minimum-strength, Minimum-length, and Blocklist RequirementsJoshua Tan, Lujo Bauer, Nicolas Christin, Lorrie Faith CranorCCS 2020 · 49 citations
Related papers
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres et al.CCS 2019 · 46 citations
- "I just stopped using one and started using the other": Motivations, Techniques, and Challenges When Switching Password ManagersCollins W. Munyendo, Peter Mayer, Adam J. AvivCCS 2023 · 10 citations
- Investigating the Password Policy Practices of Website AdministratorsSena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank LiS&P 2023
- A Large-Scale Measurement of Website Login PoliciesSuood Abdulaziz Al-Roomi, Frank LiUSENIX Security 2023
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib et al.CCS 2017 · 168 citations
