USENIX Security2016Top-tier venue
zxcvbn: Low-Budget Password Strength Estimation
Daniel Lowe Wheeler
Abstract
For over 30 years, password requirements and feedback have largely remained a product of LUDS: counts of lowerand uppercase letters, digits and symbols. LUDS remains ubiquitous despite being a conclusively burdensome and ineffective security practice.
zxcvbn is an alternative password strength estimator that is small, fast, and crucially no harder than LUDS to adopt. Using leaked passwords, we compare its estimations to the best of four modern guessing attacks and show it to be accurate and conservative at low magnitudes, suitable for mitigating online attacks. We find 1.5 MB of compressed storage is sufficient to accurately estimate the best-known guessing attacks up to 10 5 guesses, or 10 4 and 10 3 guesses, respectively, given 245 kB and 29 kB. zxcvbn can be adopted with 4 lines of code and downloaded in seconds. It runs in milliseconds and works as-is on web, iOS and Android.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext c6f3a172-e0e1-4218-b91a-a9bfc4e2a02eCited by top-tier papers32
- Protecting accounts from credential stuffing with password breach alertingKurt Thomas, Jennifer Pullman, Kevin Yeo, Ananth Raghunathan et al.USENIX Security 2019 · 154 citations
- Beyond Credential Stuffing: Password Similarity Models Using Neural NetworksBijeeta Pal, Tal Daniel, Rahul Chatterjee, Thomas RistenpartS&P 2019 · 100 citations
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 100 citations
- Protocols for Checking Compromised CredentialsLucy Li, Bijeeta Pal, Junade Ali, Nick Sullivan et al.CCS 2019 · 80 citations
- Better managed than memorized? Studying the Impact of Managers on Password Strength and ReuseSanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes et al.USENIX Security 2018 · 63 citations
Builds on1
Related papers
- No Single Silver Bullet: Measuring the Accuracy of Password Strength MetersDing Wang, Xuan Shan, Qiying Dong, Yaosheng Shen et al.USENIX Security 2023
- Confident Monte Carlo: Rigorous Analysis of Guessing Curves for Probabilistic Password ModelsPeiyuan Liu, Jeremiah Blocki, Wenjie BaiS&P 2023
- Reasoning Analytically about Password-Cracking SoftwareEnze Liu, Amanda Nakanishi, Maximilian Golla, David Cash et al.S&P 2019 · 33 citations
- Distinguishing Attacks from Legitimate Authentication Traffic at ScaleCormac Herley, Stuart E. SchechterNDSS 2019 · 15 citations
- Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsMing Xu, Chuanwang Wang, Jitao Yu, Junjie Zhang et al.CCS 2021 · 32 citations
