A Large-scale Analysis of the Mnemonic Password Advice
Johannes Kiesel, Benno Stein, Stefan Lucks
摘要
How to choose a strong but still easily memorable password? An often recommended advice is to memorize a random sentence (the mnemonic) and to concatenate the words' initials: a so-called mnemonic password. The paper in hand analyzes the effectiveness of this advice-in terms of the obtained password strength-and sheds light on various related aspects. While it is infeasible to obtain a sufficiently large sample of human-chosen mnemonics, the password strength depends only on the distribution of certain character probabilities. We provide several pieces of evidence that these character probabilities are approximately the same for human-chosen mnemonics and sentences from a web crawl and exploit this connection for our analyses. The presented analyses are independent of cracking software, avoid privacy concerns, and allow full control over the details of how passwords are generated from sentences. In particular, the paper introduces the following original research contributions: (1) construction of one of the largest corpora of human-chosen mnemonics, (2) construction of two web sentence corpora from the 27.3 TB ClueWeb12 web crawl, (3) demonstration of the suitability of web sentences as substitutes for mnemonics in password strength analyses, (4) improved estimation of password probabilities by position-dependent language models, and (5) analysis of the obtained password strength using web sentence samples of different sentence complexity and using 18 generation rules for mnemonic password construction. Our findings include both expected and less expected results, among others: mnemonic passwords from lowercase letters only provide comparable strength to mnemonic passwords that exploit the 7-bit visible ASCII character set, less complex mnemonics reduce password strength in offline scenarios by less than expected, and longer mnemonic passwords provide more security in an offline but not necessarily in an online scenario. When compared to passwords generated by uniform sampling from a dictionary, distributions of mnemonic passwords can reach the same strength against offline attacks with less characters. Permission to freely reproduce all or part of this paper for noncommercial purposes is granted provided that copies bear this notice and the full citation on the first page. Reproduction for commercial purposes is strictly prohibited without the prior written consent of the Internet Society, the first-named author (for reproduction of an entire paper only), and the author's employer if the paper was prepared within the scope of employment.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- Abstractive Snippet GenerationWei-Fan Chen, Shahbaz Syed, Benno Stein, Matthias Hagen 等WWW 2020 · 被引用 33 次
- Chunk-Level Password Guessing: Towards Modeling Refined Password Composition RepresentationsMing Xu, Chuanwang Wang, Jitao Yu, Junjie Zhang 等CCS 2021 · 被引用 32 次
它引用的顶会 Paper1
相关 Paper
- Choose From a List: A User Study of Random Password MemorabilityMichael Clark, Gregory L. Snow, Kent E. SeamonsCHI 2025 · 被引用 1 次
- Can Foundation LLMs Accurately Estimate Password Strength and Provide Appropriate Password Feedback?Madison Pickering, Garrison Hinson-Hasty, Luca Dovichi, Helena Williams 等S&P 2026
- How Do We Create a Fantabulous Password?Simon S. WooWWW 2020 · 被引用 4 次
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
- On the Accuracy of Password Strength MetersMaximilian Golla, Markus DürmuthCCS 2018 · 被引用 100 次
