Unmasking the Security and Usability of Password Masking
Yuqi Hu, Suood Alroomi, Sena Sahin, Frank Li
摘要
Password masking, a practice where passwords are obscured during entry, is widely adopted for online authentication. However, its merits have been debated for over a decade, with questions about its security benefits and concerns about its usability impact. Yet to date, masking has received limited prior exploration. In this work, we empirically investigate the security and usability impact of password masking. We first assess the masking practices of popular browsers and websites, demonstrating masking's ubiquity as well as its design diversity. Guided by our real-world observations, we then conduct a mixed-method evaluation of masking for both mobile and PC devices, combining a survey of over 200 participants on their experiences with and perspectives on masking along with user experiments of 600 participants performing password logins under varying masking conditions. Through our study, we uncover misconceptions about masking, masking's usability and security impact, and user preferences on masking's use and its design. Ultimately, our study establishes empirical grounding on how this popular technique manifests in practice, providing recommendations for its use moving forward. CCS Concepts • Security and privacy → Usability in security and privacy; Authentication.
问问这篇 Paper
智能体会读完全文。
Lune 把这篇 Paper 索引到了每一个公式,引用它的顶会 Paper 也一样。你提问,回答直接引用原文。
引用它的顶会 Paper2
- SeQR: A User-Friendly and Secure-by-Design Configurator for Enterprise Wi-FiS. Mahmudul Hasan, Che Wei Tu, Md. Endadul Hoque, Omar Chowdhury 等CHI 2025 · 被引用 2 次
- Success Rates Doubled with Only One Character: Mask Password GuessingYunkai Zou, Ding Wang, Fei DuanNDSS 2026 · 被引用 1 次
它引用的顶会 Paper7
- zxcvbn: Low-Budget Password Strength EstimationDaniel Lowe WheelerUSENIX Security 2016 · 被引用 243 次
- Measuring HTTPS Adoption on the WebAdrienne Porter Felt, Richard Barnes, April King, Chris Palmer 等USENIX Security 2017 · 被引用 177 次
- CSP Is Dead, Long Live CSP! On the Insecurity of Whitelists and the Future of Content Security PolicyLukas Weichselbaum, Michele Spagnuolo, Sebastian Lekies, Artur JancCCS 2016 · 被引用 114 次
- pASSWORD tYPOS and How to Correct Them SecurelyRahul Chatterjee, Anish Athayle, Devdatta Akhawe, Ari Juels 等S&P 2016 · 被引用 68 次
- Practical Recommendations for Stronger, More Usable Passwords Combining Minimum-strength, Minimum-length, and Blocklist RequirementsJoshua Tan, Lujo Bauer, Nicolas Christin, Lorrie Faith CranorCCS 2020 · 被引用 49 次
相关 Paper
- "I don't see why I would ever want to use it": Analyzing the Usability of Popular Smartphone Password ManagersSunyoung Seiler-Hwang, Patricia Arias Cabarcos, Andrés Marín, Florina Almenáres 等CCS 2019 · 被引用 46 次
- "I just stopped using one and started using the other": Motivations, Techniques, and Challenges When Switching Password ManagersCollins W. Munyendo, Peter Mayer, Adam J. AvivCCS 2023 · 被引用 10 次
- Investigating the Password Policy Practices of Website AdministratorsSena Sahin, Suood Abdulaziz Al-Roomi, Tara Poteat, Frank LiS&P 2023
- A Large-Scale Measurement of Website Login PoliciesSuood Abdulaziz Al-Roomi, Frank LiUSENIX Security 2023
- Let's Go in for a Closer Look: Observing Passwords in Their Natural HabitatSarah Pearman, Jeremy Thomas, Pardis Emami Naeini, Hana Habib 等CCS 2017 · 被引用 168 次
