Forgetting of passwords: Ecological theory and data

dc.contributorAalto-yliopistofi
dc.contributorAalto Universityen
dc.contributor.authorGao, Xianyien_US
dc.contributor.authorYang, Yulongen_US
dc.contributor.authorLiu, Canen_US
dc.contributor.authorMitropoulos, Christosen_US
dc.contributor.authorLindqvist, Janneen_US
dc.contributor.authorOulasvirta, Anttien_US
dc.contributor.departmentDepartment of Communications and Networkingen
dc.contributor.groupauthorHelsinki Institute for Information Technology (HIIT)en
dc.contributor.groupauthorUser Interfacesen
dc.contributor.organizationRutgers, The State University of New Jerseyen_US
dc.date.accessioned2019-02-25T08:41:24Z
dc.date.available2019-02-25T08:41:24Z
dc.date.issued2018en_US
dc.description.abstractIt is well known that text-based passwords are hard to remember and that users prefer simple (and non-secure) passwords. However, despite extensive research on the topic, no principled account exists for explaining when a password will be forgotten. This paper contributes new data and a set of analyses building on the ecological theory of memory and forgetting. We propose that human memory naturally adapts according to an estimate of how often a password will be needed, such that often used, important passwords are less likely to be forgotten. We derive models for login duration and odds of recall as a function of rate of use and number of uses thus far. The models achieved a root-mean-square error (RMSE) of 1.8 seconds for login duration and 0.09 for recall odds for data collected in a month-long field experiment where frequency of password use was controlled. The theory and data shed new light on password management, account usage, password security and memorability.en
dc.description.versionPeer revieweden
dc.format.mimetypeapplication/pdfen_US
dc.identifier.citationGao, X, Yang, Y, Liu, C, Mitropoulos, C, Lindqvist, J & Oulasvirta, A 2018, Forgetting of passwords: Ecological theory and data . in Proceedings of the 27th USENIX Security Symposium . USENIX -The Advanced Computing Systems Association, pp. 221-238, USENIX Security Symposium, Baltimore, Maryland, United States, 15/08/2018 . < https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-gao.pdf >en
dc.identifier.isbn978-1-931971-46-1
dc.identifier.otherPURE UUID: 1a5171a6-e233-415f-9d8c-325472c87f09en_US
dc.identifier.otherPURE ITEMURL: https://research.aalto.fi/en/publications/1a5171a6-e233-415f-9d8c-325472c87f09en_US
dc.identifier.otherPURE LINK: https://www.usenix.org/system/files/conference/usenixsecurity18/sec18-gao.pdfen_US
dc.identifier.otherPURE FILEURL: https://research.aalto.fi/files/31644223/ELEC_Gao_et_al_Forgetting_passwords_UsenixSS.pdfen_US
dc.identifier.urihttps://aaltodoc.aalto.fi/handle/123456789/36659
dc.identifier.urnURN:NBN:fi:aalto-201902251816
dc.language.isoenen
dc.relation.ispartofUSENIX Security Symposiumen
dc.relation.ispartofseriesProceedings of the 27th USENIX Security Symposiumen
dc.relation.ispartofseriespp. 221-238en
dc.rightsopenAccessen
dc.titleForgetting of passwords: Ecological theory and dataen
dc.typeA4 Artikkeli konferenssijulkaisussafi
dc.type.versionpublishedVersion

Files