论文标题
改进密码选择的前景
Prospects for Improving Password Selection
论文作者
论文摘要
用户选择的密码对于在线安全性仍然至关重要,但是人们继续选择弱,不安全的密码。在这项工作中,我们调查了前景理论是人们如何评估风险的行为模型,可以提供有关用户如何选择密码的见解,以及它是否可以激发新设计的密码选择机制,以推动用户选择更强大的密码。我们与762名参与者进行了一项用户研究,我们发现,通过前景理论指导的干预措施 - 通过将选择弱密码作为相对于选择更强密码的损失来利用参考依赖性效果 - 使大约25%的用户可以使密码的强度提高密码的强度(比替代方案大大增加了密码),并降低了大约25%的最终数量的密码数量。我们还评估了用户行为与用户的黑客攻击和密码攻击的心理模型之间的关系。这些结果为设计和实施帐户注册机制提供了指导,这些机制将显着提高用户选择的密码的强度,从而利用前景理论的见解来提高使用基于密码身份验证的系统的安全性。
User-chosen passwords remain essential to online security, and yet people continue to choose weak, insecure passwords. In this work, we investigate whether prospect theory, a behavioral model of how people evaluate risk, can provide insights into how users choose passwords and whether it can motivate new designs for password selection mechanisms that will nudge users to select stronger passwords. We ran a user study with 762 participants, and we found that an intervention guided by prospect theory -- which leverages the reference-dependence effect by framing selecting weak passwords as a loss relative to choosing a stronger password -- causes approximately 25% of users to improve the strength of their password (significantly more than alternative interventions) and reduced the final number of weak passwords by approximately 25%. We also evaluate the relation between user behavior and users' mental models of hacking and password attacks. These results provide guidance for designing and implementing account registration mechanisms that will significantly improve the strength of user-selected passwords, thereby leveraging insights from prospect theory to improve the security of systems that use password-based authentication.