The Memorability and Security of Passwords - Some Empirical Results
Date: September 2000
Publication: University of Cambridge Technical Report, UCAM-CL-TR-500
Source 1: http://www.cl.cam.ac.uk/techreports/UCAM-CL-TR-500.pdf
Source 2: http://www.humboldt.edu/its/sites/its/files/docs/strong_passwords.pdf
There are many things that are 'well known' about passwords, such as that uers can't remember strong passwords and that the passwords they can remember are easy to guess. However, there seems to be a distinct lack of research on the subject that would pass muster by the standards of applied psychology.
Here we report a controlled trial in which, of four sample groups of about 100 first-year students, three were recruited to a formal experiment and of these two were given specific advice about password selection. The incidence of weak passwords was determined by cracking the password file, and the number of password resets was measured from system logs. We observed a number of phenomena which run counter to the established wisdom. For example, passwords based on mnemonic phrases are just as hard to crack as random passwords yet just as easy to remember as naive user selections.
PasswordResearch.com Note: A version of this paper was published with the title Password Memorability and Security: Empirical Results in the IEEE Security & Privacy Journal, Sept/Oct 2004
Do you have additional information to contribute regarding this research paper? If so, please email email@example.com with the details.