TY - GEN
T1 - Towards making random passwords memorable
T2 - 33rd Annual CHI Conference on Human Factors in Computing Systems, CHI 2015
AU - Al-Ameen, Mahdi Nasrullah
AU - Wright, Matthew
AU - Scielzo, Shannon
PY - 2015/4/18
Y1 - 2015/4/18
N2 - Given the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. System-assigned passwords provide measurable security but suffer from poor memorability. To address this usability-security tension, we argue that systems should assign random passwords but also help with memorization and recall. We investigate the feasibility of this approach with CuedR, a novel cued-recognition authentication scheme that provides users with multiple cues (visual, verbal, and spatial) and lets them choose the cues that best fit their learning process for later recognition of system-assigned keywords. In our lab study, all 37 of our participants could log in within three attempts one week after registration (mean login time: 38:0 seconds). A pilot study on using multiple CuedR passwords also showed 100% recall within three attempts. Based on our results, we suggest appropriate applications for CuedR, such as financial and e-commerce accounts.
AB - Given the choice, users produce passwords reflecting common strategies and patterns that ease recall but offer uncertain and often weak security. System-assigned passwords provide measurable security but suffer from poor memorability. To address this usability-security tension, we argue that systems should assign random passwords but also help with memorization and recall. We investigate the feasibility of this approach with CuedR, a novel cued-recognition authentication scheme that provides users with multiple cues (visual, verbal, and spatial) and lets them choose the cues that best fit their learning process for later recognition of system-assigned keywords. In our lab study, all 37 of our participants could log in within three attempts one week after registration (mean login time: 38:0 seconds). A pilot study on using multiple CuedR passwords also showed 100% recall within three attempts. Based on our results, we suggest appropriate applications for CuedR, such as financial and e-commerce accounts.
KW - Authentication
KW - Cued-recognition
KW - Usable security
UR - http://www.scopus.com/inward/record.url?scp=84951082067&partnerID=8YFLogxK
UR - http://www.scopus.com/inward/citedby.url?scp=84951082067&partnerID=8YFLogxK
U2 - 10.1145/2702123.2702241
DO - 10.1145/2702123.2702241
M3 - Conference contribution
AN - SCOPUS:84951082067
T3 - Conference on Human Factors in Computing Systems - Proceedings
SP - 2315
EP - 2324
BT - CHI 2015 - Proceedings of the 33rd Annual CHI Conference on Human Factors in Computing Systems
PB - Association for Computing Machinery
Y2 - 18 April 2015 through 23 April 2015
ER -