Sciweavers

CHI
2010
ACM

The true cost of unusable password policies: password use in the wild

13 years 9 months ago
The true cost of unusable password policies: password use in the wild
HCI research published 10 years ago pointed out that many users cannot cope with the number and complexity of passwords, and resort to insecure workarounds as a consequence. We present a study which re-examined password policies and password practice in the workplace today. 32 staff members in two organisations kept a password diary for 1 week, which produced a sample of 196 passwords. The diary was followed by an interview which covered details of each password, in its context of use. We find that users are in general concerned to maintain security, but that existing security policies are too inflexible to match their capabilities, and the tasks and contexts in which they operate. As a result, these password policies can place demands on users which impact negatively on their productivity and, ultimately, that of the organisation. We conclude that, rather than focussing password policies on maximizing password strength and enforcing frequency alone, policies should be designed using ...
Philip Inglesant, Martina Angela Sasse
Added 03 Jul 2010
Updated 03 Jul 2010
Type Conference
Year 2010
Where CHI
Authors Philip Inglesant, Martina Angela Sasse
Comments (0)