Password Security: What Users Know and What They Actually Do
Date: February 2006
Publication: Usability News, Volume 8, Issue 1
Source 1: http://psychology.wichita.edu/surl/usabilitynews/81/pdf/Usability%20News%2081%20-%20Riley.pdf
Source 2: http://psychology.wichita.edu/surl/usabilitynews/81/passwords.asp
Abstract or Summary:
This study investigated the common password generation practices of online users. Three hundred and fifteen undergraduate and graduate students completed a survey querying (1) the types and number of different password protected accounts maintained; (2) actual practices used in generating, storing and using passwords; (3) practices believed they should use in generating and storing passwords; and (4) general demographic information. Results indicate that, in general, users do not vary the complexity of passwords depending on the nature of the site (bank account vs. instant messenger) or change their passwords on any regular basis if it is not required by the site. Users report using lower case letters, numbers or digits, personally meaningful numbers and personally meaningful words when creating passwords, despite the fact that they realize that these methods may not be the most secure.
Do you have additional information to contribute regarding this research paper? If so, please email firstname.lastname@example.org with the details.