“Self-chosen passwords are often surprisingly easy to guess.” — Jerome H., Comm. ACM, 1974
“The only secure password is the one you can’t remember.” — Troy Hunt, Blog, 2011.
“Example of cyber resilience. Password policy too complex couldn't be bothered to comment on blog.” — A tweet by Gamingworks, June, 2015.
This is a big project encouraged by some wonderful reviewers and of my personal interest: it will be useful for the community and industry. It may take 3 year or 5 years to finish. Currently, I am performing related research (e.g., my ESORICS'15 paper on password policies of 100+ leading sites, ACM CCS'16 paper on targeted online guessing threat, ACM ASIACCS'17 paper on human-chosen PINs and NDSS'18 paper on password storage) and collecting related materials (e.g., evidence for over 30+ debates from the literature). Thanks for the great help from my team members. I am also grateful to many constructive feedbacks.
“It has to have upper case, lower case, special characters, and at least one numeral. Also, spaces aren't allowed. It's not enough to come up with a secure password. You have to come up with a secure password that follows the arcane rules, different for each site, and you have to change it every 90 days. Then you have to do this fifty more times, because you probably log into at least fifty sites and the worst thing you can do is re-use a password.”
High complexity + Not reuse + Frequent expiration = Not usable policy
Circumvent high complexity + highly re-use + recycling/write down = common user practice
A user survey:
So far, we have got 500+ effective responses. Thanks for your participation!
Despite many pioneering works, there is still a lack of both theoretic and empirical academic exploration: