Alice in Passphraseland: Assessing the Memorability of Familiar Vocabularies for System-Assigned Passphrases

12/06/2021
by   Noopa Jagadeesh, et al.
0

Text-based secrets are still the most commonly used authentication mechanism in information systems. IT managers must strike a balance between security and memorability while developing password policies. Initially introduced as more secure authentication keys that people could recall, passphrases are passwords consisting of multiple words. However, when left to the choice of users, they tend to choose predictable natural language patterns in passphrases, resulting in vulnerability to guessing attacks. System-assigned authentication keys can be guaranteed to be secure, but this comes at a cost to memorability. In this study we investigate the memorability of system-assigned passphrases from a familiar vocabulary to the user. The passphrases are generated with the Generative Pre-trained Transformer 2 (GPT-2) model trained on the familiar vocabulary and are readable, pronounceable, sentence like passphrases resembling natural English sentences. Through an online user study with 500 participants on Amazon Mechanical Turk, we test our hypothesis - following a spaced repetition schedule, passphrases as natural English sentences, based on familiar vocabulary are easier to recall than passphrases composed of random common words. As a proof-of-concept, we tested the idea with Amazon Mechanical Turk participants by assigning them GPT-2 generated passphrases based on stories they were familiar with. Contrary to expectations, following a spaced repetition schedule, passphrases as natural English sentences, based on familiar vocabulary performed similarly to system-assigned passphrases based on random common words.

READ FULL TEXT

page 1

page 7

research
02/15/2023

FIDO2 the Rescue? Platform vs. Roaming Authentication on Smartphones

Modern smartphones support FIDO2 passwordless authentication using eithe...
research
05/19/2021

Detection of Emotions in Hindi-English Code Mixed Text Data

In recent times, we have seen an increased use of text chat for communic...
research
12/09/2019

Force vs Nudge : Comparing Users Pattern Choices on SysPal and TinPal

Android's 3X3 graphical pattern lock scheme is one of the widely used au...
research
12/09/2019

Extended- Force vs Nudge : Comparing Users' Pattern Choices on SysPal and TinPal

Android's 3X3 graphical pattern lock scheme is one of the widely used au...
research
03/16/2023

MASCARA: Systematically Generating Memorable And Secure Passphrases

Passwords are the most common mechanism for authenticating users online....
research
01/30/2019

The effect of a physical robot on vocabulary learning

This study investigates the effect of a physical robot taking the role o...

Please sign up or login with your details

Forgot password? Click here to reset