MASCARA: Systematically Generating Memorable And Secure Passphrases

03/16/2023
by   Avirup Mukherjee, et al.
0

Passwords are the most common mechanism for authenticating users online. However, studies have shown that users find it difficult to create and manage secure passwords. To that end, passphrases are often recommended as a usable alternative to passwords, which would potentially be easy to remember and hard to guess. However, as we show, user-chosen passphrases fall short of being secure, while state-of-the-art machine-generated passphrases are difficult to remember. In this work, we aim to tackle the drawbacks of the systems that generate passphrases for practical use. In particular, we address the problem of generating secure and memorable passphrases and compare them against user chosen passphrases in use. We identify and characterize 72, 999 user-chosen in-use unique English passphrases from prior leaked password databases. Then we leverage this understanding to create a novel framework for measuring memorability and guessability of passphrases. Utilizing our framework, we design MASCARA, which follows a constrained Markov generation process to create passphrases that optimize for both memorability and guessability. Our evaluation of passphrases shows that MASCARA-generated passphrases are harder to guess than in-use user-generated passphrases, while being easier to remember compared to state-of-the-art machine-generated passphrases. We conduct a two-part user study with crowdsourcing platform Prolific to demonstrate that users have highest memory-recall (and lowest error rate) while using MASCARA passphrases. Moreover, for passphrases of length desired by the users, the recall rate is 60-100 current system-generated ones.

READ FULL TEXT

page 1

page 2

page 3

page 4

research
04/21/2023

PiXi: Password Inspiration by Exploring Information

Passwords, a first line of defense against unauthorized access, must be ...
research
08/12/2023

Copilot Security: A User Study

Code generation tools driven by artificial intelligence have recently be...
research
02/22/2019

On How Users Edit Computer-Generated Visual Stories

A significant body of research in Artificial Intelligence (AI) has focus...
research
12/06/2021

Alice in Passphraseland: Assessing the Memorability of Familiar Vocabularies for System-Assigned Passphrases

Text-based secrets are still the most commonly used authentication mecha...
research
06/01/2015

User Preferences Modeling and Learning for Pleasing Photo Collage Generation

In this paper we consider how to automatically create pleasing photo col...
research
04/28/2023

Can deepfakes be created by novice users?

Recent advancements in machine learning and computer vision have led to ...
research
12/24/2022

Bernoulli honeywords

Decoy passwords, or “honeywords,” planted in a credential database can a...

Please sign up or login with your details

Forgot password? Click here to reset