Title
A Spoonful of Sugar?: The Impact of Guidance and Feedback on Password-Creation Behavior
Abstract
Users often struggle to create passwords under strict requirements. To make this process easier, some providers present real-time feedback during password creation, indicating which requirements are not yet met. Other providers guide users through a multi-step password-creation process. Our 6,435-participant online study examines how feedback and guidance affect password security and usability. We find that real-time password-creation feedback can help users create strong passwords with fewer errors. We also find that although guiding participants through a three-step password-creation process can make creation easier, it may result in weaker passwords. Our results suggest that service providers should present password requirements with feedback to increase usability. However, the presentation of feedback and guidance must be carefully considered, since identical requirements can have different security and usability effects depending on presentation.
Year
DOI
Venue
2015
10.1145/2702123.2702586
CHI
Keywords
Field
DocType
password-composition policies,authentication,passwords,usable security,security policy
Internet privacy,Authentication,Password strength,Computer security,Computer science,Usability,Service provider,Password policy,Password,Security policy,Cognitive password
Conference
Citations 
PageRank 
References 
12
0.55
14
Authors
10
Name
Order
Citations
PageRank
Richard Shay1107343.90
Lujo Bauer22460120.71
Nicolas Christin32133126.02
Lorrie Faith Cranor46767515.80
Alain Forget538320.53
Saranga Komanduri6109541.21
Michelle L. Mazurek7105957.67
William Melicher81447.94
Sean M. Segreti924010.08
Blase Ur1097348.81