Title
Password advice shouldn't be boring: Visualizing password guessing attacks
Abstract
Users are susceptible to password guessing attacks when they create weak passwords. Despite an abundance of text-based password advice, it appears insufficient to help home users create strong memorable passwords. We propose that users would be empowered to make better password choices if they understood how password guessing attacks work through visual communication. We created three infographic posters and an online educational comic to help users to learn about the threats. We conducted two studies to assess their effectiveness. All four methods led to superior learning outcomes than the text-alone approach. Our pre-test questionnaires also highlighted that users' understanding of password guessing attacks is limited to a “target” mental model. One week after viewing our materials, the majority of users created strong sample passwords, and correctly described all three attacks: targeted, dictionary, and brute-force.
Year
DOI
Venue
2013
10.1109/eCRS.2013.6805770
eCrime Researchers Summit
Keywords
DocType
ISSN
computer aided instruction,data visualisation,human computer interaction,security of data,brute-force attacks,dictionary attack,infographic posters,online educational comic,password guessing attack visualization,target mental model,targeted attack,text-alone approach,text-based password advice,visual communication
Conference
2159-1237
Citations 
PageRank 
References 
7
0.53
17
Authors
3
Name
Order
Citations
PageRank
Zhang-Kennedy, L.170.53
Chiasson, S.2562.12
Biddle, R.370.53