Title
Why we hate IT: two surveys on pre‐generated and expiring passwords in an academic setting
Abstract
We performed two surveys to understand how members of a university managed their passwords. At password creation, the university offered people four pre-generated random passwords, with the option of creating their own subject to stringent requirements. All passwords expired after 120days. We found that most respondents chose to create their own password and utilized coping strategies that undermined the security of the requirements, as well as reporting that the expiration times were too short. We also attempt to connect these behaviors to respondents' other password habits and demographics. We conclude that pre-generated random passwords, stringent password requirements, and rapid password expiration dates are unusable security requirements for most people and lead users to subvert password requirements and reuse passwords. Copyright (c) 2015 John Wiley & Sons, Ltd.
Year
DOI
Venue
2015
10.1002/sec.1184
SECURITY AND COMMUNICATION NETWORKS
Keywords
Field
DocType
pre-generated,password,university,usability,survey,expire
Internet privacy,Computer science,Computer security,Reuse,Usability,Coping (psychology),Password policy,Password,Demographics,Cognitive password
Journal
Volume
Issue
ISSN
8
13
1939-0114
Citations 
PageRank 
References 
1
0.35
17
Authors
2
Name
Order
Citations
PageRank
Michael Farcasin181.14
Eric Chan-Tin222915.79