Skip to main content
QUICK REVIEW

[论文解读] Studying the Impact of Managers on Password Strength and Reuse

Sanam Ghorbani Lyastani, Michael Schilling|arXiv (Cornell University)|Dec 24, 2017
User Authentication and Security Systems参考文献 43被引用 5
一句话总结

本研究通过浏览器插件从170名用户处收集现场密码输入数据,调查密码管理器对密码强度和重复使用的影响,发现只有在与强密码创建策略(尤其是使用内置密码生成器)结合时,管理器才能提升密码质量;而缺乏生成器的管理器可能加剧密码重复和弱化问题。

ABSTRACT

Despite their well-known security problems, passwords are still the incumbent authentication method for virtually all online services. To remedy the situation, end-users are very often referred to password managers as a solution to the password reuse and password weakness problems. However, to date the actual impact of password managers on password security and reuse has not been studied systematically. In this paper, we provide the first large-scale study of the password managers' influence on users' real-life passwords. From 476 participants of an online survey on users' password creation and management strategies, we recruit 170 participants that allowed us to monitor their passwords in-situ through a browser plugin. In contrast to prior work, we collect the passwords' entry methods (e.g., human or password manager) in addition to the passwords and their metrics. Based on our collected data and our survey, we gain a more complete picture of the factors that influence our participants' passwords' strength and reuse. We quantify for the first time that password managers indeed benefit the password strength and uniqueness, however, also our results also suggest that those benefits depend on the users' strategies and that managers without password generators rather aggravate the existing problems.

研究动机与目标

  • 为了理解密码管理器如何影响现实世界中的密码强度和重复使用,突破以往缺乏细粒度输入方式检测的研究局限。
  • 探究密码管理器是否真正提升安全性,还是仅用于存储用户创建的弱密码和重复密码。
  • 研究用户密码创建与存储策略如何与管理器使用相互作用,尤其关注密码生成与输入方式的影响。
  • 评估基于浏览器的密码管理器(如Chrome的)是否减少或加剧密码重复和弱化问题。
  • 基于用户在自然环境中的实际行为,识别密码管理器提供实质性安全收益的条件。

提出的方法

  • 通过在线调查收集476名参与者的反馈,以描绘其密码创建、存储与管理策略,包括信任度、技术能力及过往经验。
  • 招募170名同意安装浏览器插件的参与者,以监控其实时密码输入方式(如手动输入、管理器自动填充、复制粘贴)。
  • 收集并分析实际密码及其输入方式与安全指标(如熵值、唯一性、重复模式)之间的关系。
  • 采用探索性数据分析与统计建模(包括回归分析)来关联输入方式与用户策略,以及密码强度和重复使用情况。
  • 区分具有内置密码生成器与不具生成器的密码管理器,以评估其影响差异。
  • 通过定性反馈评估用户认知,以理解关于密码管理器安全性的误解,例如认为其可防范键盘记录器。

实验结果

研究问题

  • RQ1在现实使用中,使用密码管理器是否会导致更强且更独特的密码?
  • RQ2密码管理器是否具备内置密码生成器,如何影响密码强度和重复使用?
  • RQ3用户密码创建与存储策略在多大程度上影响密码管理器的有效性?
  • RQ4与其它管理器相比,浏览器集成的密码管理器(如Google Chrome)是否减少或增加密码重复?
  • RQ5用户是否误解了密码管理器的安全优势,例如错误地认为其可防范键盘记录器?

主要发现

  • 当用户依赖密码管理器进行密码生成时,尤其是使用内置密码生成器时,密码管理器能显著提升密码强度和唯一性。
  • 借助密码管理器(特别是具备生成器的)创建密码的用户,即使后续手动输入或通过复制粘贴输入,其生成的密码也更强且更独特。
  • 缺乏密码生成器的管理器未能提升安全性,反而与更高的密码重复率和更弱密码相关,表明其主要功能是存储而非安全增强。
  • 发现Google Chrome的内置密码管理器加剧了密码重复问题,可能因其以便捷性为导向的设计及默认不强制使用强密码生成。
  • 许多用户错误地认为密码管理器可防范键盘记录器,这种误解削弱了其对真实威胁模型的理解。
  • 用户对密码管理器安全性的认知常与现实脱节,许多人认为基于浏览器的管理器是安全的,尽管其已知易受恶意软件和设备入侵的影响。

更好的研究,从现在开始

从阅读论文到最终审阅,大幅缩短您的研究时间。

无需绑定信用卡

本解读由 AI 生成,并经人工编辑审核。