Human-Generated and Machine-Generated Ratings of Password Strength: What Do Users Trust More?

Human-Generated and Machine-Generated Ratings of Password Strength: What Do Users Trust More?
复制标题

DOI:
10.4108/eai.13-7-2018.162797
复制
发表时间:
2019-08
期刊:
EAI Endorsed Trans. Security Safety
影响因子:
--
通讯作者:
S. Alqahtani;Shujun Li;Haiyue Yuan;P. Rusconi
S. Alqahtani;Shujun Li;Haiyue Yuan;P. Rusconi
中科院分区:
其他
文献类型:
--
作者:
S. Alqahtani;Shujun Li;Haiyue Yuan;P. Rusconi

文献摘要

相似文献

主动密码检查器已被广泛用于通过提供机器生成的密码强度评级来说服用户选择更强的密码。如果这样的评级与人类用户的人工生成评级不匹配,则可能会失去对PPC的信任。为了研究PPC的有效性,调查人类用户如何根据他们的信任来感知这种机器和人类生成的评级将是有用的,这在文献中很少被研究。为了填补这一空白,我们报告了一项涉及1,000多名员工的大规模众包研究。参与者被要求选择他们更信任的两个评级中的哪一个。这些密码是根据对100多名人工密码专家的调查选出的。结果显示,当密码被隐藏时,参与者表现出四种不同的行为模式,许多人在密码被披露后显着改变了他们的行为,这表明他们报告的信任受到自己判断的影响。
Proactive password checkers have been widely used to persuade users to select stronger passwords by providing machine-generated strength ratings of passwords. If such ratings do not match human-generated ratings of human users, there can be a loss of trust in PPCs. In order to study the effectiveness of PPCs, it would be useful to investigate how human users perceive such machine- and human-generated ratings in terms of their trust, which has been rarely studied in the literature. To fill this gap, we report a large-scale crowdsourcing study with over 1,000 workers. The participants were asked to choose which of the two ratings they trusted more. The passwords were selected based on a survey of over 100 human password experts. The results revealed that participants exhibited four distinct behavioral patterns when the passwords were hidden, and many changed their behaviors significantly after the passwords were disclosed, suggesting their reported trust was influenced by their own judgments.