Pretty good persuasion: a first step towards effective password security in the real world

Pretty good persuasion: a first step towards effective password security in the real world
复制标题

DOI:
10.1145/508171.508195
复制
发表时间:
2001-09
期刊:
--
影响因子:
--
通讯作者:
Dirk Weirich;M. Sasse
Dirk Weirich;M. Sasse
中科院分区:
其他
文献类型:
--
作者:
Dirk Weirich;M. Sasse

文献摘要

被引文献

相似文献

过去,对密码机制的研究几乎完全集中在技术问题上。直到最近几年,安全研究界才认识到,用户行为在许多安全故障中起到了一定作用,单靠策略可能不足以确保正确的行为。我们认为,密码机制及其用户形成了一个社会技术系统,其有效性在很大程度上取决于用户是否愿意做出安全意识行为所需的额外努力。在大多数组织中,不能强迫用户遵守;相反,必须说服他们这样做。归根结底,机制本身、政策、教程、培训和一般话语的设计都必须考虑到它们的说服力。我们介绍了可以指导这种说服努力的第一项研究的结果,并描述了可以用来说服用户使用正确的密码实践的方法。
In the past, research on password mechanisms has focussed almost entirely on technical issues. Only in recent years has the security research community acknowledged that user behavior plays a part in many security failures, and that policies alone may not be sufficient to ensure correct behavior. We argue that password mechanisms and their users form a socio-technical system, whose effectiveness relies strongly on users' willingness to make the extra effort that security-conscious behavior requires. In most organizations, users cannot be forced to comply; rather, they have to be persuaded to do so. Ultimately, the mechanisms themselves, policies, tutorials, training and the general discourse have to be designed with their persuasive power in mind. We present the results of a first study that can guide such persuasive efforts, and describe methods that can be used to persuade users to employ proper password practice.