Revisiting password rules: facilitating human management of passwords

Revisiting password rules: facilitating human management of passwords
复制标题

重新审视密码规则:促进密码的人性化管理

DOI:
10.1109/ecrime.2016.7487945
复制
发表时间:
2016
期刊:
2016 APWG Symposium on Electronic Crime Research (eCrime)
影响因子:
--
通讯作者:
P. V. Oorschot
P. V. Oorschot
中科院分区:
--
文献类型:
--
作者:
L. Zhang;Sonia Chiasson;P. V. Oorschot

文献摘要

被引文献

相似文献

密码规则是在过去的安全问题背景下建立的。最近在计算机安全方面的工作挑战了密码专家建议的传统智慧,比如经常更改密码,不要重复使用密码,或者不要把密码写下来。这些保护用户账户免受现实世界攻击的规则的有效性受到质疑。我们回顾了在网络上检查通用用户身份验证密码规则的最新研究,并讨论了基于经验证据和坚实理由继续接受或拒绝规则背后的论据。在检查之后,我们建议更新一组密码规则。
Password rules were established in the context of past security concerns. Recent work in computer security challenges the conventional wisdom of expert password advice, such as change your passwords often, do not reuse your passwords, or do not write your passwords down. The effectiveness of these rules for protecting user accounts against real world attacks is questioned. We review the latest research examining password rules for general-purpose user authentication on the web, and discuss the arguments behind the continued acceptance or the rejection of the rules based on empirical evidence and solid justifications. Following the review, we recommend an updated set of password rules.