Who creates strong passwords when nudging fails

Who creates strong passwords when nudging fails
复制标题

DOI:
10.1016/j.chbr.2021.100132
复制
发表时间:
2021-08
期刊:
Computers in Human Behavior Reports
影响因子:
--
通讯作者:
S. Kennison;Ian T. Jones;Victoria H. Spooner;D. E. Chan-Tin
S. Kennison;Ian T. Jones;Victoria H. Spooner;D. E. Chan-Tin
中科院分区:
其他
文献类型:
--
作者:
S. Kennison;Ian T. Jones;Victoria H. Spooner;D. E. Chan-Tin

文献摘要

相似文献

使用强密码被视为一种推荐的网络安全做法,因为对弱密码的黑客攻击导致了重大的网络安全漏洞。这项研究调查了基于参与者的自我图式对消息进行微调是否会导致他们创建更强的密码。我们的研究以之前的健康相关研究为模型,使用基于自我图式类别(即,真彩色类别-同情、忠诚、智力和冒险)的消息展示了积极的结果。我们进行了一项在线研究,其中一项研究涉及256名本科生(185名女性,66名男性,5名其他人),另一项研究涉及424名(240名男性,179名女性,5名其他)亚马逊土耳其机械师(Amazon Machine Turk,MTurk)员工,我们随机分配参与者接收与他们的自我图式匹配或不匹配的消息。我们还调查了五大人格特征、安全密码知识、态度和行为、认知需求和总体冒险行为的差异是否预测了参与者在研究期间创造的密码的强度。多个个体差异变量预测密码强度(即尽职尽责、情绪稳定性、认知需求、自我报告的安全密码知识、态度和行为,以及总体风险承担)。与大学生相比,MTurk员工拥有更高的网络安全知识水平,并创造出更强的密码。这些轻推的消息并没有产生更强的密码。讨论了增加使用安全密码的策略的含义。
The use of strong passwords is viewed as a recommended cybersecurity practice, as the hacking of weak passwords led to major cybersecurity breaches. The present research investigated whether nudging with messages based on participants’ self-schemas could lead them to create stronger passwords. We modeled our study on prior health-related research demonstrating positive results using messages based on self-schema categories (i.e., True Colors categories -compassionate, loyal, intellectual, and adventurous). We carried out an online study, one with 256 (185 women, 66 men, 5 other) undergraduates and one with 424 (240 men, 179 women, 5 other) Amazon Mechanical Turk (MTurk) workers, in which we randomly assigned participants to receive messages that matched or mismatched their self-schema. We also investigated whether differences across the Big Five personality traits, secure password knowledge, attitudes and behavior, need for cognition, and general risk-taking predicted the strength of passwords that participants created during the study. Multiple individual difference variables predicted password strength (i.e., conscientiousness, emotional stability, need for cognition, self-reported secure password knowledge, attitude, and behavior, and general risk-taking). MTurk workers had higher levels of cybersecurity knowledge and created stronger passwords than college students. The nudging messages did not lead to stronger passwords. Implications for strategies to increase the use of secure passwords are discussed.