A Large-scale Analysis of the Mnemonic Password Advice
نویسندگان
چکیده
How to choose a strong but still easily memorable password? An often recommended advice is to memorize a random sentence (the mnemonic) and to concatenate the words’ initials: a so-called mnemonic password. The paper in hand analyzes the effectiveness of this advice—in terms of the obtained password strength—and sheds light on various related aspects. While it is infeasible to obtain a sufficiently large sample of human-chosen mnemonics, the password strength depends only on the distribution of certain character probabilities. We provide several pieces of evidence that these character probabilities are approximately the same for human-chosen mnemonics and sentences from a web crawl and exploit this connection for our analyses. The presented analyses are independent of cracking software, avoid privacy concerns, and allow full control over the details of how passwords are generated from sentences. In particular, the paper introduces the following original research contributions: (1) construction of one of the largest corpora of human-chosen mnemonics, (2) construction of two web sentence corpora from the 27.3 TB ClueWeb12 web crawl, (3) demonstration of the suitability of web sentences as substitutes for mnemonics in password strength analyses, (4) improved estimation of password probabilities by position-dependent language models, and (5) analysis of the obtained password strength using web sentence samples of different sentence complexity and using 18 generation rules for mnemonic password construction. Our findings include both expected and less expected results, among others: mnemonic passwords from lowercase letters only provide comparable strength to mnemonic passwords that exploit the 7-bit visible ASCII character set, less complex mnemonics reduce password strength in offline scenarios by less than expected, and longer mnemonic passwords provide more security in an offline but not necessarily in an online scenario. When compared to passwords generated by uniform sampling from a dictionary, distributions of mnemonic passwords can reach the same strength against offline attacks with less characters.
منابع مشابه
Testing Computer-Aided Mnemonics and Feedback for Fast Memorization of High-Value Secrets
People sometimes require very strong passwords for high-value accounts (e.g., master passwords for password managers and encryption keys), but often cannot create these strong passwords. Assigning them provably strong secrets is one solution, and prior work has shown that people can learn these assigned secrets through rote learning, though learning the secrets takes some time and they are quic...
متن کاملThe memorability and security of passwords -- some empirical results
There are many things that are ‘well known’ about passwords, such as that uers can’t remember strong passwords and that the passwords they can remember are easy to guess. However, there seems to be a distinct lack of research on the subject that would pass muster by the standards of applied psychology. Here we report a controlled trial in which, of four sample groups of about 100 first-year stu...
متن کاملGenerating Memorable Mnemonic Encodings of Numbers
The major system is a mnemonic system that can be used to memorize sequences of numbers. In this work, we present a method to automatically generate sentences that encode a given number. We propose several encoding models and compare the most promising ones in a password memorability study. The results of the study show that a model combining part-of-speech sentence templates with an n-gram lan...
متن کاملInformation Security Applications of Natural Language Processing Techniques a Dissertation
Topkara, Umut Ph.D., Purdue University, August, 2007. Information Security Applications of Natural Language Processing Techniques . Major Professor: Mikhail J. Atallah. In this thesis we investigate applications of natural language processing (NLP) techniques to information security problems. We present our results in this direction for two important areas: password authentication, and informat...
متن کاملIndividuality in Higher Education: The Use of the Multiple-Mnemonic Method to Enhance ESP Students' Vocabulary Development (Depth and Size) and Retention
Vocabulary learning is considered to be the most comprehensive and the most difficult part of language learning for all the students especially for ESP students. These students complain that vocabulary items are too many and are easily forgotten after they are learned. Mnemonic devices, a group of mental strategies, are developed to facilitate vocabulary learning and retention for such students...
متن کامل