首页> 外文会议>Information Security for South Africa Conference >Enriched nudges lead to stronger password replacements … but implement mindfully
【24h】

Enriched nudges lead to stronger password replacements … but implement mindfully

机译:丰富的讽刺导致更强大的密码更换......但是明显地实施

获取原文

摘要

People usually respond to enforced changes caused by password expiry by making each successive password weaker. This is because the effort involved in memorising a password cannot be amortised over a period of time. To ensure retention they use a password they know they will not forget. This paper explores the password-changing behaviour of the participants exposed to an enriched nudge intervention. The enriched nudge combined a traditional nudge (manipulation of the “choice architecture” (user interface)) with a carrot (utility offered by a variable password expiry period, depending on the strength of the password) and a prod (frequent reminders). A longitudinal study discovered that, contrary to expectations and usual practice, participants chose stronger passwords when they replaced them. This finding suggests that changing passwords is more cognitively demanding and effortful than the memorising of a single strong password. Moreover, allowing people to engage in the latter to avoid the former has the effect of improving password strength overall. The paper concludes with an admonition for implementers to be aware of the burden imposed on users by password aging, and urging them to apply it only when the risk justifies imposing this burden.
机译:人们通常通过使每次连续密码较弱,响应由密码到期造成的强制更改。这是因为在一段时间内无法摊销密码所涉及的努力。为确保保留,他们使用他们知道他们不会忘记的密码。本文探讨了暴露于丰富的轻推干预的参与者的密码改变行为。浓缩的轻推与胡萝卜(可变密码到期时期提供的“选择架构”(用户界面))的传统轻推(使用可变密码到期时期提供的实用程序,具体取决于密码的强度)和频繁提醒)。纵向研究发现,与期望和通常的做法相反,当他们更换它们时,参与者选择了更强的密码。此发现表明,更改密码更加认知,而不是记住单个强密码的记忆。此外,允许人们从事后者以避免前者具有改善密码强度的效果。本文征服了实施者,以了解密码老化对用户施加的负担,并敦促他们仅在施加这种负担的风险证明时才申请它。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号