The Password Paradox: "Rememberability" vs. "Guessability." Entropy and Human Factors in Password Creation

CSEF · 2012 Behavioral & Social Sciences First Award

Overview

Objectives/Goals To determine whether there is a connection between the human factor in password composition/usage and the relative entropy of the password. Methods/Materials No tangible materials were used. However, the following web based software utilities were used to create webpages and store data: -cloud-based Linux web server including: --PHP scripting language --Limesurvey authoring application -cloud-based Database server including MySQL database server I created a webpage for the purpose of collecting email addresses and passwords. Participants were sent an email message requesting their participation in the project. The message included a link to the webpage which asked the participants to register using an email address and password. Three weeks later, a second email message was sent to participants who registered in the first step. The message included a link to a second webpage incorporating a 5 question survey regarding the participant's password. Results Passwords were collected from 281 initial participants and survey results were collected from 170 returning participants. With regard to strength of the 281 initial passwords, entropy values ranged from 0 to 82.72 bits. Average entropy was 36.69 bits. Median entropy was 36.19 bits. 11% of all passwords consisted of 6 lowercase letters. Furthermore, 41% of all passwords consisted only of lowercase letters. 33% of all passwords consisted of lowercase letters and numbers. Only 1 of the 281 passwords consisted of the maximum sized character set, including uppercase letters, lowercase letters, numbers, and special characters. Conclusions/Discussion With regard to frequency, there were only 9 instances of recurrence. With regard to "rememberability," 134 of 170 returning participants thought they remembered their passwords, but only 72 of those 134 actually remembered. With regard to how people remembered their passwords, of the 170 returning participants, 16 wrote them down somewhere, 127 used the same password that they have used on other websites, 19 used passwords that they associated with this project, and 12 used some other mnemonic device. With regard to relative password strength, most people did not estimate their password strength correctly. In relation to my hypothesis, I concluded that the initial set of passwords did exhibit low

Summary statement

The effects of human factors on "rememberability" and "guessability" (calculated entropy) of passwords.

Help received

Father helped organize data and solicit participants. Mother helped with project display board and also solicited participants.

Awards (1)

Competition history

  • CSEF 2012 Behavioral & Social Sciences · Entry S0414

Resources

Related projects

Closest projects by meaning, across every fair and year in the corpus.

Browse more like this

Source: California Science & Engineering Fair public projects

Save projects to your library

Sign in with Google to keep track of projects you find interesting, organized into folders. An account also raises your daily allowance for “Has this been done?”, and lets you create a key for the MCP server with a much higher limit than anonymous use. Browsing stays public.

Continue with Google