Abstract—We report on the largest corpus of user-chosen passwords ever studied, consisting of anonymized password histograms representing almost 70 million Yahoo! users, mit-igating privacy concerns while enabling analysis of dozens of subpopulations based on demographic factors and site usage characteristics. This large data set motivates a thorough sta-tistical treatment of estimating guessing difficulty by sampling from a secret distribution. In place of previously used metrics such as Shannon entropy and guessing entropy, which cannot be estimated with any realistically sized sample, we develop partial guessing metrics including a new variant of guesswork parameterized by an attacker’s desired success rate. Our new metric is comparative...
In spite of the growing adoption of two factor authentication systems, sometimes combined with hardw...
Parameterized password guessability—how many guesses a particular cracking algorithm with particular...
While trawling online/offline password guessing has been intensively studied, only a few studies hav...
Authenticating humans to computers remains a notable weak point in computer security despite decades...
Authenticating humans to computers remains a notable weak point in computer security despite decades...
password strength by simulating password-cracking algorithms Intro How effectively several heuristic...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Parameterized password guessability—how many guesses a particular cracking algorithm with particular...
<p>In an effort to improve security by preventing users from picking weak passwords, system administ...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Despite considerable research on passwords, empirical studies of password strength have been limited...
<p>Despite considerable research on passwords, empirical studies of password strength have been limi...
Despite considerable research on passwords, empirical studies of password strength have been limited...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Despite considerable research on passwords, empirical studies of password strength have been limited...
In spite of the growing adoption of two factor authentication systems, sometimes combined with hardw...
Parameterized password guessability—how many guesses a particular cracking algorithm with particular...
While trawling online/offline password guessing has been intensively studied, only a few studies hav...
Authenticating humans to computers remains a notable weak point in computer security despite decades...
Authenticating humans to computers remains a notable weak point in computer security despite decades...
password strength by simulating password-cracking algorithms Intro How effectively several heuristic...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Parameterized password guessability—how many guesses a particular cracking algorithm with particular...
<p>In an effort to improve security by preventing users from picking weak passwords, system administ...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Despite considerable research on passwords, empirical studies of password strength have been limited...
<p>Despite considerable research on passwords, empirical studies of password strength have been limi...
Despite considerable research on passwords, empirical studies of password strength have been limited...
Password guessing is one of the most common methods an attacker will use for compromising end users....
Despite considerable research on passwords, empirical studies of password strength have been limited...
In spite of the growing adoption of two factor authentication systems, sometimes combined with hardw...
Parameterized password guessability—how many guesses a particular cracking algorithm with particular...
While trawling online/offline password guessing has been intensively studied, only a few studies hav...