Rejecting the Death of Passwords: Advice for the Future
Computer Science and Information Systems, Tome 16 (2019) no. 1.

Voir la notice de l'article provenant de la source Computer Science and Information Systems website

Passwords have been a recurring subject of research ever since Morris and Thompson first pointed out their disadvantages in 1979. Several decades later, textual passwords remain to be the most used authentication method, despite the growing number of security breaches. In this article, we highlight technological advances that have the potential to ease brute-force attacks on longer passwords. We point out users’ persistently bad password creation and management practices, arguing that the users will be unable to keep up with the increasingly demanding security requirements in the future. We examine a set of real, user-generated passwords, and compare them to the passwords collected by Morris and Thompson. The results show that today’s passwords remain as weak as they were nearly four decades ago. We provide insight on how the current password security could be improved by giving recommendations to users, administrators, and researchers. We dispute the reiterated claim that passwords should be replaced, by exposing the alternatives’ weaknesses. Finally, we argue passwords will remain widespread until two conditions are met: First, a Pareto-improving authentication method is discovered, and second, the users are 21 motivated to replace textual passwords.
Keywords: authentication, password security, comparison
@article{CSIS_2019_16_1_a15,
     author = {Leon Bo\v{s}njak and Bo\v{s}tjan Brumen},
     title = {Rejecting the {Death} of {Passwords:} {Advice} for the {Future}},
     journal = {Computer Science and Information Systems},
     publisher = {mathdoc},
     volume = {16},
     number = {1},
     year = {2019},
     url = {http://geodesic.mathdoc.fr/item/CSIS_2019_16_1_a15/}
}
TY  - JOUR
AU  - Leon Bošnjak
AU  - Boštjan Brumen
TI  - Rejecting the Death of Passwords: Advice for the Future
JO  - Computer Science and Information Systems
PY  - 2019
VL  - 16
IS  - 1
PB  - mathdoc
UR  - http://geodesic.mathdoc.fr/item/CSIS_2019_16_1_a15/
ID  - CSIS_2019_16_1_a15
ER  - 
%0 Journal Article
%A Leon Bošnjak
%A Boštjan Brumen
%T Rejecting the Death of Passwords: Advice for the Future
%J Computer Science and Information Systems
%D 2019
%V 16
%N 1
%I mathdoc
%U http://geodesic.mathdoc.fr/item/CSIS_2019_16_1_a15/
%F CSIS_2019_16_1_a15
Leon Bošnjak; Boštjan Brumen. Rejecting the Death of Passwords: Advice for the Future. Computer Science and Information Systems, Tome 16 (2019) no. 1. http://geodesic.mathdoc.fr/item/CSIS_2019_16_1_a15/