Passwords, a first line of defense against unauthorized access, must be secure and memorable. However, people often struggle to create secure passwords they can recall. To address this problem, we design Password inspiration by eXploring information (PiXi), a novel approach to nudge users towards creating secure passwords. PiXi is the first of its kind that employs a password creation nudge to support users in the task of generating a unique secure password themselves. PiXi prompts users to explore unusual information right before creating a password, to shake them out of their typical habits and thought processes, and to inspire them to create unique (and therefore stronger) passwords. PiXi's design aims to create an engaging, interactive, and effective nudge to improve secure password creation. We conducted a user study ($N=238$) to compare the efficacy of PiXi to typical password creation. Our findings indicate that PiXi's nudges do influence users' password choices such that passwords are significantly longer and more secure (less predictable and guessable).
翻译:密码作为抵御未授权访问的第一道防线,必须兼具安全性与可记忆性。然而,人们往往难以创建既安全又能回忆的密码。针对这一问题,我们设计了"通过信息探索实现密码灵感"(PiXi)这一创新方法,通过助推机制引导用户创建安全密码。PiXi首次采用密码创建助推技术,支持用户自主生成独特的安全密码。PiXi在密码创建前引导用户探索非常规信息,打破其固有习惯与思维模式,激发其创建独特(因而更强大)的密码。PiXi的设计致力于打造一种兼具参与性、互动性与有效性的助推方式,以提升安全密码的创建效果。我们开展了用户研究(N=238),将PiXi与常规密码创建方式的效果进行对比。结果表明,PiXi的助推机制确实影响了用户的密码选择,使密码长度显著增加,安全性(可预测性与可猜测性)显著提升。