Passwords are the most common mechanism for authenticating users online. However, studies have shown that users find it difficult to create and manage secure passwords. To that end, passphrases are often recommended as a usable alternative to passwords, which would potentially be easy to remember and hard to guess. However, as we show, user-chosen passphrases fall short of being secure, while state-of-the-art machine-generated passphrases are difficult to remember. In this work, we aim to tackle the drawbacks of the systems that generate passphrases for practical use. In particular, we address the problem of generating secure and memorable passphrases and compare them against user chosen passphrases in use. We identify and characterize 72, 999 user-chosen in-use unique English passphrases from prior leaked password databases. Then we leverage this understanding to create a novel framework for measuring memorability and guessability of passphrases. Utilizing our framework, we design MASCARA, which follows a constrained Markov generation process to create passphrases that optimize for both memorability and guessability. Our evaluation of passphrases shows that MASCARA-generated passphrases are harder to guess than in-use user-generated passphrases, while being easier to remember compared to state-of-the-art machine-generated passphrases. We conduct a two-part user study with crowdsourcing platform Prolific to demonstrate that users have highest memory-recall (and lowest error rate) while using MASCARA passphrases. Moreover, for passphrases of length desired by the users, the recall rate is 60-100% higher for MASCARA-generated passphrases compared to current system-generated ones.
翻译:密码是在线用户认证最常用的机制。然而,研究表明用户难以创建和管理安全的密码。为此,密码短语常被推荐为可用的替代方案,其潜在优势在于既易记又难猜。但如我们所示,用户自选的密码短语在安全性上存在不足,而当前最先进的机器生成密码短语又难以记忆。本研究旨在解决实际应用中密码短语生成系统的缺陷,特别是针对生成安全且易记的密码短语这一问题,并将其与用户正在使用的自选密码短语进行对比。我们从先前泄露的密码数据库中识别并描述了72,999个由用户自选且实际使用的独特英语密码短语的特征。基于这一理解,我们构建了一个用于衡量密码短语可记忆性与可猜测性的新框架。利用该框架,我们设计了MASCARA系统,该系统遵循受约束的马尔可夫生成过程来创建在可记忆性与可猜测性上均实现优化的密码短语。对密码短语的评估表明,与用户实际生成的密码短语相比,MASCARA生成的密码短语更难被猜测;与当前最先进的机器生成密码短语相比,则更易于记忆。我们通过众包平台Prolific开展了两部分用户研究,证明用户在使用MASCARA密码短语时具有最高的记忆召回率(且错误率最低)。此外,对于用户期望长度的密码短语,MASCARA生成的密码短语的召回率比当前系统生成的高60%至100%。