skip to main content
10.1145/1518701.1518837acmconferencesArticle/Chapter ViewAbstractPublication PageschiConference Proceedingsconference-collections
research-article

A comprehensive study of frequency, interference, and training of multiple graphical passwords

Published:04 April 2009Publication History

ABSTRACT

Graphical password systems have received significant attention as one potential solution to the need for more usable authentication, but nearly all prior work makes the unrealistic assumption of studying a single password. This paper presents the first study of multiple graphical passwords to systematically examine frequency of access to a graphical password, interference resulting from interleaving access to multiple graphical passwords, and patterns of access while training multiple graphical passwords. We find that all of these factors significantly impact the ease of authenticating using multiple facial graphical passwords. For example, participants who accessed four different graphical passwords per week were ten times more likely to completely fail to authenticate than participants who accessed a single password once per week. Our results underscore the need for more realistic evaluations of the use of multiple graphical passwords, have a number of implications for the adoption of graphical password systems, and provide a new basis for comparing proposed graphical password systems.

Skip Supplemental Material Section

Supplemental Material

1518946_1.mp4

mp4

126.5 MB

References

  1. Adams, A. and Sasse, M.A. Users are not the enemy. Communications of the ACM, (CACM Dec 1999), 40--46. Google ScholarGoogle ScholarDigital LibraryDigital Library
  2. Adams, A., Sasse, M.A., and Lunt, P. Making passwords secure and usable. Proceedings of HCI on People and Computers XII, (HCI 1997), 1--19. Google ScholarGoogle ScholarDigital LibraryDigital Library
  3. BBC News. UN warns on password 'explosion'. http://news.bbc.co.uk/2/hi/technology/6199372.stm.Google ScholarGoogle Scholar
  4. Brostoff, S. and Sasse, M.A. Are PassfacesTM more usable than passwords? A field trial investigation. Proceedings of HCI on People and Computers XIV, (HCI 2000), 405--424.Google ScholarGoogle ScholarCross RefCross Ref
  5. Chiasson, S., Biddle, R., and van Oorschot, P.C. A second look at the usability of click-based graphical passwords. Proceedings of the Symposium on Usable Privacy and Security, (SOUPS 2007), 1--12. Google ScholarGoogle ScholarDigital LibraryDigital Library
  6. Davis, D., Monrose, F., and Reiter, M. On user choice in graphical password schemes. Proceedings of the Conference on USENIX Security Symposium, (2005), 11--11. Google ScholarGoogle ScholarDigital LibraryDigital Library
  7. DeAngeli, A., Coventry, L., Johnson, G., and Renaud, K. Is a picture really worth a thousand words? Exploring the feasibility of graphical authentication systems. International Journal of Human-Computer Studies, v. 63, n. 1-2 (2005), 128--152. Google ScholarGoogle ScholarDigital LibraryDigital Library
  8. Dhamija, R. and Perrig, A. Déjà vu: A user study using Images for Authentication. Proceedings of the Conference on USENIX Security Symposium, (2000), 4--4. Google ScholarGoogle ScholarDigital LibraryDigital Library
  9. Dunphy, P., Nicholson, J., Olivier, P. Securing Passfaces for Description. Proceedings of the Symposium on Usable Privacy and Security, (SOUPS 2007), 24--35. Google ScholarGoogle ScholarDigital LibraryDigital Library
  10. Ensor, B. How Consumers Remember Passwords. Forrester Research Report, June 2, 2004.Google ScholarGoogle Scholar
  11. The Face of Tomorrow Face Dataset. http://www.flickr.com/photos/istanbulmike/sets/72157594201837268/.Google ScholarGoogle Scholar
  12. Florencio, D. and Herley, C. A large-scale study of web password habits. Proceedings of the International Conference on World Wide Web, (WWW 2007), 657--666. Google ScholarGoogle ScholarDigital LibraryDigital Library
  13. Gaw, S. and Felten, E. Password management strategies for online accounts. Proceedings of the Symposium on Usable Privacy and Security, (SOUPS 2006), 44--55. Google ScholarGoogle ScholarDigital LibraryDigital Library
  14. Ives, B., Walsh K.R., and Schneider, H. The domino effect of password reuse. In Communications of the ACM, (CACM Apr 2004), 75--78. Google ScholarGoogle ScholarDigital LibraryDigital Library
  15. Moncur, W. and Leplâtre, G. Pictures at the ATM: exploring the usability of multiple graphical passwords. Proceedings of SIGCHI Conference on Human Factors in Computing Systems, (CHI 2007), 887--894. Google ScholarGoogle ScholarDigital LibraryDigital Library
  16. Morris, R. and Thompson, K. Password security: A case history. Communications of the ACM (CACM Nov 1979), 594--497. Google ScholarGoogle ScholarDigital LibraryDigital Library
  17. PassfacesTM. http://www.realuser.com/Google ScholarGoogle Scholar
  18. Rock, I.,&Engelstein, P. (1959). A study of memory for visual form. American Journal of Psychology (1959), 72, 221--229.Google ScholarGoogle Scholar
  19. Standing, L. Learning 10,000 pictures. Quarterly Journal of Experimental Psychology 25 (1973), 207--222.Google ScholarGoogle Scholar
  20. Tari, F., Ozok A.A., and Holden, S.H. A comparison of perceived and real shoulder-surfing risks between alphanumeric and graphical passwords. Proceedings of the Symposium on Usable Privacy and Security, (SOUPS 2006), 56--66. Google ScholarGoogle ScholarDigital LibraryDigital Library
  21. Valentine, T. An evaluation of the PassfacesTM personal authentication system. Goldsmiths College Technical Report, 1998.Google ScholarGoogle Scholar
  22. Valentine, T. Memory for PassfacesTM after a long delay. Goldsmiths College Technical Report, 1999.Google ScholarGoogle Scholar
  23. Wiedenbeck, S., Waters, J., Birget, J.C., Brodskiy, A., and Memon, N. PassPoints: Design and longitudinal evaluation of a graphical password system. International Journal of Human-Computer Studies, v. 63, n. 1--2, (2005), 102--127. Google ScholarGoogle ScholarDigital LibraryDigital Library

Index Terms

  1. A comprehensive study of frequency, interference, and training of multiple graphical passwords

    Recommendations

    Comments

    Login options

    Check if you have access through your login credentials or your institution to get full access on this article.

    Sign in
    • Published in

      cover image ACM Conferences
      CHI '09: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
      April 2009
      2426 pages
      ISBN:9781605582467
      DOI:10.1145/1518701

      Copyright © 2009 ACM

      Permission to make digital or hard copies of all or part of this work for personal or classroom use is granted without fee provided that copies are not made or distributed for profit or commercial advantage and that copies bear this notice and the full citation on the first page. Copyrights for components of this work owned by others than ACM must be honored. Abstracting with credit is permitted. To copy otherwise, or republish, to post on servers or to redistribute to lists, requires prior specific permission and/or a fee. Request permissions from [email protected]

      Publisher

      Association for Computing Machinery

      New York, NY, United States

      Publication History

      • Published: 4 April 2009

      Permissions

      Request permissions about this article.

      Request Permissions

      Check for updates

      Qualifiers

      • research-article

      Acceptance Rates

      CHI '09 Paper Acceptance Rate277of1,130submissions,25%Overall Acceptance Rate6,199of26,314submissions,24%

      Upcoming Conference

      CHI '24
      CHI Conference on Human Factors in Computing Systems
      May 11 - 16, 2024
      Honolulu , HI , USA

    PDF Format

    View or Download as a PDF file.

    PDF

    eReader

    View online with eReader.

    eReader