Figure 1. Athena Nike Temple on the Acropolis, February 2026.

Workshop & Non-Archival Paper

Poster: The Art of Password Creation

Blase Ur, Saranga Komanduri, Richard Shay, Stephanos Matsumoto, Lujo Bauer, Nicolas Christin, Lorrie Faith Cranor, Patrick Gage Kelley, Michelle L. Mazurek, Timothy Vidas

IEEE Symposium on Security and Privacy (S&P '13), Poster Session, 2013

May 2013

Abstract

Offline attacks, in which an adversary acquires a hashed password database and attempts to guess its contents, remain a significant threat to password security. Recent, highly publicized examples include LinkedIn, eHarmony, Sony, and Gawker. Because many users reuse passwords (exactly or with minor adjustments), these passwords can have value beyond the source site. In an effort to make passwords more resistant to guessing attacks, system administrators provide users with suggestions and/or requirements for the passwords they create. This guidance may include password-composition requirements, such as requiring the password to have a minimum length and include both letters and numbers. Other common strategies include using a meter to suggest or enforce composition rules, forbidding use of dictionary words, and forbidding common passwords. Many of these strategies were developed based on folk wisdom and educated guesses; until recently, most had not been empirically evaluated. In previously published work, we tested different password-composition policies using 12,000 passwords collected in an online study. We found that requiring long passwords with no other restrictions provides stronger guessing resistance than other tested policies, while being more palatable to users than other relatively strong policies. We also examined the effectiveness of password meters that nudge users toward stronger passwords without enforcing strict requirements. We found that while meters with a variety of visual appearances led to longer passwords, only meters that scored passwords stringently led to significantly more guess-resistant passwords. Meters that were too stringent, however, led to increased user annoyance and in some cases to users discounting the importance of satisfying the meter. Our recent work considers password strength from a new perspective: not only how guidance affects password strength, but why. We examine in depth how users create passwords, which words they use, and how the component pieces of passwords relate to each other.

Cite this paper
@inproceedings{ur2013poster,
  title     = {Poster: The Art of Password Creation},
  author    = {Ur, Blase and Komanduri, Saranga and Shay, Richard and Matsumoto, Stephanos and Bauer, Lujo and Christin, Nicolas and Cranor, Lorrie Faith and Kelley, Patrick Gage and Mazurek, Michelle L. and Vidas, Timothy},
  year      = {2013},
  booktitle = {IEEE Symposium on Security and Privacy (S&P '13), Poster Session, 2013},
  url       = {https://pgk.io/papers/2013-poster-the-art-of-password-creation/},
}
← Back to Papers