Managing passwords securely and conveniently is still an open problem for many users. Existing research has examined users' password management strategies and identified pain points, such as security concerns, leading to insecure practices. We investigate how Blind and Low-Vision (BLV) users tackle this problem and how password managers can assist them. This paper presents the results of a qualitative interview study with N = 33 BLV participants. We found that all participants utilize password managers to some extent, which they perceive as fairly accessible. However, the adoption is mainly driven by the convenience of storing and retrieving passwords. The security advantages - generating strong, random passwords - were avoided mainly due to the absence of practical accessibility. Password managers do not adhere to BLV users' underlying needs for agency, which stem from experiences with inaccessible software and vendors who deprioritize accessibility issues. Underutilization of password managers leads BLV users to adopt insecure practices, such as reusing predictable passwords or resorting to 'security through obscurity' by writing important credentials in braille. We conclude our analysis by discussing the need to implement practical accessibility and usability improvements for password managers as a way of establishing trust and secure practices while maintaining BLV users' agency.
翻译:安全且便捷地管理密码对许多用户而言仍是一个悬而未决的难题。现有研究已探讨用户的密码管理策略并识别出痛点,例如安全顾虑导致的不安全实践。本研究调查视障与低视力用户如何应对此问题,以及密码管理器如何协助他们。本文呈现了一项针对 N = 33 位视障与低视力参与者的质性访谈研究结果。我们发现所有参与者均在一定程度上使用密码管理器,并认为其具有较好的可访问性。然而,采用密码管理器的主要驱动力在于存储与检索密码的便利性。其安全优势——生成高强度随机密码——则因缺乏实际可访问性而多被回避。密码管理器未能满足视障与低视力用户对自主性的根本需求,这种需求源于使用不可访问软件的经历以及供应商对可访问性问题的忽视。密码管理器的未充分利用导致视障与低视力用户采取不安全实践,例如重复使用可预测密码,或通过以盲文记录重要凭证的方式依赖“隐蔽式安全”。我们在分析结论中探讨了需改进密码管理器的实际可访问性与可用性,以此建立信任并促进安全实践,同时维护视障与低视力用户的自主性。