User-chosen passwords remain essential to online security, and yet people continue to choose weak, insecure passwords. In this work, we investigate whether prospect theory, a behavioral model of how people evaluate risk, can provide insights into how users choose passwords and whether it can motivate new designs for password selection mechanisms that will nudge users to select stronger passwords. We ran a user study with 762 participants, and we found that an intervention guided by prospect theory -- which leverages the reference-dependence effect by framing selecting weak passwords as a loss relative to choosing a stronger password -- causes approximately 25% of users to improve the strength of their password (significantly more than alternative interventions) and reduced the final number of weak passwords by approximately 25%. We also evaluate the relation between user behavior and users' mental models of hacking and password attacks. These results provide guidance for designing and implementing account registration mechanisms that will significantly improve the strength of user-selected passwords, thereby leveraging insights from prospect theory to improve the security of systems that use password-based authentication.
翻译:用户选择的密码对于在线安全仍然至关重要,然而人们仍然选择薄弱的、不安全的密码。在这项工作中,我们调查前景理论(一种人们如何评价风险的行为模式)是否能够提供洞察力,了解用户如何选择密码,以及它能否激发密码选择机制的新设计,从而促使用户选择更强的密码。我们开展了一项用户研究,有762人参加,我们发现,以前景理论为指南的干预 — — 通过选择弱的密码作为选择更强的密码的损失来利用参考依赖效应 — — 大约25%的用户提高了密码的强度(大大超过替代干预措施),并将弱密码的最后数量减少了大约25%。我们还评估了用户行为与用户黑客和密码攻击心理模式之间的关系。这些结果为设计和实施账户登记机制提供了指导,这将大大提高用户选择的密码的强度,从而利用前景理论的见解来提高使用密码认证系统的安全性。