120 likes | 238 Vues
Passwords can be a major headache for users, especially on mobile devices where inputs are cumbersome. The issues include slow entry, frequent mistakes, low recall rates, and the insecurity of resets. PINs offer speed but lack security. This article delves into the usability and recall challenges of passwords, proposes solutions like auto-correction, and highlights how understanding these issues can lead to more usable and secure authentication methods. We can significantly improve password systems by addressing fundamental questions about user experience.
E N D
Fastwords Markus Jakobsson RujAkavipat
A Bit about Authentication Difficulty customizing settings Difficulty authenticating Short battery life Lack of coverage 1 2 3 4 5 Slow Web connection Poor voice quality Small screen size
Problems • People hate passwords – especially on handsets • Slow to enter … • … and then you realize you mistyped something! • At the same time, recall rates are low for passwords • … and reset is difficult / insecure / expensive • PINs are faster … • … but not very secure • … and reuse is rampant Jakobsson/Akavipat: www.fastword.me
Understanding usability issues Q. Why are passwords more painful than text? A. Text uses auto-correction/completion! Jakobsson/Akavipat: www.fastword.me
Understanding recall issues Q. Why are (good) passwords hard to recall? A. Good passwords are weird! (Ebbinghausen, 1885) Jakobsson/Akavipat: www.fastword.me
A stab at a solution Not so secure, you say? Approx. 64k words only. frog frof fro fr f frof Auto correct works Jakobsson/Akavipat: www.fastword.me
Improved solution frog flat work Auto correct works Jakobsson/Akavipat: www.fastword.me
Looking at speed Jakobsson/Akavipat: www.fastword.me
Looking at security Average fastword Average password Jakobsson/Akavipat: www.fastword.me
Forgot fastword? Hint: first word EFFECTIVE RECALL: 0.36+(1-0.36)*0.48=0.67 …. 67% Jakobsson/Akavipat: www.fastword.me
Forgot fastword? Hint: first word Average password Average fastword Jakobsson/Akavipat: www.fastword.me
Big-picture insight We can improve as basic things as passwords – if we ask “why”. Jakobsson/Akavipat: www.fastword.me