Keywords

passwords, passphrases, authentication, security, memory, usability, user behavior

Abstract

Although the use of multiple methods of user authentication for IT system increases security, passwords are often the only credential required for access. Consequently, the challenge is to discover ways to improve password strength without impairing usability. Longer pass “phrases” have received increased attention as a solution to this challenge because they are potentially more resistant to attacks yet are easy to remember. Recent evidence, however, suggests that passphrases increase the likelihood of typographical errors resulting in login failures and negative user perceptions. This paper presents experimental results that demonstrate well-designed passphrases do not increase login failures and, thereby, generate positive user perceptions. Implications are drawn to help IT managers develop effective IT security policies in utilizing passphrases to improve authentication and to assist researchers in identifying avenues for future research.

Original Publication Citation

"A Behavioral Analysis of Passphrase Design and Effectiveness", Journal of the Association for Information Systems, Edition 2, Volume 10, 2009

Document Type

Peer-Reviewed Article

Publication Date

2009

Publisher

Journal of the Association for Information Systems

Language

English

College

Marriott School of Business

Department

Information Systems Management

University Standing at Time of Publication

Associate Professor

Share

COinS