Visible to the public Why people (don't) use password managers effectivelyConflict Detection Enabled

TitleWhy people (don't) use password managers effectively
Publication TypeConference Proceedings
Year of Publication2019
AuthorsSarah Pearman, Shikun Zhang, Lujo Bauer, Nicolas Christin, Lorrie Cranor
Conference NameFifteenth USENIX Conference on Usable Privacy and Security SOUPS'19
Pagination319-338
Date Published08/2019
PublisherUSENIX Association Berkeley, CA, USA ©2019
Conference LocationSanta Clara, CA, USA
ISBN Number978-1-939133-05-2
ISBN978-1-939133-05-2
Accession Number238303
Keywords2019: October, CMU, Human Behavior, Security Behavior Observatory, Understanding and Accounting for Human Behavior
Abstract

Security experts often recommend using password-management tools that both store passwords and generate random passwords. However, research indicates that only a small fraction of users use password managers with password generators. Past studies have explored factors in the adoption of password managers using surveys and online store reviews. Here we describe a semi-structured interview study with 30 participants that allows us to provide a more comprehensive picture of the mindsets underlying adoption and effective use of password managers and password-generation features. Our participants include users who use no password-specific tools at all, those who use password managers built into browsers or operating systems, and those who use separately installed password managers. Furthermore, past field data has indicated that users of built-in, browser-based password managers more often use weak and reused passwords than users of separate password managers that have password generation available by default. Our interviews suggest that users of built-in password managers may be driven more by convenience, while users of separately installed tools appear more driven by security. We advocate tailored designs for these two mentalities and provide actionable suggestions to induce effective password manager usage.

URLhttps://www.usenix.org/conference/soups2019/presentation/pearman
Citation Keynode-63198

Other available formats:

Pearman_Why_People_Dont_Cranor.pdf
AttachmentSize
bytes