Studying the Impact of Managers on Password Strength and Reuse
Sanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Sven Bugiel,, Michael Backes

TL;DR
This study systematically examines how password managers influence password strength and reuse, revealing they generally improve security but depend on user strategies and features like password generators.
Contribution
First large-scale analysis of password managers' impact on real user passwords, including entry methods and user strategies, providing new insights into their effectiveness.
Findings
Password managers generally improve password strength and uniqueness.
Benefits of password managers depend on user strategies and features.
Managers without password generators may worsen security issues.
Abstract
Despite their well-known security problems, passwords are still the incumbent authentication method for virtually all online services. To remedy the situation, end-users are very often referred to password managers as a solution to the password reuse and password weakness problems. However, to date the actual impact of password managers on password security and reuse has not been studied systematically. In this paper, we provide the first large-scale study of the password managers' influence on users' real-life passwords. From 476 participants of an online survey on users' password creation and management strategies, we recruit 170 participants that allowed us to monitor their passwords in-situ through a browser plugin. In contrast to prior work, we collect the passwords' entry methods (e.g., human or password manager) in addition to the passwords and their metrics. Based on our…
Peer Reviews
No public reviews on file for this paper yet. If you reviewed it on a platform where reviews are public (OpenReview, ICLR, NeurIPS, ICML), you can paste yours below so the community can read it here.
Videos
No videos yet. Explain this paper in a talk, walkthrough, or lecture? Add one.
Taxonomy
TopicsUser Authentication and Security Systems · Innovative Human-Technology Interaction · Privacy, Security, and Data Protection
