“It Basically Started Using Me:” An Observational Study of Password Manager Usage

要旨

There is limited information regarding how users employ password managers in the wild and why they use them in that manner. To address this knowledge gap, we conduct observational interviews with 32 password manager users. Using grounded theory, we identify four theories describing the processes and rationale behind participants' usage of password managers. We find that many users simultaneously use both a browser-based and a third-party manager, using each as a backup for the other, with this new paradigm having intriguing usability and security implications. Users also eschew generated passwords because these passwords are challenging to enter and remember when the manager is unavailable, necessitating new generators that create easy-to-enter and remember passwords. Additionally, the credential audits provided by most managers overwhelm users, limiting their utility and indicating a need for more proactive and streamlined notification systems. We also discuss mobile usage, adoption and promotion, and other related topics.

著者
Sean Oesch
University of Tennessee, Knoxville, Tennessee, United States
Scott Ruoti
University of Tennessee, Knoxville, Tennessee, United States
James Simmons
University of Tennessee, Knoxville, Tennessee, United States
Anuj Gautam
University of Tennessee, Knoxville, Tennessee, United States
論文URL

https://dl.acm.org/doi/abs/10.1145/3491102.3517534

動画

会議: CHI 2022

The ACM CHI Conference on Human Factors in Computing Systems (https://chi2022.acm.org/)

セッション: Social media, Privacy, and Mitigations

395
5 件の発表
2022-05-02 23:15:00
2022-05-03 00:30:00