Pithayuth Charnsethikul (University of Southern California), Anushka Fattepurkar (University of Southern California), Dipsy Desai (University of Southern California), Gale Lucas (University of Southern California), Jelena Mirkovic (University of Southern California)

We replicated the study by Mayer et al. [1] on password habits and password manager (PM) usage at a large private US university. We conducted an online survey (n=437) and found high awareness (96%) and usage (94%) of PMs, but limited use of password generation (26%) and substantial password reuse, with participants reusing more than half of their passwords. These findings are consistent with the original study. However, we found that participants were unlikely to adopt a free third-party PM offered by the university, contrary to the original findings. Extending the original study, we found that awareness of the free PM was low: only 35% knew about it, and its adoption was even lower, at just 15%. We also found that faculty had the strongest password habits, while students had the weakest. Based on our findings, we provide recommendations for increasing the use of password generation features, broadening adoption of an institution-provided PM, and guiding future replication efforts.

View More Papers

Case Study – Exploring Children’s Password Knowledge and Practices

Yee-Yin Choong, Mary Theofanos (NIST); Karen Renaud, Suzanne Prior (Abertay University)

Read More

On Borrowed Time: Measurement-Informed Understanding of the NTP Pool's...

Robert Beverly (San Diego State University), Erik Rye (Johns Hopkins University)

Read More

Poster: From Earth to Orbit: A Quantum-Secure Authentication Key-Establishment...

Salman Shamshad (University of Bristol, Bristol, United Kingdom), Waqas Bin Abbas (University of Bristol, Bristol, United Kingdom), Sana Belguith (University of Bristol, Bristol, United Kingdom), Lucy Berthoud (University of Bristol, Bristol, United Kingdom)

Read More