Investigating the distribution of password choices
- 16 April 2012
- conference paper
- conference paper
- Published by Association for Computing Machinery (ACM)
- p. 301-310
- https://doi.org/10.1145/2187836.2187878
Abstract
In this paper we will look at the distribution with which passwords are chosen. Zipf's Law is commonly observed in lists of chosen words. Using password lists from four different on-line sources, we will investigate if Zipf's law is a good candidate for describing the frequency with which passwords are chosen. We look at a number of standard statistics, used to measure the security of password distributions, and see if modelling the data using Zipf's Law produces good estimates of these statistics. We then look at the the similarity of the password distributions from each of our sources, using guessing as a metric. This shows that these distributions provide effective tools for cracking passwords. Finally, we will show how to shape the distribution of passwords in use, by occasionally asking users to choose a different passwordKeywords
This publication has 12 references indexed in Scilit:
- Password Strength: An Empirical AnalysisPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2010
- Power-Law Distributions in Empirical DataSiam Review, 2009
- Randomness Requirements for Security2005
- Guesswork and EntropyIEEE Transactions on Information Theory, 2004
- Guessing and entropyPublished by Institute of Electrical and Electronics Engineers (IEEE) ,2002
- An inequality on guessing and its application to sequential decodingIEEE Transactions on Information Theory, 1996
- Unified login with pluggable authentication modules (PAM)Published by Association for Computing Machinery (ACM) ,1996
- Monte Carlo sampling methods using Markov chains and their applicationsBiometrika, 1970
- Monte Carlo Sampling Methods Using Markov Chains and Their ApplicationsBiometrika, 1970
- Equation of state calculations by fast computing machinesPublished by Office of Scientific and Technical Information (OSTI) ,1953