five

On the user friendliness of password creation policy designs in the wild

收藏
中国科学数据2026-03-05 更新2026-04-25 收录
下载链接:
https://www.sciengine.com/AA/doi/10.1007/s11432-025-4594-4
下载链接
链接失效反馈
官方服务:
资源简介:
Password creation policy designs (PCPDs) are the design of site interfaces for user password registration. Much attention has been paid to the security of password policies, but there is a lack of research on the presentation of PCPDs (i.e., password rule (PR), password registration error message (PREM), and password strength meter (PSM)). To fill this gap, we, for the first time, evaluate the user-friendliness of PCPDs across 163 Chinese and 202 U.S. websites. We define two key criteria for PCPD user-friendliness: friendly timing and friendly explanation. Our results present a concerning picture: only 8.6% (14/163) of Chinese sites and 3.5% (7/202) of U.S. sites meet our user-friendliness criteria for PCPDs. To validate our user-friendly PCPDs, we conduct a survey with 249 U.S. and Chinese participants, confirming that over 75% of participantssupport our criteria for optimal password creation interfaces. Furthermore, we conduct a correlation analysis of the security of the PCPD and corresponding password datasets from eleven Chinese and U.S. websites. We reveal that an unfriendly PCPD increases the time for password creation and login, but does not improve password security. Our work highlights that leading services need substantial improvements in the usability of PCPDs during the user registration process.
创建时间:
2025-09-26
二维码
社区交流群
二维码
科研交流群
商业服务