Influence of Mobile Devices on Password Composition and Authentication Performance Paper by: Emanuel von Zezschwitz, University of Munich, Germany Alexander De Luca, University of Munich, Germany Heinrich Hussmann, University of Munich, Germany
Pre-study assessing password performance
Independent variables 3 devices Smartphone (Apple iPhone 5) Tablet (Apple iPad 4 10”) PC (Windows PC with 24” display and Cherry JK-0100DE keyboard) 3 password categories Dictionary (ex. casanova) Internet (ex. Yasana75) Random (ex.
Procedure Training: enter short text, no logging Typing speed: enter text (different for each device) Authentication: enter 4 password of each category Repeat until all 3 devices had been tested Participants 24 experienced users 20 males; 4 females Average age of 25
Results Typing speed Significantly influenced by the device Smartphone slowest, PC fastest Slower when string complexity increases Error rate Significantly influenced by the device Smartphone is error prone
Large scale study choice and perception
Procedure Password creation task asked to select a password for an imaginary service they would frequently use on the current device Participants 149 tablet users; 149 PC users; 152 smartphone users 238 males; 212 females Average age of 31 years
Results Password Significantly influenced by the device Smartphone shortest passwords, PC longest passwords Tablet and smartphone use fewer upper case letters Errors Significantly influenced by the device 50% of all errors occurred on smartphones
Conclusion
Mobile devices have significant impact on alphanumeric passwords Slower input More errors Users opt for easy and fast to enter passwords Limiting factors of password security Used to be memorability now it is input effort Should provide adjusted authentication methods