Password Policy Effects on Entropy and Recall: Research in Progress
Jim Marquardson · Americas Conference on Information Systems · 2012
Passwords are commonly used for authentication. System architects generally put in place password poli cies that define the required length of a password, the complexity requi rements of the password, and the expiration (if eve r) of the password. Password policies are designed with the intent of h elping users choose secure passwords, and in the ca se of password expiration, limit the potential damage of a comprom ised password. However, password policies can have unintended consequences that could potentially undermine their security aims. Based on the theory of cognitive lo ad, it is hypothesized that password policy elements increase extraneous l oad, which can result in high entropy passwords, bu t to the detriment of recall. It is further hypothesized that certain pas sword policy elements can still help increase entro py, while minimizing the negative impact on recall. An experiment to test th e hypotheses and determine both a secure and user f riendly password policy is put forward.