Assessing password guidance and enforcement on leading websites

Steven Furnell · Computer Fraud & Security · 2011

For more than five decades, passwords have been the dominant means of user authentication for IT systems and are now used on a daily basis by millions of users worldwide.1 Their significance is such that recent research has suggested 11% of people are now leaving (or planning to leave) details of Internet passwords in their wills so that they are able to pass on valuable online content to loved ones.2 Meanwhile, in Italy the use of passwords has even become a matter of law, with privacy legislation laying down some minimum requirements (including that, where permitted by the system, they should be at least eight characters long, and be changed every six months).3 Although passwords continue to dominate the field in user authentication, their use is accompanied by a significant lack of awareness and bad practice on the part of users. So how do websites go about providing advice and guidance when it comes to choosing passwords? Prof Steven Furnell at the University of Plymouth offers new research, studying 10 leading websites, and assesses how well they support and encourage the use of strong passwords. He finds there are some potentially surprising limitations and inconsistencies, and few of the market-leading sites are failing to show the way in terms of promoting good security practice.

Read the paper · More papers on PaperTik