Decoding developer password patterns: A comparative analysis of password extraction and selection practices

Nikolaos Lykousas, Constantinos Patsakis · Computers & Security · 2024

Passwords play a crucial role in authentication, ensuring that only authorised entities can access sensitive information. However, user password choices are often weak and predictable, making them susceptible to cyber-attacks. Additionally, hard-coded credentials in source code can expose organisations and infrastructure to significant risks. This paper explores the patterns of passwords used by developers, examining their similarities to those of typical users. We also investigate the efficacy of large language models (LLMs) in identifying hard-coded credentials in source code. Our findings suggest that developers foster more complex and, hence, more secure password selection patterns than regular users. Nevertheless, they can use worse patterns when the context allows them. The latter, combined with the ample commits in public code repositories containing secrets, exemplifies the need for more targeted awareness campaigns and tighter integration of code security tools in the development lifecycle. Finally, we explore the capacity of LLMs to detect hard-coded credentials, highlighting their differences and limitations.

Read the paper · More papers on PaperTik