Questioning a security assumption: Are unique passwords harder to remember than reused or modified passwords?
Naomi Woods, Mikko T. Siponen · Computers & Security · 2025
Many users have serious problems remembering all their passwords. Even with available technologies such as, password managers, many users choose to rely solely on their memory. Managing multiple strong passwords lead many to adopt insecure password practices, for example, reusing and modifying passwords for multiple organizational and personal accounts. These insecure behaviors are widespread, resulting in substantial security breaches and financial losses. Numerous users reuse and modify their passwords believing it will help their password memorability. However, human memory theory would suggest the contrary. Therefore, to test this premise, two longitudinal studies (12 and 10 weeks) were conducted to examine password recall and memory interference from over 20,000 recalled passwords. Our results challenge the common belief that unique passwords are hard to remember; suggesting that they can be more memorable than modified or reused passwords. These findings have important implications as creating unique passwords is considered good security practice, while simultaneously improving password memorability, which could reduce insecure password behaviors and the associated costs.