Do users' perceptions of password security match reality?

We know that users often create poor passwords. But is this because they don't know what makes a password strong or weak, or for another reason?

We ran a study in which we asked participants to compare pairs of carefully chosen passwords and rate which they thought was stronger. We then compared their answers to what our models of password guessing predicted about the strength of those passwords. Take the quiz below to compare your perception of password security to our participants', as well as to what our models of attackers predicted.

Do Users' Perceptions of Password Security Match Reality?   [PDF, BibTeX, video teaser, online game, ]
Blase Ur, Jonathan Bees, Sean Segreti, Lujo Bauer, Nicolas Christin, and Lorrie Faith Cranor.
In CHI'16: 34th Annual ACM Conference on Human Factors in Computing Systems, May 2016. ACM. CHI 2016 Honorable Mention. © authors  DOI:10.1145/2858036.2858546

If you see a blank box below, you may need to whitelist in your ad blocker.