Choose From a List: A User Study of Random Password Memorability

Passwords & AuthenticationPrivacy Perception & Decision-Making

Research Background and Issues

  • What problems or challenges did the authors identify?

    1. Secure password managers still require a hard-to-guess master password, but users often struggle to remember high-strength, randomly generated passwords.
    2. Psychology suggests that choice can enhance memory, but no studies have thoroughly explored the impact of choice on the memorability of randomly generated passwords.
  • Why is this issue important? Randomly generated passwords provide higher security, but if they are difficult to remember, users may resort to insecure behaviors such as writing them down or reusing passwords, thereby compromising security.

  • Research Motivation and Related Work

    1. Psychological strategies (e.g., choice, the superiority of images) have potential benefits for memory, but their specific application to password generation has not been clearly validated.
    2. Most existing studies focus on how to generate more secure or memorable password systems but lack independent analysis of individual memory enhancement factors.

Solution

  • What methods or solutions did the authors propose? The authors designed and conducted a longitudinal user study where participants selected passwords from lists of varying sizes (1, 8, 32, or 128 randomly generated passwords) and underwent memory testing.

  • What is innovative about this solution?

    1. Specifically tests the hypothesis "Does choice enhance the memorability of random passwords?"
    2. Isolates "choice" from other memory enhancement strategies for independent study.
  • What are the implementation steps and key techniques used?

    1. Participants were randomly assigned to receive a list containing 1, 8, 32, or 128 random passwords.
    2. Users selected one password from the list and familiarized themselves with it through a single memory task.
    3. Participants were tested on password recall after 7 days and 28 days.
    4. Statistical modeling and regression analysis were used to measure the impact of the number of choices on memorability.

Research Findings

  • What specific results were achieved?

    1. Allowing users to choose from a list of random passwords did not significantly improve password memorability.
    2. Increasing the number of choices (e.g., from 1 to 128) resulted in a positive memory gain of less than 5% or even a significant decline.
    3. Users did not exhibit clear "satisficing" behavior (choosing arbitrarily); approximately half of the participants scrolled to the bottom of the list.
  • What are the advantages compared to existing solutions? Provides a long-term, human behavior-based comparative analysis of password generation, featuring a larger sample size and more rigorous methodology.

  • What are the experimental or evaluation results?

    1. After the initial memory test, only 57.3% of users recalled their password, with recall rates dropping to 51.3% after 28 days.
    2. Different password list sizes (1 to 128) showed no significant differences in memory test results.
  • Limitations and Future Directions Limitations:

    1. The experiment only examined password generation results with approximately 30 bits of strength, excluding scenarios requiring higher strength (e.g., offline attack resistance).
    2. Participants were recruited from the Prolific platform, which may differ culturally and behaviorally from the general population.
    3. It was not possible to fully detect or prevent participants from recording passwords, potentially inflating actual memory estimates.

    Future Directions:

    1. Explore the interaction of multiple memory enhancement strategies, such as the synergy between "choice" and "spaced repetition."
    2. Develop new user interfaces to intuitively generate random passwords that are both easy to input and remember.
    3. Investigate other non-memory-driven reasons for choice, such as usability (ease of password entry on mobile devices) or relevance to specific contexts.

Through this study, although no significant memory enhancement effects were found, a research design framework was provided to enable stricter and more reproducible studies on password-related memory effects in the future. These findings may hold significant value for the practical design and adoption of password generation systems.

Quick Actions

Share

Share this page

ios_share

https://hci.top/en/papers/chi/189622/2025

AdRecommended

Learn AI Coding at CodeNow

open_in_newOpen DOI Link
DOI: https://dl.acm.org/doi/10.1145/3706598.3714043
At a Glance

Paper Snapshot

fact_check
dataset
Source
CHI
calendar_month
Year
2025
emoji_events
Award
No award tagged
group
Authors
3 authors
sell
Subtopics
Passwords & Authentication, Privacy Perception & Decision-Making
work
Professions
article
Content Status
Full text indexed
hub
Related Papers
10 related papers