Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking
Authors
Entering text passwords on mobile devices is a significant challenge. Current systems either display passwords in plain text: making them visible to bystanders, or replace characters with asterisks shortly after they are typed: making editing them harder. This work presents a novel approach to mask text passwords by distorting them using graphical filters. Distorted passwords are difficult to observe by attackers because they cannot mentally reverse the distortions. Yet passwords remain readable by their owners because humans can recognize visually distorted versions of content they saw before. We present results of an online questionnaire and a user study where we compared Color-halftone, Crystallize, Blurring, and Mosaic filters to Plain text and Asterisks when 1) entering, 2) editing, and 3) shoulder surfing one-word passwords, random character passwords, and passphrases. Rigorous analysis shows that Color-halftone and Crystallize filters significantly improve editing speed, editing accuracy and observation resistance compared to current approaches.
Research Questions / Practical Problems
Question signals indexed for this paper.
- 80%
Security During Application Development: an Application Security Expert Perspective
CHI '18· Privacy by Design & User Control +1
- 80%
'Think secure from the beginning': A Survey with Software Developers
CHI '19· Privacy by Design & User Control +2
- 67%
"Pretty Close to a Must-Have:" Balancing Usability Desire and Security Concern in Biometric Adoption
CHI '19· Privacy by Design & User Control +2
- 67%
"I'm Surprised So Much is Connected": A Study on Users' Online Account Security Connections
CHI '22· Privacy by Design & User Control +2
- 60%
Leveraging Semantic Transformation to Investigate Password Habits and Their Causes
CHI '18· Privacy by Design & User Control +1
- 60%
On the Usability of HTTPS Deployment
CHI '19· Privacy by Design & User Control +1
- 60%
I Don't Even Have to Bother Them!: Using Social Media to Automate the Authentication Ceremony in Secure Messaging
CHI '19· Privacy by Design & User Control +1
- 60%
Analyzing the Use of Public and In-house Secure Development Guidelines in U.S. and Japanese Industries
CHI '23· Privacy by Design & User Control +1
- 60%
No Silver Bullet: Towards Demonstrating Secure Software Development for Small and Medium Enterprises in a Business-to-Business Model
CHI '25· Privacy by Design & User Control +1
- 60%
Exploring Redirection and Shifting Techniques to Mask Hand Movements from Shoulder-Surfing Attacks during PIN Authentication in Virtual Reality
MobileHCI '24· Passwords & Authentication
Based on Jaccard similarity of research subtopics & professions (≥60%)