Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Operations //

Identity & Access Management

8/10/2020
06:25 PM
100%
0%

Gamifying Password Training Shows Security Benefits

When picking passwords, users often fall back on certain insecure patterns, but good habits can be learned using simple games, a group of researchers find.

Passwords continue to be problematic for many companies because users tend to pick predictable combinations of letters, numbers, and symbols. Using a game for training can reinforce the rules for picking stronger passwords, a group of researchers from the India-based Tata Consulting Services stated in a presentation at the USENIX Symposium on Usable Privacy and Security on August 10 and in a report.

In a study with the company's 4,904 employees, the researchers found that an educational game — called Passworld — improved users' choice of passwords along several measurements, such as creating unique sequences of characters without duplicates or repeating patterns. The game required users to find a valuable artifact and then protect it using a strong set of gates, each of which represented a letter, number, or special symbol. 

While the game did not actually try to break the player's password, it did evaluate the user's choices against the list of rules, said Gokul Chettoor Jayakrishnan, a researcher with Tata Consultancy Services and one of the authors of the paper.

"We are not exclusively telling the users that this is a strong password, but at the end of the game, we are seeing whether the users learned the heuristics and produced more diverse passwords at the end," he says.

The game first tested the player's knowledge of the heuristics for strong password creation during a pretest, and then had the user play the game and create a password. Then it distracted the user with minigames, until the game tested the person's recall of the password. Finally, the game tested the player's knowledge of strong passwords. 

While users originally tended to follow similar, insecure practices to create passwords — such as a word followed by a number — after playing the game, the participants increased their password diversity, the paper found. In addition, many fewer employees chose to include blocked terms in their passwords, leading to a 77% reduction in the use of common organizational terms.

"In the beginning, there was a common trend of the users to create similar passwords, because there were rules, such as the password must be a certain length," Jayakrishnan said. "But once they played the game, there was a greater diversity of passwords."

Users' poor choice of passwords, and the penchant to reuse passwords, have been at the heart of many data breaches and network compromises. Smaller companies of less than 25 employees tend to have 14 passwords per employee, while those in larger companies of more than 1,000 employees have only 4 passwords per person, credential management firm LastPass stated in its "2019 Annual Global Password Security" report.

Password strength meters, which give users an interactive metric of a password as they are entering the characters, help to some extent, but researchers have found that some users mistrust the guides because the users have no foundation in the rules for creating strong passwords, the researchers stated in their paper.

For many companies, the solution is to take users' choices out of the equation. Companies are increasingly adopting multifactor authentication (MFA) to help strengthen security that otherwise would rely on employees' password choice. In 2019, 57% of companies had adopted MFA, up from 45% the previous year, according to the LastPass report.

In addition, as password managers have become more common on mobile devices, employees have increasingly adopted the technology. Nearly a quarter of employees used a password manager on their mobile devices, according to LastPass. 

The gamification of everything has not necessarily improved every metric of security. Users still chose to use predictable keyboard patterns, such as "querty," and predictable placement of uppercase letters, such as the beginning or end of a sentence. 

"Some of the heuristics saw a decline, including keyboard patterns and uppercase patterns, which may indicate that they need more training in the game," Jayakrishnan says.

The researchers intend to add modifications to the game to incorporate what they have learned, such as reminding users in real time about the importance of not including common uppercase or keyboard patterns.

Related Content:

 

Veteran technology journalist of more than 20 years. Former research engineer. Written for more than two dozen publications, including CNET News.com, Dark Reading, MIT's Technology Review, Popular Science, and Wired News. Five awards for journalism, including Best Deadline ... View Full Bio
 

Recommended Reading:

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
RichardM23501
50%
50%
RichardM23501,
User Rank: Apprentice
9/1/2020 | 1:19:23 PM
Let it go, let it go...!
Great article.

Soon, password usage will be deprecated, like many obsolete technologies. Wtih 2FA, MFA and IDMs becoming mainstream, the concept of paswords is very short lived. 

Looking forward to forgetting many more passwords.
rainajordan
50%
50%
rainajordan,
User Rank: Apprentice
8/26/2020 | 3:53:41 AM
Thanks
Nice Information, Thanks 
COVID-19: Latest Security News & Commentary
Dark Reading Staff 9/25/2020
Google Cloud Debuts Threat-Detection Service
Robert Lemos, Contributing Writer,  9/23/2020
Shopify's Employee Data Theft Underscores Risk of Rogue Insiders
Kelly Sheridan, Staff Editor, Dark Reading,  9/23/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Special Report: Computing's New Normal
This special report examines how IT security organizations have adapted to the "new normal" of computing and what the long-term effects will be. Read it and get a unique set of perspectives on issues ranging from new threats & vulnerabilities as a result of remote working to how enterprise security strategy will be affected long term.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-26120
PUBLISHED: 2020-09-27
XSS exists in the MobileFrontend extension for MediaWiki before 1.34.4 because section.line is mishandled during regex section line replacement from PageGateway. Using crafted HTML, an attacker can elicit an XSS attack via jQuery's parseHTML method, which can cause image callbacks to fire even witho...
CVE-2020-26121
PUBLISHED: 2020-09-27
An issue was discovered in the FileImporter extension for MediaWiki before 1.34.4. An attacker can import a file even when the target page is protected against "page creation" and the attacker should not be able to create it. This occurs because of a mishandled distinction between an uploa...
CVE-2020-25812
PUBLISHED: 2020-09-27
An issue was discovered in MediaWiki 1.34.x before 1.34.4. On Special:Contributions, the NS filter uses unescaped messages as keys in the option key for an HTMLForm specifier. This is vulnerable to a mild XSS if one of those messages is changed to include raw HTML.
CVE-2020-25813
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, Special:UserRights exposes the existence of hidden users.
CVE-2020-25814
PUBLISHED: 2020-09-27
In MediaWiki before 1.31.10 and 1.32.x through 1.34.x before 1.34.4, XSS related to jQuery can occur. The attacker creates a message with [javascript:payload xss] and turns it into a jQuery object with mw.message().parse(). The expected result is that the jQuery object does not contain an <a> ...