<!DOCTYPE article PUBLIC "-//NLM//DTD JATS (Z39.96) Journal Archiving and Interchange DTD v1.0 20120330//EN" "JATS-archivearticle1.dtd">
<article xmlns:xlink="http://www.w3.org/1999/xlink">
  <front>
    <journal-meta />
    <article-meta>
      <title-group>
        <article-title>Understanding how users choose passwords: analysis and best practices</article-title>
      </title-group>
      <contrib-group>
        <contrib contrib-type="author">
          <string-name>Alessia Michela Di Campi</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <contrib contrib-type="author">
          <string-name>Flaminia L. Luccio</string-name>
          <xref ref-type="aff" rid="aff0">0</xref>
        </contrib>
        <aff id="aff0">
          <label>0</label>
          <institution>DAIS, University Ca' Foscari of Venice</institution>
          ,
          <addr-line>Venice</addr-line>
          ,
          <country country="IT">Italy</country>
        </aff>
      </contrib-group>
      <abstract>
        <p>In an era where digital services and password-protected platforms are becoming ubiquitous in various aspects of our lives, from healthcare technology to home environments, security has emerged as a paramount concern. To remotely access these devices, users must go through an authentication process, which typically involves the use of passwords. These passwords must meet two essential criteria: usability and security. Usability implies that passwords should be easy for users to remember and use. Security requires that passwords be resistant to unauthorized access. This study aims to investigate potential links between human behavior and password selection, as well as users' perceptions of password security. To address this issue, we analyzed multiple data leaks and surveyed 217 users across various age groups and backgrounds. Data analysis reveals that, regardless of educational or professional background, most people tend to opt for simple, easily guessable passwords. Surprisingly, users with a technology background chose the weakest passwords. Based on the results of our analysis, we propose recommendations for both users and IT professionals. These suggestions can help users create stronger passwords and help IT professionals formulate efective access policies.</p>
      </abstract>
      <kwd-group>
        <kwd>eol&gt;passwords</kwd>
        <kwd>human behaviour</kwd>
        <kwd>usability</kwd>
      </kwd-group>
    </article-meta>
  </front>
  <body>
    <sec id="sec-1">
      <title>1. Introduction</title>
      <p>
        Passwords play a crucial role in our daily lives as they are the key to accessing various computer systems.
To ensure security, it is critical to examine and understand how to create passwords that are not easily
guessed [
        <xref ref-type="bibr" rid="ref1 ref2">1, 2</xref>
        ]. In recent years, several papers have proposed models and techniques for measuring
password strength, aiming to provide real-time feedback to users and guide them in selecting stronger
passwords (see, e.g., [
        <xref ref-type="bibr" rid="ref3 ref4 ref5 ref6">3, 4, 5, 6</xref>
        ]). However, one of the primary concerns for users is the fear of forgetting
their passwords, leading them to choose easily memorable ones. Unfortunately, this practice makes
them vulnerable to various eficient attacks (see e.g., [
        <xref ref-type="bibr" rid="ref5 ref7 ref8 ref9">5, 7, 8, 9</xref>
        ]).
      </p>
      <p>Passwords’ memorability is influenced by their composition and patterns. In this work, we will
analyze common words and patterns used in password creation. This analysis is crucial as some attacks
exploit these commonalities and can even guess encrypted passwords. By examining the most commonly
used patterns and word categories in password creation and their potential correlation with language,
we aim to gain valuable insights into password security vulnerabilities. Thus, this work focuses on
analyzing known data leaks and responses from participants to a questionnaire in order to address the
following research questions:</p>
      <p>RQ1: Which are the most common patterns and word categories used for password creation, and do they
depend on the used language? Passwords’ efectiveness is closely linked to users’ cognitive abilities and
behaviour. Understanding how cognition and behaviour afect password security can lead to insights
into vulnerabilities and strategies to improve digital security.</p>
      <p>RQ2: How does user cognition impact password security and usage? Experts and regular users have
diferent approaches to password security based on their knowledge and experience. By analyzing
these diferences, we can identify opportunities for targeted interventions and educational initiatives to
enhance cybersecurity for all users.</p>
      <p>RQ3: Are there diferences between experts and regular users? We aim to explore how computer
knowledge may afect attitudes towards choosing passwords.</p>
      <p>This comprehensive analysis aims to shed light on password security and help users and IT
professionals in making informed decisions to enhance the protection of computer systems. The contributions
of our work are: i) A comprehensive analysis of multiple data leaks: we analyzed multiple data leaks to
understand password choice behaviors, patterns, and vulnerabilities and provided a comprehensive
understanding of password security practices. ii) Exploration of cognitive aspects: we delved into the
cognitive aspects underlying password choices, identifying common mistakes and proposing techniques
to prevent them. iii) Investigation into factors shaping password selection: we explored the factors
influencing individuals’ password choices, including demographic variables and level of IT experience
through a questionnaire survey.</p>
      <p>This manuscript is organized as follows: in Section 2, We discuss recent studies on psychological
factors that influence password choice, as well as studies on password structure. In Section 3, we discuss
the analysis made to pre-existing data leaks. In Section 4 we introduce the analysis and results of the
proposed questionnaire, and in Section 5 we try to answer to RQ1, RQ2 and RQ3. We conclude in
Section 6 giving some general recommendations and discussing future work.</p>
    </sec>
    <sec id="sec-2">
      <title>2. Related Work</title>
      <p>In this section, we discuss recent studies on the psychological factors that influence password choice, as
well as studies on the best password structure for security purposes.</p>
      <p>
        Cognitive dissonance. Many websites enforce strict password guidelines, frustrating users [
        <xref ref-type="bibr" rid="ref10 ref11 ref12 ref13">10, 11, 12,
13</xref>
        ]. Psychological factors, such as cognitive dissonance, i.e., the psychological discomfort stemming
from the simultaneous adherence to conflicting sets of beliefs, values, or attitudes, influence password
choices [
        <xref ref-type="bibr" rid="ref14">14</xref>
        ]. Users often exhibit cognitive dissonance regarding password behavior, knowing the risks
of reusing passwords but persisting in the behavior. Despite awareness of best practices, like changing
passwords regularly, many users do not adhere to them.
      </p>
      <p>
        Neutralization mitigation. Diferent strategies are proposed to reduce risky behaviors in password
creation. An empirical study by [
        <xref ref-type="bibr" rid="ref15">15</xref>
        ] found individuals applying psychological mechanisms like denial
of responsibility. This mechanism involves individuals justifying their non-compliance with company
password guidelines by asserting ignorance of such guidelines. Educational interventions can reduce
such behaviors and promote secure password practices [
        <xref ref-type="bibr" rid="ref16">16</xref>
        ].
      </p>
      <p>
        Cognitive depletion and training memory. Another important aspect studied in password choices is
the influence of cognitive depletion [
        <xref ref-type="bibr" rid="ref17">17</xref>
        ], often referred to as cognitive exhaustion [
        <xref ref-type="bibr" rid="ref18">18</xref>
        ]. According to
Baumeister’s theory, individuals have limited mental resources for decision-making and self-control.
This limitation leads users to fear forgetting their passwords, resulting in password reuse across various
websites. A study conducted by Wash et al. [19] found that people were reusing each password on
average on 1.7 out of 3.4 diferent websites. Users tend to reuse passwords they enter frequently or those
that are more complex. This pattern was evident in our questionnaire, where participants often used the
same password for multiple questions. Cognitive depletion arises due to limited mental memory capacity.
Nelson and Vu [20] in 2010 proposed image-based techniques to simplify password memorization,
leveraging humans’ strong image recall ability [21, 22, 23, 24, 25, 26]. Image-based passwords are easier
to remember compared to text-based ones, triggering the stream of consciousness [27].
      </p>
      <p>Attention processes. Experts in a particular field tend to enter a state of energy conservation, as
the process of focusing their attention is cognitively demanding. On the contrary, when people lack
significant knowledge on a topic, their attention it is often heightened, allowing them to remember even
the smallest details [28]. Consequently, experts in a particular field may focus solely on the end goal,
such as registering on a website, inadvertently overlooking a critical aspect: security. This behavior is
rooted in the intrinsic nature of the attention processes.</p>
      <p>
        Pattern frequency analysis. To access certain systems, complex passwords are required to enhance
security against guessing attacks. Password strength is typically measured by entropy [29, 30, 31].
Users often slightly modify passwords across accounts to improve uniqueness while maintaining
security, though this practice is understudied [32]. However, meeting complexity requirements does
not guarantee strong passwords, for instance, P45sw0rd1 appears secure but can be easily guessed due
to common patterns [
        <xref ref-type="bibr" rid="ref12">12, 33</xref>
        ]. Moreover, techniques such as Leetspeak, that replaces characters with
symbols, do not significantly enhance security [
        <xref ref-type="bibr" rid="ref19 ref20 ref21">34, 35, 36, 37, 38, 39</xref>
        ].
      </p>
    </sec>
    <sec id="sec-3">
      <title>3. Dataset Analysis</title>
      <p>
        We analyzed various datasets to scrutinize the relationship between common patterns in password
creation across multiple data leaks. Our aim was to extract insights applicable to any data leak using
diverse datasets, departing from the practice of tailoring results to specific datasets observed in prior
research such as [
        <xref ref-type="bibr" rid="ref22 ref23">35, 40, 41</xref>
        ].
      </p>
      <sec id="sec-3-1">
        <title>3.1. Dataset Selection</title>
        <p>
          After an accurate selection we downloaded diferent datasets which are publicly available on GitHub,
and that contain a substantial number of passwords. The datasets are the following ones: RockYou
Dataset [
          <xref ref-type="bibr" rid="ref24">42</xref>
          ]: Contains 32,603,048 passwords leaked from accounts of RockYou, a company known for
developing widgets for MySpace and social networking applications; Hotmail Dataset [
          <xref ref-type="bibr" rid="ref25">43</xref>
          ]: Includes 8,930
passwords from a data breach of Microsoft’s web-based email service; PhpBB Dataset [
          <xref ref-type="bibr" rid="ref26">44</xref>
          ]: Comprises
184,388 passwords leaked from PhpBB, a popular free forum management system; Ashley Madison
Dataset [
          <xref ref-type="bibr" rid="ref27">45</xref>
          ]: Contains 375,831 passwords leaked from Ashley Madison, a dating service; Most Common
Words Dataset [
          <xref ref-type="bibr" rid="ref28">46</xref>
          ]: Consists of over 4000 English words; Most Common Names Dataset [
          <xref ref-type="bibr" rid="ref29 ref30 ref31 ref32">47, 48, 49, 50</xref>
          ]:
Includes over 8000 English, German, and Spanish names.
        </p>
      </sec>
      <sec id="sec-3-2">
        <title>3.2. Password Analysis and Results</title>
        <p>We analyzed diferent data leaks to extract commonly used password patterns. Our focus was on the
frequency and position of characters, as well as their similarity to commonly used words. We also
ensured our findings were not uniquely linked to a particular dataset.</p>
        <sec id="sec-3-2-1">
          <title>3.2.1. Password Patterns</title>
          <p>To answer to RQ1 we followed diferent steps in a systematic manner. To describe the steps we first
need to introduce some notation, and then we explain the analysis.</p>
          <p>We followed the notation of [35], where passwords are defined using a concatenation of diferent
symbols: L, N, U and S, where N represents numbers, L lowercase letters, U uppercase letters, and S
symbols. We define a pattern class as a variable-length (eventually empty) sequence of numbers  +,
lower or upper case letters + or  +, and symbols +. Moreover, a password pattern is a combination
of strings of the type , , , or . For example 3 represents a numeric string composed of three
characters, and 5 denotes an uppercase letter string composed of five characters.</p>
          <p>
            For each data leak, we calculated the average length of passwords and which ranges of length were the
most frequent ones in order to create datasets with suficient data for statistical analysis. Then, following
the research outlined in [
            <xref ref-type="bibr" rid="ref33">51</xref>
            ], we delineated diverse password construction methodologies. First, we
categorized passwords by pattern class using a simple algorithm that converts a string input (password)
into the corresponding pattern class. For example, Password1 becomes  ++ +, and Pas5word@1
becomes  ++ +++ +. This facilitated faster understanding of password structure, and we
calculated frequencies to determine the most common patterns.
          </p>
          <p>
            Then, we performed common substitutions of numbers and symbols with characters (see Table 5 in
the Appendix). After substitution, we removed any numbers or symbols at the beginning or end of the
password and analyzed the resulting passwords to generate statistics. In the case of comparisons with
other dictionaries, were counted how many comparisons had hits. In the case of single string analysis,
were divided the strings into characters and analysed the structure. To measure the minimum number
of single-character edits (insertions, deletions, or substitutions) needed to transform one word into
another, we used an edit distance algorithm. In particular, we used a modified version of the Levenshtein
Distance algorithm [
            <xref ref-type="bibr" rid="ref34">52</xref>
            ], taking two files and a threshold as input. The first file contained common
words, and the second file contained processed plaintext passwords. The algorithm found potential
matches in the dictionary based on a chosen threshold, indicating common substitution methods used
in passwords. We also used this algorithm to categorize passwords, considering common words along
with commonly used names, colors, superheroes, etc. We analyzed the distribution of capital letters,
lowercase letters, symbols, and numbers within passwords to better understand password structures.
We analyzed passwords containing numbers and symbols positioned either at the beginning or end of a
sequence to derive detailed statistics on employed numerical values, or symbols.
          </p>
          <p>Then, we conducted an analysis on special format patterns, including passwords with specific
structures such as dates in various formats and combinations of birth months, days or years. We
analyzed repeating patterns, reversing patterns, and mixed patterns that combine various types of
patterns.</p>
          <p>Finally, we investigated whether users of diferent languages exhibited distinct password patterns.
After analyzing word lengths in datasets of frequently used words in languages other than English, we
focused on Spanish and German datasets, applying to them the same analytical procedures used for
English passwords.</p>
        </sec>
        <sec id="sec-3-2-2">
          <title>3.2.2. Dataset Analysis Results</title>
          <p>Pattern Analysis Results. Our analysis of password lengths revealed that they typically range from 7
to 8 characters, with the majority falling between 5 and 12 characters. We excluded passwords shorter
than 5 and longer than 12 characters for our examinations. From the pattern analysis results, we
identified the dominant pattern class as one characterized by the presence of both letters and numbers
+ + and only letters + (details in Table 1). We noticed that as the password length increases, the
occurrence of lowercase letters ascends towards the end of the password, while the occurrence of
numbers decreases. Uppercase letters exhibit a descending pattern from the first character to the end
of the password. We also observed that pattern classes starting or ending with numbers or symbols
were frequent. Regarding prefixes and sufixes, numeric prefixes are more common than symbolic
prefixes across all databases, with sufixes being predominantly numeric. For instance, in Rockyou,
approximately 22.90% of passwords have numeric prefixes, while only 0.72% have symbolic prefixes. As
for sufixes, 57.98% are numeric characters, while 2.38% are symbolic characters. Additionally, an inline
dif analysis revealed that in 90% of cases, password symbols corresponded to characters resulting from
common substitutions, such as “@” for “a”, “$” for ’s”, “!” for “l”, and “[” for “p”.</p>
          <p>Pattern class
Rockyou
Ashley Madison
PhpBB
Hotmail
+ +
33
37
24
20
+
26
33
41
42
%
 +
17
12
11
19
 ++
4
4
5
3
+ ++
1
2
2
2</p>
          <p>Frequent Categories. We employed the Levenshtein Distance algorithm to categorize passwords
based on input word files, such as lists of personal names. In analyzing personal names, we found that
certain names were more prevalent than others across the datasets. The most common names in the
RockYou dataset were Love, Mari, Angel, and Anna. In PHPBB, Love, Star, and King were prevalent.
Hotmail showed Mari and Love as the most common names, while Ashley Madison exhibited Love,
King, and Mike. Furthermore, we observed that passwords with five characters tended to contain names
more frequently than passwords of other lengths. Match percentages decreased as password length
increased, indicating longer passwords were more complex and less likely to contain common names.
Additionally, an examination of potential connections between names, dates, and numbers showed that
passwords containing numbers with names became more common as password length increased across
all datasets.</p>
          <p>Analysis of other Languages. Regarding the analysis of the Spanish and German languages, even
though the datasets contained fewer words, we uncovered noteworthy patterns and trends. We found
that the most used patterns are the same as those used for the English language.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-4">
      <title>4. Case Study</title>
      <sec id="sec-4-1">
        <title>4.1. Questionnaire</title>
        <p>We created a questionnaire for users across diferent age groups and backgrounds to gather insights
into their password creation practices and attitudes toward password security. The questionnaire
was distributed through multiple social networks including Facebook, Instagram and Twitter and we
collected 217 responses. Notice that, a potential bias may have occurred in the questionnaire responses,
particularly when we requested passwords that adhered to the reported policies. Participants might
have chosen safer but more dificult-to-remember passwords, given that they knew they would not
need to recall them in the future.</p>
        <p>Ethics. To gather data, we distributed an anonymous questionnaire to request responses from our
target participants. We chose this anonymized approach to ensure the privacy and candidness of
respondents, thereby encouraging a more open and unbiased exchange of information. Participation in
the research by filling in the questionnaires was purely voluntary. The questions had no mandatory
answers, so those who did not want to answer could skip and go to the next question. Participants did
not get any reward by participating in the research.</p>
        <sec id="sec-4-1-1">
          <title>4.1.1. Passwords Shapes and Categories</title>
          <p>We proposed some questions involving user-invented passwords. By doing so, we were able to build a
dataset of passwords to be analysed. To answer RQ1, we analysed the new dataset to deduce patterns,
distributions of numbers and symbols, and the most commonly used words. The questionnaire free
answers were analyzed following the pattern notation explained in Section 3.2 with letters representing
lowercase letters, numbers, uppercase letters, and symbols. Passwords were categorized into pattern
classes, and common substitutions of numbers and symbols were examined. Using editing distance
algorithms, patterns were identified and special formats like dates and combinations of birth months
were investigated. While for multiple-choice answers we applied averages and standard deviation. For
some questions it was necessary to go deeper by applying additional statistical tools to visualise whether
there were substantial diferences between groups of answers or persons. As for the categories, we
proposed a list of possible categories based on the results of data leaks and asked participants to specify
whether they sometimes, never, or always use a specific category among those proposed. We also asked
to explicitly specify the patterns they usually use, giving them a choice of lowercase, uppercase, number,
and symbol for the various positions of a password of arbitrary length.</p>
        </sec>
        <sec id="sec-4-1-2">
          <title>4.1.2. Human Cognition: Perception, Behavior, and Knowledge</title>
          <p>To address RQ2, we asked the participants to describe their perception and behaviour w.r.t. the choice
of a password.</p>
          <p>
            Password Comparison. To gauge user perception of password strength, as in [
            <xref ref-type="bibr" rid="ref35">53</xref>
            ], we presented a
list of 8 couples of passwords. The pairs were composed of similar passwords and we asked participants
to compare them and select the strongest one. The participants rated the passwords on a 7-point Likert
scale 1. 8 of the 12 proposed passwords were taken from [
            <xref ref-type="bibr" rid="ref35">53</xref>
            ] as a reference, while the other 4 were
created by us.
          </p>
          <p>Preferences and Practices in Password Security. We asked about the user’s password-strength
preferences - whether it should be easy to remember, secure, or both. For the participants who responded
positively regarding the ease of remembering passwords, we conducted a follow-up inquiry asking why
a password should be easy to remember through a multiple-choice question. This question provided
predefined options as well as the opportunity for the participants to include free-text responses, allowing
for a more detailed explanation of their reasons. We investigated also common beliefs about the strategies
malicious users employ to guess passwords (e.g. software, brute force, common words).</p>
          <p>
            External Stimuli. We designed an experiment in which users were directed to three distinct websites.
The first website centered around dog training [
            <xref ref-type="bibr" rid="ref36">54</xref>
            ], the second one featured CD sales [
            <xref ref-type="bibr" rid="ref37">55</xref>
            ], and the
third one was focused on helicopter sales [
            <xref ref-type="bibr" rid="ref38">56</xref>
            ]. We instructed participants to indicate the password
they would use if they were to subscribe to each website in the questionnaire. This was undertaken to
evaluate the impact of visual cues on their password selection. Our goal was to analyze how visual
stimuli, encompassing images and content, afected their choice of passwords.
          </p>
          <p>Expert Users. To answer to RQ3, we decided to investigate whether users who are presumed to be
experienced employ better policies and patterns than non-experts. By expert users we mean people
who responded that they were completing or had completed studies in computer science. We are aware
that computer science encompasses many categories, so not necessarily everyone has to be a security
expert, but still we expect a greater knowledge of good strategies than participants in other fields.</p>
        </sec>
      </sec>
      <sec id="sec-4-2">
        <title>4.2. Results</title>
        <p>
          In this section, we present the findings from our study, which aimed to investigate the relationship
between human behaviour, password selection, and user perceptions of password security. We used
Python3 and IBM SPSS statistics for string examination for data analysis [
          <xref ref-type="bibr" rid="ref39">57</xref>
          ].
        </p>
        <p>Sample. In total, 222 individuals, with diferent types of jobs (64%) and students (36%), took part in
the questionnaire, but 5 of them interrupted the compilation after the first questions, so we removed
them from the analysis and considered only 217 responses. The average age of participants was 25
years, ranging from 17 to 62. The cohort was equally divided between men and women, with 44.2% of
the sample belonging to the female gender, 55.3% to the male gender, and 0.5% preferred not to answer.
In addition, the educational level of the participants was recorded, with 42.4% of the responders having
a high school degree, 37.3% a bachelor’s degree, 12% a master’s degree, Ph.D. degree (1%), or they
stopped their study at primary school (1%) or secondary school (6%). In terms of careers, participants
included employees, executives, and workers. We assessed participants’ computer proficiency levels,
categorizing them as advanced, autonomous, or average users. Participants classified as advanced users
were 45.2%, 40.6% as autonomous users, and 12.4% as intermediate users, with the remainder possessing
basic computer knowledge. The participants were instructed to answer each question spontaneously,
without any prior review of their responses. However, they were free to revisit their answers at any
point during the study. The summarised questionnaire is shown in Table 6 in the Appendix.</p>
        <sec id="sec-4-2-1">
          <title>4.2.1. Password Patterns and Categories</title>
          <p>We now consider the password patterns and the categories of words used in their construction to
respond to RQ1. We explicitly asked the participants about the type of password pattern they usually
use; it has been observed that most of the passwords analyzed start with a capital letter followed
by lowercase characters, numbers and then symbols (as shown in Table 2a). Participants were also
instructed to invent passwords based on their preferences. We collected a total of 643 passwords and
analyzed their diferent patterns and frequencies. The most common pattern was a combination of one
1The scale ofers two moderate opinions, along with two extremes, two intermediate, and one neutral opinion to the
respondents. Selecting 1 would indicate that the first password is considered more secure than the second one. At the same
time, 4 suggests they are equally secure, and 7 implies that the second one is more secure.</p>
          <p>e
yp L
T</p>
          <p>U
N
S</p>
          <p>N
%*
N
%*
N
%*
N
%*</p>
          <p>C1
C2
C3
C4
C5
C6
C7
C8
(a) Typical password pattern of the N=217
users.</p>
          <p>(b) Most common password patterns and
related frequencies of 643 passwords.
or more uppercase letters, followed by one or more lowercase letters, and then one or more numbers
( ++ +). This was followed by the pattern of  ++ ++, and then  +++ + (see Table 2b).</p>
          <p>We also checked each password to determine which symbols were present and counted them. It
emerged that the exclamation point, at sign, and hyphen were the most commonly used symbols.</p>
          <p>Regarding the categories of words used to create passwords, the results are that 76% of the respondents
used names of relatives, 28% random numbers, and 25% numbers that remind of important dates. Table
7 in the Appendix lists all results.</p>
        </sec>
        <sec id="sec-4-2-2">
          <title>4.2.2. Human Cognition: Perception, Behavior, and Knowledge</title>
          <p>Passwords Comparison. To respond to RQ2 we asked the participants to compare a set of eight pairs
of passwords, and we analysed the distributions of the various responses. Only one password was
correctly perceived to be more secure than the other. In fact, as can be seen from Table 3, only in the
third comparison did the users correctly perceive the second password as the most secure. In all other
cases, they either noticed no diference or perceived the less secure one as more secure.</p>
          <p>Preferences and Practices in Password Security. According to the survey results, 64% of
participants believe that a password should be highly secure, while 31% consider a moderate level of security
to be suficient. Regarding ease of remembering passwords, 37% prefer passwords that are very easy to
remember, while 42% find a moderate ease level acceptable. Interestingly, 55.30% of participants prefer
easy-to-remember passwords due to fear of forgetting them, 28.90% opt for using the same pattern
across all websites, and 23.20% find password recovery processes bothersome. As the survey included
opportunities for open-ended responses, the remaining percentage of individuals provided their reasons.
Many mentioned the challenge of remembering unique passwords for numerous websites they are
registered on, leading them to use one password for multiple accounts or select simple passwords
to avoid frequent recovery procedures. Regarding potential methods attackers might use to guess

M
3.81
4.63
4.57
4.00
4.17
5.89
2.62
2.87
passwords, 41.90% of participants believed attackers would try commonly used passwords, while 33.20%
thought attackers would use words and names familiar to the participant’s native language. However, a
significant proportion (66.40%) admitted to consistently using the same password, often incorporating
commonly used words.</p>
          <p>External Stimuli. An intriguing finding from our study was related to a specific survey question
which considered possible correlations between the name of a website and the corresponding login
password. 84% of the respondents expressed concerns about the security of such a practice, however,
a contrasting 24% created passwords closely related to the specific website name. Furthermore, we
noted that 6.91% of the participants used identical passwords across all three websites despite their
initial security concerns. Additionally, 13% of the respondents answered negatively when we asked if
they often use the same password, and 62.77% of those who admitted of reusing the same password for
multiple accounts, created three diferent passwords for the various websites.</p>
        </sec>
        <sec id="sec-4-2-3">
          <title>4.2.3. Expert Users</title>
          <p>To answer to question RQ3, for each of the passwords asked in the questionnaire, we have decided
to investigate the relationship between IT knowledge and the right view of password security. We
expect expert users to be the most knowledgeable about how to choose good passwords. To assess the
relationship between IT knowledge and password security, we performed a one-way ANOVA2 test for
each of the eight pair of passwords PW1 and PW2 of Table 3. We recall that PW2 is always more secure
and values of answers range from 1 to 7, and 4 indicates that the passwords are equally secure.</p>
          <p>The goal was to determine whether individuals with diferent levels of IT knowledge, specifically
non experts (G1) versus experts (G2), exhibited significant variations in their ability to select secure
passwords. Our null hypothesis (H0) posited that there would be no significant diferences in password
security perceptions between these two groups, while the alternative hypothesis (H1) suggested that
significant diferences would be present. An ANOVA analysis was conducted to examine diferences
between the password comparison (C1, C2,..,C8), and on the expertise of the participants as the dependent
variable. The significance level (  ) was set at 0.05. The results of our ANOVA analysis are summarized
in Table 4. The  column lists the categories of elements that were compared between the two groups,
G1 and G2. The G1 and G2 (M and SD) columns provide the means (M) and standard deviations (SD) of
the category values for the two groups. For example, in the row for category C1, for group G1, the mean
is 3.81 with a standard deviation of 1.53, while for group G2, the mean is 4.20 with a standard deviation
of 1.53. The F-value column contains the F-values calculated from the analysis of variance (ANOVA)
and determines whether group means are equal. In one-way ANOVA, the F-value is the ratio between
variation between sample means and variation within the samples. ANOVA assesses whether there
2ANOVA (Analysis of Variance) is a statistical test used to determine whether there are significant diferences between the
averages of three or more independent groups by comparing the variations between them with the variations within the
groups themselves.
are significant diferences between group means, higher values indicate greater diferences between
groups. For example, for category C7, the F-value is 4.89. The test included 1 degree of freedom between
groups (numerator) and 97 degrees of freedom within groups (denominator), where 97 corrisponds
to the summation between the experts users (N=44) and non experts users (N=54) - 1. The  column
contains the p-values associated with the significance tests conducted by ANOVA. The p-value is the
probability of obtaining a result equal to or more extreme than the observed one, assuming the null
hypothesis is true. In this context, a low p-value (typically less than 0.05) indicates that the diferences
between groups are statistically significant. For example, for category C7, the p-value is 0.029, indicating
statistical significance at a 95% confidence level. When the p-value is less than

= 0.05, it’s indicated
with an asterisk (*) to emphasize the significance of the diference. As seen in the table, the ANOVA
analysis revealed that for passwords C1 through C6, there were no statistically significant diferences
between experts and other participants concerning their ability to select secure passwords. However,
for passwords C7 and C8, the results were diferent. In the case of C7, expert users answered more
correctly, while for C8, the result was opposite.</p>
        </sec>
      </sec>
    </sec>
    <sec id="sec-5">
      <title>5. Discussion</title>
      <p>We analyzed breach data and questionnaire results, addressing our research questions. For our first
query, we identified prevalent usage patterns, commonly used symbols in passwords, and predominant
password categories. Surprisingly, despite the diversity of languages used, common structures persisted.
Regarding our second question, we uncovered numerous misconceptions surrounding factors believed
to enhance password complexity. Finally, our investigation into the third question revealed that
misconceptions about password security techniques extend even to those with substantial expertise in
computer science. In the subsequent paragraphs, we delve into each question’s findings.</p>
      <p>RQ1: Which are the most common patterns and word categories used for password creation,
and do they depend on the used language? Several important considerations emerge from the
analyses conducted on the methods of constructing passwords and the related composition schemes.
First, password pattern analysis highlighted various techniques users use to create their credentials even
when they are asked to follow standard password policies. These techniques include combining letters,
numbers, and symbols and more complex strategies such as adding, inserting, and repeating elements
within passwords. In particular, the use of insertions, both through adding digits and symbols within
common words and through approaches such as password munging, suggests a wrong awareness on
the part of users of the importance of creating longer passwords and complexity to increase security.
Another significant discovery is adopting practices such as replacing letters with symbols or numbers,
as in the case of Leetspeak or Faux Cyrillic. While these techniques seem to broaden the complexity
of the password, they do not improve it. Additionally, observing repetition patterns indicates that
many users use common or recurring sequences to create their passwords. This behavior makes such
passwords more easily guessable and vulnerable to dictionary-based or brute-force attacks. Regarding
the diference in patterns used in diferent languages, it was observed that the password pattern in both
Spanish and German is not significantly diferent from that in English.</p>
      <p>
        RQ2: How does user cognition impact password security and usage? We investigated users’
tendency to rely on easily memorable passwords due to fear of forgetting them, despite understanding
the attributes of strong passwords. However, they lack substantial guidance on improving password
security. Users often overestimate the efectiveness of symbols and numbers, underestimating the
predictability of common patterns. For instance, passwords like p@ssw0rd are perceived as strong but
remain vulnerable. Similarly, punk4life is weak due to predictable substitutions, while ieatkale88
is stronger than iloveyou88 but still vulnerable to dictionary attacks. Passwords like astleyabc
and astley123 receive similar ratings despite diferences in character sets. Using uncommon words
like rtxe is becoming popular, but these passwords still lack entropy. Numeric-only passwords and
common patterns result in weak security. Overall, users need more guidance on choosing secure
passwords, considering both common misconceptions and emerging trends. The authors of [
        <xref ref-type="bibr" rid="ref35">53</xref>
        ] found
similar results, identifying four main misconceptions. Users tend to believe that adding digits inherently
enhances security, underestimate the impact of substituting digits or symbols for letters, overrate
the security of keyboard patterns, and underestimate the prevalence of common words or phrases in
passwords. These misconceptions contrast with current password-cracking capabilities, highlighting
the need for improved understanding of password security among users. Our study delved deeper to
investigate whether even experienced users made the same errors.
      </p>
      <p>
        RQ3: Are there diferences between experts and regular users? We have shown some user
misconceptions and we have highlighted how IT knowledge does not directly correspond to a correct
attitude towards IT security. The results highlight that expert users evaluate only one password
comparisons correctly while in the other cases they gave similar, if not weaker, ratings on average than
non-expert users. Specifically, in one comparison, they predominantly selected the incorrect password
w.r.t. to individuals from varied backgrounds. The results of our questionnaire are diferent and ofer
new insights compared to the findings of a previous study on a similar topic (e.g. [
        <xref ref-type="bibr" rid="ref35">53</xref>
        ]). Inexperienced
users tend to pay more attention to detail, while experienced users often engage in energy-saving
behavior, focusing solely on the ultimate goal of site registration, which may lead them to neglect
security concerns.
      </p>
    </sec>
    <sec id="sec-6">
      <title>6. Recommendations and Conclusions</title>
      <p>The paper delves into how human attitudes afect password creation, analyzing various data leaks
to identify common patterns. A questionnaire was conducted to understand user perceptions and
behaviors. Upon analyzing data from known data leaks and a recently created questionnaire, it has
become apparent that despite the passage of time, the methods for creating passwords have remained
unchanged. Even with the implementation of password policies, users still find ways to circumvent them
and rely on predictable patterns. Additionally, even those who claim to be experienced in educating
others on proper password usage have not demonstrated a complete understanding of the issue.</p>
      <p>
        Our research underscores psychology’s potent influence on password creation and security, ofering
strategies for promoting robust passwords. Password policies must prioritize length and diversity,
avoiding common patterns attackers exploit. Avoiding dictionary words is crucial, despite the challenge.
Admins can enhance security by categorizing accounts based on user interaction levels and ofering
guidance on password choices. Monitoring user patterns and banning vulnerable ones can mitigate
risks. Psychological factors like cognitive dissonance contribute to users’ password mistakes, which
can be addressed through techniques like neutralization, as identified by [
        <xref ref-type="bibr" rid="ref40">58</xref>
        ].
      </p>
      <p>Future developments could focus on guiding users to strengthen passwords and improving systems to
overcome neutralization. Suggestions include auto-completing passwords, enhancing password meters,
and developing adaptive policies for usability. Continuous questionnaires could be employed to assess
memory retention.</p>
    </sec>
    <sec id="sec-7">
      <title>Acknowledgments</title>
      <p>The authors would like to thank all the anonymous participants to the questionnaire. This work is
partially supported by projects “SEcurity and RIghts In the CyberSpace - SERICS” (PE00000014 - CUP
H73C2200089001), “Interconnected Nord-Est Innovation Ecosys- tem - iNEST” (ECS00000043 - CUP
H43C22000540006), and PRIN/PNRR “Automatic Modelling and ∀erification of Dedicated sEcUrity
deviceS - AM∀DEUS” (P2022EPPHM - CUP H53D23008130001), all under the National Recovery and
Resilience Plan (NRRP) funded by the European Union - NextGenerationEU.
resource?, Journal of personality and social psychology 74 (1998) 1252.
[19] R. Wash, E. Rader, R. Berman, Z. Wellmer, Understanding password choices: How frequently
entered passwords are re-used across websites, in: Twelfth Symposium on Usable Privacy and
Security (SOUPS 2016), 2016, pp. 175–188.
[20] D. Nelson, K.-P. L. Vu, Efectiveness of image-based mnemonic techniques for enhancing the
memorability and security of user-generated passwords, Computers in Human Behavior 26 (2010)
705–715.
[21] T. F. Brady, T. Konkle, G. A. Alvarez, A. Oliva, Visual long-term memory has a massive storage
capacity for object details, Proceedings of the National Academy of Sciences 105 (2008) 14325–
14329.
[22] C. L. Grady, A. R. McIntosh, M. N. Rajah, F. I. M. Craik, Neural
correlates of the episodic encoding of pictures and words, Proceedings of the
National Academy of Sciences 95 (1998) 2703–2708. doi:10.1073/pnas.95.5.
2703. arXiv:https://www.pnas.org/doi/pdf/10.1073/pnas.95.5.2703,
https://www.pnas.org/doi/abs/10.1073/pnas.95.5.2703.
[23] G. Lu, N. Sebe, C. Xu, C. Kambhamettu, Memory eficient large-scale image-based localization,</p>
      <p>Multimedia Tools and Applications 74 (2014) 479–503. doi:10.1007/s11042-014-1977-3.
[24] D. Marks, Visual imagery diferences and eye movements in the recall of pictures, Perception &amp;</p>
      <p>Psychophysics 14 (1973) 407–412. doi:10.3758/BF03211175.
[25] D. L. Nelson, V. S. Reed, C. L. McEvoy, Learning to order pictures and words: A model of sensory
and semantic encoding., Journal of Experimental Psychology: human learning and memory 3
(1977) 485.
[26] L. Standing, J. Conezio, R. N. Haber, Perception and memory for pictures: Single-trial learning of
2500 visual stimuli, Psychonomic science 19 (1970) 73–74.
[27] C. Merrick, M. Farnia, T. K. Jantz, A. Gazzaley, E. Morsella, External control of the stream of
consciousness: Stimulus-based efects on involuntary thought sequences, Consciousness and
Cognition 33 (2015) 217–225.
[28] G. Matthews, L. Dorn, Cognitive and attentional processes in personality and intelligence, in:</p>
      <p>International handbook of personality and intelligence, Springer, 1995, pp. 367–396.
[29] L. Bošnjak, J. Sreš, B. Brumen, Brute-force and dictionary attack on hashed real-world passwords, in:
2018 41st International Convention on Information and Communication Technology, Electronics
and Microelectronics (MIPRO), 2018, pp. 1161–1166. doi:10.23919/MIPRO.2018.8400211.
[30] B. Hitaj, P. Gasti, G. Ateniese, F. Pérez-Cruz, PassGAN: A Deep Learning Approach for Password
Guessing, in: Int. Conference on Applied Cryptography and Network Security, volume 11464 of
LNCS, Springer, 2019, pp. 217–237.
[31] D. Wang, Z. Zhang, P. Wang, J. Yan, X. Huang, Targeted online password guessing: An
underestimated threat, in: Proc. of the 2016 ACM SIGSAC Conference on Computer and Communications
Security, CCS ’16, ACM, New York, USA, 2016, p. 1242–1254. Https://doi.org/10.1145/2976749.2978339.
[32] B. Ur, F. Noma, J. Bees, S. M. Segreti, R. Shay, L. Bauer, N. Christin, L. F. Cranor, "i added ’!’ at
the end to make it secure": Observing password creation in the lab, in: Eleventh Symposium
On Usable Privacy and Security (SOUPS 2015), USENIX Association, Ottawa, 2015, pp. 123–140.</p>
      <p>Https://www.usenix.org/conference/soups2015/proceedings/presentation/ur.
[33] M. Golla, B. Beuscher, M. Dürmuth, On the security of cracking-resistant password vaults, in:
Proceedings of the 2016 ACM SIGSAC Conference on Computer and Communications Security,
CCS ’16, Association for Computing Machinery, New York, NY, USA, 2016, p. 1230–1241. doi:10.
1145/2976749.2978416, https://doi.org/10.1145/2976749.2978416.
[34] K. Blashki, S. Nichol, Game geek’s goss: Linguistic creativity in young males within an online
university forum (94//3 933k’5 9055oneone), Australian Journal of Emerging Technologies and
Society 3 (2005).
[35] H.-C. Chou, H.-C. Lee, H.-J. Yu, F.-P. Lai, K.-H. Huang, C.-W. Hsueh, et al., Password cracking
based on learned patterns from disclosed passwords, IJICIC 9 (2013) 821–839.
[36] W. Li, J. Zeng, Leet usage and its efect on password security, IEEE Transactions on Information</p>
      <p>A. Appendix
# 1 ! &lt; 1 i ;
h i i k l l l o
0
q
9
s
5
s
$
t
+
v
&gt;
v
&lt;
x
%
y
?
w
uu
w</p>
      <sec id="sec-7-1">
        <title>Question</title>
        <p>Informations about participants
Do you often reuse the same
password?
When you create a password you
think it must be:
If you think a password should be
easy to remember it’s because
Do you frequently reuse passwords
with variations like substituting
letters with numbers or symbols?
Do you use password manager?
What is the pattern you use the
most when creating a password?
Categories of words
Choose which of the two passwords
is more secure in your opinion
Select who you believe is more
likely to steal one of your passwords
What do you think a malicious user
does to try to guess your password?
Why would an attacker try to guess
your password?
Enter a password for registration
on this site (dog.com, cd.com,
leonardo.com), Minimum 6
characters with lowercase, uppercase,
symbols, and numbers. Enter a
password at least 8 characters long
with upper and lower case letters,
numbers, and symbols.
Easy to remember, safe, or both
I’m afraid to forget it 59.3%; all sites ask me for the same pattern
so I don’t want to waste time thinking about a new password
28.9%; when I think about a new password, one that I use often
comes to mind 20.1%; I have no imagination 9.8%; doing "recover
password" bothers me 23.2%
Yes 64.5%, No 35.5%
Yes 21.7%, No 78.3%
Table 2a show participants’ answers
Table 7 shows how many people answered that use the proposed
category
Table 3 shows which passwords were perceived to be stronger
and which actually were
A stranger 65.4%; a family member 24%; a friend 21.7%; a
colleague 16.6%; other people I know 21.2%
Uses software 73.3%; uses brute force 29.5%; tries the most
used and known words and names in my language 33.2%; tries
common passwords 41.9%; tries dates and numbers 38.7%
Financial reward 44%; to collects personal information 73.6%;
for identity theft 64.8%; fun / proof they can 35.2%; spamming
19.9%; espionage 20.8%
Table 2b reports the results of the analysis we conducted on the
responses</p>
      </sec>
    </sec>
  </body>
  <back>
    <ref-list>
      <ref id="ref1">
        <mixed-citation>
          [1]
          <string-name>
            <given-names>P. G.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Vidas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lopez</surname>
          </string-name>
          ,
          <article-title>Guess again (and again and again): Measuring password strength by simulating passwordcracking algorithms</article-title>
          ,
          <source>in: 2012 IEEE Symposium on Security and Privacy</source>
          ,
          <year>2012</year>
          , pp.
          <fpage>523</fpage>
          -
          <lpage>537</lpage>
          . doi:
          <volume>10</volume>
          .1109/SP.
          <year>2012</year>
          .
          <volume>38</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref2">
        <mixed-citation>
          [2]
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. G.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          , S. Egelman,
          <article-title>Of passwords and people: Measuring the efect of password-composition policies</article-title>
          ,
          <source>in: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems, CHI '11</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2011</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref3">
        <mixed-citation>
          [3]
          <string-name>
            <given-names>W.</given-names>
            <surname>Melicher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          , Fast, Lean, and
          <article-title>Accurate: Modeling Password Guessability Using Neural Networks, in: 25th USENIX Security Symposium</article-title>
          , USENIX Association,
          <year>2016</year>
          , pp.
          <fpage>175</fpage>
          -
          <lpage>191</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref4">
        <mixed-citation>
          [4]
          <string-name>
            <given-names>A.</given-names>
            <surname>Narayanan</surname>
          </string-name>
          ,
          <string-name>
            <given-names>V.</given-names>
            <surname>Shmatikov</surname>
          </string-name>
          ,
          <article-title>Fast Dictionary Attacks on Passwords Using Time-Space Tradeof</article-title>
          ,
          <source>in: Proceedings of the 12th ACM Conference on Computer and Communications Security, ACM</source>
          ,
          <year>2005</year>
          , p.
          <fpage>364</fpage>
          -
          <lpage>372</lpage>
          . Https://doi.org/10.1145/1102120.1102168.
        </mixed-citation>
      </ref>
      <ref id="ref5">
        <mixed-citation>
          [5]
          <string-name>
            <given-names>D.</given-names>
            <surname>Pasquini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Gangwal</surname>
          </string-name>
          , G. Ateniese,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bernaschi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Conti</surname>
          </string-name>
          ,
          <article-title>Improving password guessing via representation learning</article-title>
          ,
          <source>in: 42nd IEEE Symposium on Security and Privacy</source>
          , IEEE,
          <year>2021</year>
          , pp.
          <fpage>1382</fpage>
          -
          <lpage>1399</lpage>
          . Https://doi.org/10.1109/SP40001.
          <year>2021</year>
          .
          <volume>00016</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref6">
        <mixed-citation>
          [6]
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P. G.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Lee</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Maass</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Passaro</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>T.</given-names>
            <surname>Vidas</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <article-title>How Does Your Password Measure Up? The Efect of Strength Meters on Password Creation</article-title>
          ,
          <source>in: Proceedings of the 21th USENIX Security Symposium, USENIX Association</source>
          ,
          <year>2012</year>
          , pp.
          <fpage>65</fpage>
          -
          <lpage>80</lpage>
          . Https://www.usenix.org/conference/usenixsecurity12/technicalsessions/presentation/ur.
        </mixed-citation>
      </ref>
      <ref id="ref7">
        <mixed-citation>
          [7]
          <string-name>
            <given-names>A. M.</given-names>
            <surname>Di Campi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Focardi</surname>
          </string-name>
          ,
          <string-name>
            <given-names>F. L.</given-names>
            <surname>Luccio</surname>
          </string-name>
          ,
          <article-title>The revenge of password crackers: Automated training of password cracking tools</article-title>
          , in: V.
          <string-name>
            <surname>Atluri</surname>
            ,
            <given-names>R. Di</given-names>
          </string-name>
          <string-name>
            <surname>Pietro</surname>
            ,
            <given-names>C. D.</given-names>
          </string-name>
          <string-name>
            <surname>Jensen</surname>
          </string-name>
          , W. Meng (Eds.),
          <source>Computer Security - ESORICS 2022</source>
          , Springer Nature Switzerland, Cham,
          <year>2022</year>
          , pp.
          <fpage>317</fpage>
          -
          <lpage>336</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref8">
        <mixed-citation>
          [8]
          <string-name>
            <given-names>D.</given-names>
            <surname>Pasquini</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Cianfriglia</surname>
          </string-name>
          , G. Ateniese,
          <string-name>
            <given-names>M.</given-names>
            <surname>Bernaschi</surname>
          </string-name>
          ,
          <article-title>Reducing Bias in Modeling Real-world Password Strength via Deep Learning and Dynamic Dictionaries, in: 30th USENIX Security Symposium</article-title>
          , USENIX Association,
          <year>2021</year>
          , pp.
          <fpage>821</fpage>
          -
          <lpage>838</lpage>
          . Https://www.usenix.org/conference/usenixsecurity21/presentation/pasquini.
        </mixed-citation>
      </ref>
      <ref id="ref9">
        <mixed-citation>
          [9]
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Kurilova</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Melicher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <source>Measuring Real-World Accuracies and Biases in Modeling Password Guessability, in: Proceedings of the 24th USENIX Conference on Security Symposium, USENIX Association</source>
          ,
          <year>2015</year>
          , p.
          <fpage>463</fpage>
          -
          <lpage>481</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref10">
        <mixed-citation>
          [10]
          <string-name>
            <given-names>H.</given-names>
            <surname>Habib</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Colnago</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Melicher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          , L. Cranor,
          <article-title>Password creation in the presence of blacklists</article-title>
          , in: Workshop on Usable Security, USEC, volume
          <volume>17</volume>
          ,
          <year>2017</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref11">
        <mixed-citation>
          [11]
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Kelley</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Cranor</surname>
          </string-name>
          , S. Egelman,
          <article-title>Of passwords and people: measuring the efect of password-composition policies</article-title>
          ,
          <source>in: Proceedings of the sigchi conference on human factors in computing systems</source>
          ,
          <year>2011</year>
          , pp.
          <fpage>2595</fpage>
          -
          <lpage>2604</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref12">
        <mixed-citation>
          [12]
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A. L.</given-names>
            <surname>Durity</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Huh</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <article-title>Can long passwords be secure and usable?</article-title>
          ,
          <source>in: Proceedings of the SIGCHI Conference on Human Factors in Computing Systems</source>
          ,
          <year>2014</year>
          , pp.
          <fpage>2927</fpage>
          -
          <lpage>2936</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref13">
        <mixed-citation>
          [13]
          <string-name>
            <given-names>R.</given-names>
            <surname>Shay</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Forget</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Komanduri</surname>
          </string-name>
          ,
          <string-name>
            <given-names>M. L.</given-names>
            <surname>Mazurek</surname>
          </string-name>
          ,
          <string-name>
            <given-names>W.</given-names>
            <surname>Melicher</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <article-title>A spoonful of sugar? the impact of guidance and feedback on passwordcreation behavior</article-title>
          ,
          <source>in: Proceedings of the 33rd Annual ACM Conference on Human Factors in Computing Systems</source>
          ,
          <year>2015</year>
          , pp.
          <fpage>2903</fpage>
          -
          <lpage>2912</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref14">
        <mixed-citation>
          [14]
          <string-name>
            <given-names>L.</given-names>
            <surname>Festinger</surname>
          </string-name>
          , Cognitive dissonance,
          <source>Scientific American</source>
          <volume>207</volume>
          (
          <year>1962</year>
          )
          <fpage>93</fpage>
          -
          <lpage>106</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref15">
        <mixed-citation>
          [15]
          <string-name>
            <surname>A. M. Di Campi</surname>
          </string-name>
          ,
          <article-title>Password guessing: learn the nature of passwords by studying the human behavior (</article-title>
          <year>2021</year>
          ).
        </mixed-citation>
      </ref>
      <ref id="ref16">
        <mixed-citation>
          [16]
          <string-name>
            <given-names>M.</given-names>
            <surname>Siponen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>P.</given-names>
            <surname>Puhakainen</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Vance</surname>
          </string-name>
          ,
          <article-title>Can individuals' neutralization techniques be overcome? a ifeld experiment on password policy</article-title>
          ,
          <source>Computers &amp; Security</source>
          <volume>88</volume>
          (
          <year>2020</year>
          )
          <fpage>101617</fpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref17">
        <mixed-citation>
          [17]
          <string-name>
            <given-names>T.</given-names>
            <surname>Groß</surname>
          </string-name>
          ,
          <string-name>
            <given-names>K.</given-names>
            <surname>Coopamootoo</surname>
          </string-name>
          ,
          <string-name>
            <given-names>A.</given-names>
            <surname>Al-Jabri</surname>
          </string-name>
          ,
          <article-title>Efect of cognitive depletion on password choice</article-title>
          ,
          <source>in: The LASER Workshop: Learning from Authoritative Security Experiment Results (LASER</source>
          <year>2016</year>
          ),
          <year>2016</year>
          , pp.
          <fpage>55</fpage>
          -
          <lpage>66</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref18">
        <mixed-citation>
          [18]
          <string-name>
            <given-names>R. F.</given-names>
            <surname>Baumeister</surname>
          </string-name>
          , E. Bratslavsky,
          <string-name>
            <given-names>M.</given-names>
            <surname>Muraven</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D. M.</given-names>
            <surname>Tice</surname>
          </string-name>
          ,
          <article-title>Ego depletion: Is the active self a limited Forensics and Security 16 (</article-title>
          <year>2021</year>
          )
          <fpage>2130</fpage>
          -
          <lpage>2143</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref19">
        <mixed-citation>
          [37]
          <string-name>
            <given-names>N.</given-names>
            <surname>Ross</surname>
          </string-name>
          ,
          <article-title>Writing in the information age</article-title>
          ,
          <source>English Today</source>
          <volume>22</volume>
          (
          <year>2006</year>
          )
          <fpage>39</fpage>
          -
          <lpage>45</lpage>
          . doi:
          <volume>10</volume>
          .1017/ S0266078406003063.
        </mixed-citation>
      </ref>
      <ref id="ref20">
        <mixed-citation>
          [38]
          <string-name>
            <given-names>M.</given-names>
            <surname>Weir</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S.</given-names>
            <surname>Aggarwal</surname>
          </string-name>
          , B. de Medeiros,
          <string-name>
            <given-names>B.</given-names>
            <surname>Glodek</surname>
          </string-name>
          ,
          <article-title>Password cracking using probabilistic context-free grammars</article-title>
          ,
          <year>2009</year>
          , pp.
          <fpage>391</fpage>
          -
          <lpage>405</lpage>
          . doi:
          <volume>10</volume>
          .1109/SP.
          <year>2009</year>
          .
          <volume>8</volume>
          .
        </mixed-citation>
      </ref>
      <ref id="ref21">
        <mixed-citation>
          [39]
          <string-name>
            <given-names>D. L.</given-names>
            <surname>Wheeler</surname>
          </string-name>
          ,
          <article-title>zxcvbn:low-budget password strength estimation</article-title>
          ,
          <source>in: 25th USENIX Security Symposium (USENIX Security 16)</source>
          ,
          <year>2016</year>
          , pp.
          <fpage>157</fpage>
          -
          <lpage>173</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref22">
        <mixed-citation>
          [40]
          <string-name>
            <given-names>M.</given-names>
            <surname>Vainer</surname>
          </string-name>
          ,
          <article-title>Password Dataset Generation for Further Analysis by Machine Learning Methods</article-title>
          ,
          <source>Ph.D. thesis</source>
          ,
          <year>2022</year>
          . doi:
          <volume>10</volume>
          .13140/RG.2.2.16711.16805.
        </mixed-citation>
      </ref>
      <ref id="ref23">
        <mixed-citation>
          [41]
          <string-name>
            <given-names>R. V.</given-names>
            <surname>Guimarães</surname>
          </string-name>
          ,
          <article-title>An investigation of semantic patterns in passwords, 2013</article-title>
          . URL: https://api. semanticscholar.org/CorpusID:51963378.
        </mixed-citation>
      </ref>
      <ref id="ref24">
        <mixed-citation>
          [42]
          <string-name>
            <surname>Kali</surname>
            <given-names>Linux</given-names>
          </string-name>
          , Rockyou dataset, https://gitlab.com/kalilinux/packages/wordlists,
          <source>Accessed April</source>
          <year>2022</year>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref25">
        <mixed-citation>
          [43]
          <string-name>
            <surname>Hotmail</surname>
          </string-name>
          , Hotmail dataset, https://github.com/danielmiessler/SecLists/blob/master/Passwords/ Leaked-Databases/hotmail.txt,
          <source>Accessed April</source>
          <year>2022</year>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref26">
        <mixed-citation>
          [44] phpBB, phpbb dataset, https://github.com/danielmiessler/SecLists/blob/master/Passwords/ Leaked-Databases/phpbb.txt,
          <source>Accessed April</source>
          <year>2022</year>
          ,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref27">
        <mixed-citation>
          [45]
          <string-name>
            <surname>Ashley</surname>
            <given-names>Madison</given-names>
          </string-name>
          , Ashley madison dataset, https://github.com/danielmiessler/SecLists/blob/master/ Passwords/Leaked-Databases/Ashley-Madison.txt,
          <source>Accessed April</source>
          <year>2022</year>
          ,
          <year>2020</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref28">
        <mixed-citation>
          [46] pkLazer, 4000 Most common english words, https://github.com/pkLazer/password_rank/blob/ master/4000-most
          <article-title>-common-english-words-csv</article-title>
          .csv,
          <source>Accessed April</source>
          <year>2022</year>
          ,
          <year>2013</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref29">
        <mixed-citation>
          [47]
          <article-title>Compute.io, Common english female name</article-title>
          , https://github.com/datasets-io/
          <article-title>female-first-names-</article-title>
          <string-name>
            <surname>en</surname>
          </string-name>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref30">
        <mixed-citation>
          [48]
          <article-title>Compute.io, Common english male name</article-title>
          , https://github.com/datasets-io/
          <article-title>female-first-names-</article-title>
          <string-name>
            <surname>en</surname>
          </string-name>
          ,
          <year>2015</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref31">
        <mixed-citation>
          [49]
          <string-name>
            <surname>PenTestical</surname>
          </string-name>
          , Common german names, https://github.com/PenTestical/german_names,
          <year>2019</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref32">
        <mixed-citation>
          [50] marcboquet, Common spanish names, https://github.com/marcboquet/spanish-names,
          <year>2012</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref33">
        <mixed-citation>
          [51]
          <string-name>
            <surname>E. I. Tatli</surname>
          </string-name>
          ,
          <article-title>Cracking more password hashes with patterns</article-title>
          ,
          <source>IEEE Transactions on Information Forensics and Security</source>
          <volume>10</volume>
          (
          <year>2015</year>
          )
          <fpage>1656</fpage>
          -
          <lpage>1665</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref34">
        <mixed-citation>
          [52]
          <string-name>
            <surname>V. I. Levenshtein</surname>
          </string-name>
          ,
          <article-title>Binary codes capable of correcting deletions, insertions, and reversals</article-title>
          ,
          <source>Soviet physics. Doklady</source>
          <volume>10</volume>
          (
          <year>1965</year>
          )
          <fpage>707</fpage>
          -
          <lpage>710</lpage>
          .
        </mixed-citation>
      </ref>
      <ref id="ref35">
        <mixed-citation>
          [53]
          <string-name>
            <given-names>B.</given-names>
            <surname>Ur</surname>
          </string-name>
          ,
          <string-name>
            <given-names>J.</given-names>
            <surname>Bees</surname>
          </string-name>
          ,
          <string-name>
            <given-names>S. M.</given-names>
            <surname>Segreti</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L.</given-names>
            <surname>Bauer</surname>
          </string-name>
          ,
          <string-name>
            <given-names>N.</given-names>
            <surname>Christin</surname>
          </string-name>
          ,
          <string-name>
            <given-names>L. F.</given-names>
            <surname>Cranor</surname>
          </string-name>
          , Do Users'
          <article-title>Perceptions of Password Security Match Reality?</article-title>
          ,
          <source>in: Proceedings of the 2016 CHI Conference on Human Factors in Computing Systems, CHI '16</source>
          ,
          <string-name>
            <surname>Association</surname>
          </string-name>
          for Computing Machinery, New York, NY, USA,
          <year>2016</year>
          , p.
          <fpage>3748</fpage>
          -
          <lpage>3760</lpage>
          . Https://doi.org/10.1145/2858036.2858546.
        </mixed-citation>
      </ref>
      <ref id="ref36">
        <mixed-citation>
          [54]
          <string-name>
            <surname>Sant'Uberto</surname>
          </string-name>
          ,
          <article-title>Tutto il mondo del cane in un click</article-title>
          , https://cani.com/,
          <year>2023</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref37">
        <mixed-citation>
          [55]
          <string-name>
            <surname>Dvd-store</surname>
          </string-name>
          , Dvd-store,
          <volume>20</volume>
          anni,
          <fpage>2003</fpage>
          -
          <lpage>2023</lpage>
          , https://www.dvd-store.it/,
          <year>2003</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref38">
        <mixed-citation>
          [56]
          <string-name>
            <surname>Leonardo</surname>
          </string-name>
          , Leonardo elicotteri, https://helicopters.leonardo.com/it/home,
          <year>2022</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref39">
        <mixed-citation>
          [57]
          <string-name>
            <surname>IBM</surname>
          </string-name>
          , Ibm-spss, https://www.ibm.com/,
          <year>2024</year>
          .
        </mixed-citation>
      </ref>
      <ref id="ref40">
        <mixed-citation>
          [58]
          <string-name>
            <given-names>G. M.</given-names>
            <surname>Sykes</surname>
          </string-name>
          ,
          <string-name>
            <given-names>D.</given-names>
            <surname>Matza</surname>
          </string-name>
          ,
          <article-title>Techniques of neutralization: A theory of delinquency, American sociological review 22 (</article-title>
          <year>1957</year>
          )
          <fpage>664</fpage>
          -
          <lpage>670</lpage>
          .
        </mixed-citation>
      </ref>
    </ref-list>
  </back>
</article>