The Password Game: Negative Externalities from Weak Password Practices

  • Sören Preibusch
  • Joseph Bonneau
Conference paper

DOI: 10.1007/978-3-642-17197-0_13

Volume 6442 of the book series Lecture Notes in Computer Science (LNCS)
Cite this paper as:
Preibusch S., Bonneau J. (2010) The Password Game: Negative Externalities from Weak Password Practices. In: Alpcan T., Buttyán L., Baras J.S. (eds) Decision and Game Theory for Security. GameSec 2010. Lecture Notes in Computer Science, vol 6442. Springer, Berlin, Heidelberg

Abstract

The combination of username and password is widely used as a human authentication mechanism on the Web. Despite this universal adoption and despite their long tradition, password schemes exhibit a high number of security flaws which jeopardise the confidentiality and integrity of personal information. As Web users tend to reuse the same password for several sites, security negligence at any one site introduces a negative externality into the entire password ecosystem. We analyse this market inefficiency as the equilibrium between password deployment strategies at security-concerned Web sites and indifferent Web sites.

The game-theoretic prediction is challenged by an empirical analysis. By a manual inspection of 150 public Web sites that offer free yet password-protected sign-up, complemented by an automated sampling of 2184 Web sites, we demonstrate that observed password practices follow the theory: Web sites that have little incentive to invest in security are indeed found to have weaker password schemes, thereby facilitating the compromise of other sites. We use the theoretical model to explore which technical and regulatory approaches could eliminate the empirically detected inefficiency in the market for password protection.

Preview

Unable to display preview. Download preview PDF.

Unable to display preview. Download preview PDF.

Copyright information

© Springer-Verlag Berlin Heidelberg 2010

Authors and Affiliations

  • Sören Preibusch
    • 1
  • Joseph Bonneau
    • 1
  1. 1.Computer LaboratoryUniversity of CambridgeCambridgeUK