{"id":6386,"date":"2014-10-20T12:30:13","date_gmt":"2014-10-20T16:30:13","guid":{"rendered":"https:\/\/www.kaspersky.com\/blog\/?p=6386"},"modified":"2020-02-26T10:56:45","modified_gmt":"2020-02-26T15:56:45","slug":"remember-strong-passwords","status":"publish","type":"post","link":"https:\/\/www.kaspersky.com\/blog\/remember-strong-passwords\/6386\/","title":{"rendered":"How to Remember Strong, Unique Passwords"},"content":{"rendered":"<p>It\u2019s 2014. Lockheed Martin recently announced that it is making real progress towards developing a compact nuclear fusion reactor capable of providing unimaginably vast supplies of energy, in exchange for a couple handfuls of clean, somewhat easily available fuel. And yet, we\u2019re still stuck memorizing ever-longer <a href=\"https:\/\/www.kaspersky.com\/blog\/21st-century-passwords\/\" target=\"_blank\" rel=\"noopener nofollow\">lists of passwords<\/a> like it\u2019s 1999. If we\u2019re going to rely on an ancient authenticator for future technology, then we might as well come up with a solid way to remember our passwords. This is exactly what our friends at <a href=\"https:\/\/www.kaspersky.com\/blog\/video-2-privacy-and-bad-bargains\/\" target=\"_blank\" rel=\"noopener nofollow\">Carnegie Mellon<\/a> University\u2019s computer science department have done.<\/p>\n<p>Unfortunately, it turns out that remembering long lists of complicated <a href=\"https:\/\/www.kaspersky.com\/blog\/heartbeat-authentication\/\" target=\"_blank\" rel=\"noopener nofollow\">passwords<\/a> requires us to do something that no one likes: study. According to research developed by Jeremiah Blocki, Saranga Komanduri, Lorrie Cranor and Anupam Datta, a system of spaced repetition paired with mnemonics, increases the likelihood that users will remember their passwords over long periods of time.<\/p>\n<p>The password construction element of this reminds us of the following <a href=\"http:\/\/xkcd.com\/936\/\" target=\"_blank\" rel=\"noopener nofollow\">XKCD comic about password strength<\/a>, which is to say, think sentences rather than words with <a href=\"http:\/\/en.wikipedia.org\/wiki\/leet\" target=\"_blank\" rel=\"noopener nofollow\">leetspeak<\/a>.<\/p>\n<p><a href=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2014\/10\/06015632\/password_strength.jpg\"><img decoding=\"async\" class=\"aligncenter wp-image-4187\" src=\"https:\/\/media.kasperskydaily.com\/wp-content\/uploads\/sites\/92\/2014\/10\/06015632\/password_strength.jpg\" alt=\"password_strength\" width=\"540\" height=\"439\"><\/a><\/p>\n<p>The participants in the Carnegie Mellon study were made to choose a person from a drop down menu that would be assigned with machine-generated random action and object pair. This method is known as a person-action-object (PAO) story. So you get something like this:\u201dMaster Yoda dropping a microphone.\u201d<\/p>\n<p>The mnemonic device at play here is that the participants in the study were also shown a picture of a setting in which to imagine their person-action-object story occurring. Let\u2019s say that the picture associated with our story is of an underwater laboratory. In this way we end up with a sentence like \u201cMaster Yoda dropping a microphone in an underwater laboratory\u201d.<\/p>\n<p>So you have six words and the password you can construct from these words is strong enough \u2014you can make sure at <a href=\"https:\/\/www.kaspersky.com\/blog\/password-check\/\" target=\"_blank\" rel=\"noopener nofollow\">our Secure Password Check page<\/a>. The point of the mnemonic technique is that you don\u2019t have to remember the entire sentence.<\/p>\n<p>In this study, participants were prompted with a scene and person pair (Master Yoda in an underwater laboratory) and were made to perform a rehearsal routine to recall the action and the object at a set number of spaced intervals over a period of 100 or so days. The specific intervals for these rehearsal rituals, and the number of passwords (either one, two or four) a given user was expected to recall, varied from one trial group to the next.<\/p>\n<p>The users with the best results were those that initially rehearsed after 12 hours and then in 12\u00d71.5 hour increasing intervals (0.5 days, 1.75 days, 4.15 days, 8.15 days, 14.65 days, 24.65 days, 40.65 days, 64.65 days and 101.65 days). In that group, 77.1 percent of the participants successfully recalled all 4 stories in 9 tests over a period of 102 days.<\/p>\n<div class=\"pullquote\">\u201cI suppose you could say that I was a little bit surprised. If you had forced me to guess which condition would yield the best results before the study, I probably would have guessed the 30minX2, though I would not have been entirely confident.\u201d<\/div>\n<p>I reached out to Blocki and asked if he was surprised by the results.<\/p>\n<p>\u201cI suppose you could say that I was a little bit surprised,\u201dhe said. \u201cIf you had forced me to guess which condition would yield the best results before the study, I probably would have guessed the 30minX2, though I would not have been entirely confident. Yes, the 12hrX1.5 group had a longer initial rehearsal interval. However, the intervals between successive rehearsals did not increase quite as quickly as they did in the 30minX2 condition. The results indicate that the spacing of rehearsals is significant (not just the total number of prior rehearsals).\u201d<\/p>\n<p>Incidentally, most of the forgetting happened in that first 12-hour period. Some 94.9 percent of participants who remembered stories in the early rounds, continued to remember them in subsequent rounds. Not surprisingly, the recall rate for participants asked to remember one or two stories was substantially better than those that were asked to remember four stories.<\/p>\n<blockquote class=\"twitter-pullquote\"><p>Remembering long lists of #passwords require us to do something we all hate: study.<\/p><a href=\"https:\/\/twitter.com\/share?url=https%3A%2F%2Fkas.pr%2FUCc3&amp;text=Remembering+long+lists+of+%23passwords+require+us+to+do+something+we+all+hate%3A+study.\" class=\"btn btn-twhite\" data-lang=\"en\" data-count=\"0\" target=\"_blank\" rel=\"noopener nofollow\">Tweet<\/a><\/blockquote>\n<p>There is a lot going on in this study, titled \u201c<a href=\"http:\/\/arxiv.org\/pdf\/1410.1490v1.pdf\" target=\"_blank\" rel=\"noopener nofollow\">Spaced Repetition and Mnemonics Enable Recall of Multiple Strong Passwords<\/a>,\u201d[PDF]. Feel free to wade through it on your own, but be warned, there are a lot of spooky math problems going on in there.<\/p>\n<p>So what did we learn today? First of all we learned it\u2019s easier to remember fewer passwords. Which is probably why nearly everyone uses the same password across multiple accounts, despite knowing that password sharing is a bad idea. In other words, passwords remain desperately flawed.<\/p>\n<p>http:\/\/instagram.com\/p\/ubLd60P0Lv\/<\/p>\n<p>But there is also good news \u2014you can improve your passwords using the relatively easy mnemonic technique:<\/p>\n<ul>\n<li>Create story passwords that you can associate with a picture.<\/li>\n<li>It\u2019s not simple, but avoid password sharing.<\/li>\n<li>Study your passwords early and often for the rest of your natural born life. Or at least until a data breach happens and you have to start all over again.<\/li>\n<\/ul>\n<p>And may <a href=\"https:\/\/www.kaspersky.com\/advert\/free-trials\/multi-device-security?redef=1&amp;THRU&amp;reseller=blog_en-global\" target=\"_blank\" rel=\"noopener nofollow\">the force be with you<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>New research shows that studying and mnemonic devices could help us to better remember our passwords.<\/p>\n","protected":false},"author":42,"featured_media":6387,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[5,9],"tags":[359,187,732,97],"class_list":{"0":"post-6386","1":"post","2":"type-post","3":"status-publish","4":"format-standard","5":"has-post-thumbnail","7":"category-news","8":"category-tips","9":"tag-authentication","10":"tag-passwords","11":"tag-research","12":"tag-security-2"},"hreflang":[{"hreflang":"x-default","url":"https:\/\/www.kaspersky.com\/blog\/remember-strong-passwords\/6386\/"},{"hreflang":"en-in","url":"https:\/\/www.kaspersky.co.in\/blog\/remember-strong-passwords\/4267\/"},{"hreflang":"en-ae","url":"https:\/\/me-en.kaspersky.com\/blog\/remember-strong-passwords\/4184\/"},{"hreflang":"en-us","url":"https:\/\/usa.kaspersky.com\/blog\/remember-strong-passwords\/4703\/"},{"hreflang":"en-gb","url":"https:\/\/www.kaspersky.co.uk\/blog\/remember-strong-passwords\/4955\/"},{"hreflang":"ja","url":"https:\/\/blog.kaspersky.co.jp\/remember-strong-passwords\/5165\/"},{"hreflang":"en-au","url":"https:\/\/www.kaspersky.com.au\/blog\/remember-strong-passwords\/6386\/"},{"hreflang":"en-za","url":"https:\/\/www.kaspersky.co.za\/blog\/remember-strong-passwords\/6386\/"}],"acf":[],"banners":"","maintag":{"url":"https:\/\/www.kaspersky.com\/blog\/tag\/authentication\/","name":"Authentication"},"_links":{"self":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6386","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/users\/42"}],"replies":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/comments?post=6386"}],"version-history":[{"count":5,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6386\/revisions"}],"predecessor-version":[{"id":33354,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/posts\/6386\/revisions\/33354"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media\/6387"}],"wp:attachment":[{"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/media?parent=6386"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/categories?post=6386"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.kaspersky.com\/blog\/wp-json\/wp\/v2\/tags?post=6386"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}