• DocumentCode
    652233
  • Title

    Exploring the Guessability of Image Passwords Using Verbal Descriptions

  • Author

    Chowdhury, Shuvro ; Poet, Ron ; Mackenzie, Lewis

  • Author_Institution
    Sch. of Comput. Sci., Univ. of Glasgow, Glasgow, UK
  • fYear
    2013
  • fDate
    16-18 July 2013
  • Firstpage
    768
  • Lastpage
    775
  • Abstract
    One claimed advantage of the image passwords used in recognition based graphical authentication systems (RBGSs) over text passwords is that they cannot be written down or verbally disclosed. However, there is no empirical evidence to support this claim. In this paper, we present the first published comparison of the vulnerability of four different image types -Mikon, doodle, art and everyday object images to verbal/spoken descriptions, when used as passwords in RBGS. This paper considers one of the human factors in security i.e. password sharing through spoken descriptions. The user study conducted with 126 participants (56 callers/ describer and 70 listeners/ attacker) measures how easy it is for an attacker to guess a password in a RBGS, if the passwords are verbally described. The experimental set up is a two way dialogue between a caller and a listener over telephone using repeated measures protocol, which measures mean successful login percentage. The results of the study show the object images to be most guessable, and doodles follow close behind. Mikon images are less guessable than doodle followed by art images, which are the least guessable. We believe that unless, the human factors in security like the one considered in this paper is taken into account, the RBGSs will always look secure on paper, but fail in practice.
  • Keywords
    human factors; image coding; security of data; Mikon image; RBGS; art image; doodle image; everyday object images; human factors; image password guessability; password sharing; recognition based graphical authentication systems; repeated measure protocol; spoken descriptions; text passwords; verbal descriptions; Art; Authentication; Educational institutions; Electronic mail; Image recognition; Protocols; graphical authentication; guessability study; human factors in security; image passwords; password disclosure; verbal descriptions;
  • fLanguage
    English
  • Publisher
    ieee
  • Conference_Titel
    Trust, Security and Privacy in Computing and Communications (TrustCom), 2013 12th IEEE International Conference on
  • Conference_Location
    Melbourne, VIC
  • Type

    conf

  • DOI
    10.1109/TrustCom.2013.93
  • Filename
    6680913