Password Strength Needs a Boost

執筆者
Brian Prince
Brian Prince
Published: Oct 16, 2009
Updated: Feb 2, 2021
2 minute read
eWeek のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

When it comes to passwords, users are often the weakest link in the chain.

According to a survey by researchers at the University of Wisconsin-Madison and IT University in Copenhagen found that just four percent of the people surveyed obeyed best practices for passwords. The survey focused on 836 staff members at company handling “very sensitive private information.”

What the academics uncovered was that just four percent of those surveyed obeyed best practice rules for passwords. Others frequently did not, doing things such as using the same passwords for different systems or writing their passwords down on post-it notes.

“On an average, respondents have different 4.1 passwords to logon to different computers and/or access different computer applications at work,” the researchers state in their paper. “If we include passwords used at home that number increases to 9. Eighteen percent of the respondents always use the same password to access the different computer systems, application or websites, 50% sometimes use the same password and sometimes another password, and 31% always use different passwords.”

This study comes on the back of an analysis of the strength of a batch of stolen passwords Acunetix. The company found similarly that many users were utilizing weak passwords to protect their Microsoft Hotmail accounts.

Just what to do about this, beyond continuing user education, is anybody’s guess. But the report from IT University and the University of Wisconsin-Madison suggests it may be time to abandon code words for pictures.

“There are also other solutions to overcome human limitations,” the report states. “For example several studies have shown that human beings are better at recognizing pictures than words or sentences and pictures are better stored in the long-term memory…Most efficient are two- or three step authentication methods, for example a combination of a token based ands knowledge-based authentication (for example a smart card in combination with a PIN number), a combination of biometrics and passwords, or a combination of token-based authentication and biometrics, depending

on the level of security needed.”

The question is, is your enterprise doing enough?

Brian Prince

Brian Prince

Content Writer
eWeek Logo

eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site's focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。