Analysis of Password Security Policies and Their Implications on Real-Life Security
Jasmin Redžepagić, Vedran Dakić, Josip Stanešić and Matej Bašić. Analysis of Password Security Policies and Their Implications on Real-Life Security. Proceedings of the 34th DAAAM International Symposium, 77–81, 2023.
Abstract
This paper examines current password security guidelines and best practices, as well as their effectiveness in preventing unauthorized access and data breaches. The research also explores the impact of these policies on user behaviour and the potential trade-offs between security and user experience. The focus is especially on password length and mandatory change requirements since the best practices conflict across different standards. The findings of this study have important implications for organizations in developing and implementing password security policies that effectively balance security and usability. The research will compare different criteria on what defines a “good” password and by applying different password analysis methods establish what objectively should be used in real-world scenarios.
My contribution
Joint work with Jasmin Redžepagić, Vedran Dakić and Josip Stanešić on what password length and rotation rules are worth in practice, where the standards disagree. The proceedings carry no author contribution statement, so I have not put a claim here yet.