Authentication systems often rely on individuals' ability to remember and accurately input complex passwords in digital environments. However, this task becomes impractical as the demand for higher security measures increases. Researchers have proposed several methods to improve password authentication over the years, yet most methods come with a trade-off between security and usability. Password managers are a well-known solution to make password security usable, but they introduce a widely discussed risk: if a password-manager (PM) vault is compromised, many accounts can be affected at once. This work augments passwords stored in PMs with a user-held secret to improve resilience in a vault-only compromise setting. The user's login secret is obtained by combining what is stored in the PM with a mnemonic remembered by the user, while the password stored in the PM serves as a decoy that can trigger an alarm indicating potential PM compromise. We conducted a user study using Mindlock, a browser-extension prototype that acts as a mnemonic application interface, to evaluate feasibility and usability in real login routines. Our study provides preliminary evidence that users can adopt mnemonic-based augmentation with limited impact on usability, and we discuss the security implications under a rate-limited online threat model.

Revamping Password Security: Leveraging Mnemonics for Enhanced Authentication

Giovanetti, Davide;Dell'Amico, Matteo;
2026-01-01

Abstract

Authentication systems often rely on individuals' ability to remember and accurately input complex passwords in digital environments. However, this task becomes impractical as the demand for higher security measures increases. Researchers have proposed several methods to improve password authentication over the years, yet most methods come with a trade-off between security and usability. Password managers are a well-known solution to make password security usable, but they introduce a widely discussed risk: if a password-manager (PM) vault is compromised, many accounts can be affected at once. This work augments passwords stored in PMs with a user-held secret to improve resilience in a vault-only compromise setting. The user's login secret is obtained by combining what is stored in the PM with a mnemonic remembered by the user, while the password stored in the PM serves as a decoy that can trigger an alarm indicating potential PM compromise. We conducted a user study using Mindlock, a browser-extension prototype that acts as a mnemonic application interface, to evaluate feasibility and usability in real login routines. Our study provides preliminary evidence that users can adopt mnemonic-based augmentation with limited impact on usability, and we discuss the security implications under a rate-limited online threat model.
File in questo prodotto:
Non ci sono file associati a questo prodotto.

I documenti in IRIS sono protetti da copyright e tutti i diritti sono riservati, salvo diversa indicazione.

Utilizza questo identificativo per citare o creare un link a questo documento: https://hdl.handle.net/11567/1314176
 Attenzione

Attenzione! I dati visualizzati non sono stati sottoposti a validazione da parte dell'ateneo

Citazioni
  • ???jsp.display-item.citation.pmc??? 1
  • Scopus ND
  • ???jsp.display-item.citation.isi??? 0
social impact