Introduction to Password Management and User Study Ethics

0.0(0)
Studied by 0 people
call kaiCall Kai
Locked
learnLearn
examPractice Test
spaced repetitionSpaced Repetition
heart puzzleMatch
flashcardsFlashcards
GameKnowt Play
Card Sorting

1/17

flashcard set

Earn XP

Description and Tags

Flashcards covering the ethics of user study participation, the psychology of password management, and threat modeling concepts as discussed in the lecture.

Last updated 4:59 AM on 8/18/26
Name
Mastery
Learn
Test
Matching
Spaced
Call with Kai
Chat

No analytics yet

Send a link to your students to track their progress

18 Terms

1
New cards

Qualtrics

An online platform for delivering surveys and gathering consent forms used by researchers to manage participant data conveniently.

2
New cards

Consent form

A document that study participants must agree to, detailing their understanding of the study and permission for their data to be used.

3
New cards

Information sheet

A document provided to participants outlining everything they are signing up for and consenting to before beginning a study.

4
New cards

Password reuse

A practice where users use the same or similar passwords across multiple online accounts, creating a significant security risk if one account is compromised.

5
New cards

Password families

Groups of similar passwords used by a single user across different websites.

6
New cards

Likert scale

A rating scale used in questionnaires to measure participants' beliefs, attitudes, or justifications regarding their password habits.

7
New cards

Personal knowledge

Information such as a pet's name, birthday, or hometown that participants believe gives known attackers an advantage in guessing passwords.

8
New cards

Ability

In the context of threat modeling, a measure of who could access an account if motivation were excluded; 52%52\% of participants ranked someone they knew as most able.

9
New cards

Motivation

A measure of who would want to compromise an account; 62%62\% of participants selected either a competitor or a hacker as the most motivated.

10
New cards

Likelihood

The metric resulting from combining the ability and motivation of a potential attacker to compromise an account.

11
New cards

Automated attacks

Attacks involving tools that can rapidly test large lists of potential passwords, such as dates or common names, without needing personal knowledge of the user.

12
New cards

Strong site password

A proposed solution where a browser generates a unique password and helps the user learn it, such as by displaying it against a low-contrast background.

13
New cards

Social credit

The prestige or status associated with maintaining a high-level account on platforms like Wikipedia, which provides incentive for account protection.

14
New cards

Graphical passwords

An alternative authentication scheme that leverages the human brain's visual processing power to make credentials more memorable than text-based passwords.

15
New cards

Password entropy

A measure of how difficult a password is to crack through offline guessing; for example, doubling the length of a password can increase the crack time from 55 years to more than a lifetime.

16
New cards

Passkeys

A modern authentication solution that aims to eliminate the password memorability problem by using cryptographic keys stored on devices.

17
New cards

Browser cookies

Convenient files that bypass the need for re-entering passwords on one machine but do not help in recovery if the user moves to another device or clears them.

18
New cards

Memory aids

Tools or methods used to help remember passwords, though the study found they did not significantly improve management compared to the burden of remembering many unique credentials.