2017/06/06 by Chun Wang, Wang, Chun, Steve T. K. Jan +5
Computer Science · Engineering · Social Sciences · #Advanced Malware Detection Techniques #Business #Computer science #Computer security #Cryptography and Security (cs.CR) #Demographics #Engineering #FOS: Computer and information sciences #Internet privacy #One-time password #Password #Password policy #Password strength #Privacy, Security, and Data Protection #Reuse #Service (business) #User Authentication and Security Systems #cs.CR
paper · pdf · doi:10.48550/arxiv.1706.01939
openalex publication_date 2017/06/06 · arxiv created 2017/06/08 · arxiv updated 2017/06/09 · openalex created_date 2025/10/10 · openalex updated_date 2026/07/28
Leaked passwords from data breaches can pose a serious threat to users if the password is reused elsewhere. With more online services getting breached today, there is still a lack of large-scale quantitative understanding of the risks of password reuse across services. In this paper, we analyze a large collection of 28.8 million users and their 61.5 million passwords across 107 services. We find that 38% of the users have reused exactly the same password across different sites, while 20% have modified an existing password to create new ones. In addition, we find that the password modification patterns are highly consistent across different user demographics, indicating a high predictability. To quantify the risk, we build a new training-based guessing algorithm, and show that more than 16 million password pairs can be cracked within just 10 attempts (30% of the modified passwords and all the reused passwords).