Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Analysis of password creation behavior using leaked credentials
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
Jönköping University, School of Engineering, JTH, Department of Computer Science and Informatics.
2025 (English)Independent thesis Advanced level (degree of Master (One Year)), 10 credits / 15 HE creditsStudent thesis
Abstract [en]

In today’s rapidly evolving cyberspace, passwords remain the most commonly used form of authentication. Despitethe growing adoption of Multi-factor Authentication (MFA), they continue to play a vital role. Understanding howpasswords are created and the factors that influence their creation are crucial for improving password policies anduser training. This study analyzes a large-scale dataset of breached credentials to explore patterns in passwordcreation, focusing on cultural, linguistic and institutional factors. Specifically, the following research questionsare addressed: (1) What password patterns are found in public data breaches across different countries? (2) Howdo cultural factors influence password selection regarding estimated password strength and length? (3) Howdo linguistic factors influence password selection and security practices? and (4) Do affiliations to the securityapparatus, like police, military or intelligence services, lead to stronger password practices?To answer these questions, a subset of 380 million credentials from the Compilation of Many Breaches (COMB)dataset was imported into a database. Password strength scores were assessed using the zxcvbn algorithm, withlanguage-specific dictionaries incorporated to evaluate linguistic effects. The analysis reveals that while passwordcreation behavior differs across domains and regions, globally recurring patterns remain dominant. The averagelength of password varies between 9.26 and 8.24, with users of .de exhibiting the longest passwords on average.Although users affiliated with the security apparatus employed more unique passwords, their average strengthscores were only marginally different from the general dataset. These findings underscore subtle cultural andlinguistic influences on password creation behavior and support the need for tailored password policies and usertraining.

Place, publisher, year, edition, pages
2025. , p. 32
National Category
Security, Privacy and Cryptography
Identifiers
URN: urn:nbn:se:hj:diva-69317OAI: oai:DiVA.org:hj-69317DiVA, id: diva2:1983747
Supervisors
Examiners
Available from: 2025-08-05 Created: 2025-07-12 Last updated: 2025-10-13Bibliographically approved

Open Access in DiVA

fulltext(603 kB)366 downloads
File information
File name FULLTEXT01.pdfFile size 603 kBChecksum SHA-512
c34a4ec6412f16cd6b39eb9eba8550a18e1b4e668a031378b175634e0679e39ef7af32f43a5e2ee9ed0c66d589afbf083c3ddd3fbd579044f6aa20c30869ec80
Type fulltextMimetype application/pdf

By organisation
JTH, Department of Computer Science and Informatics
Security, Privacy and Cryptography

Search outside of DiVA

GoogleGoogle Scholar
Total: 371 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

urn-nbn

Altmetric score

urn-nbn
Total: 907 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • modern-language-association-8th-edition
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf