AI 中文总结
研究个人密码安全中用户行为与认知偏差,整合行为经济学见解,通过调查分析用户密码创建等情况,发现即时便利重于长期安全,识别相关心理偏差,为设计用户友好型认证策略提供实用见解。
AI 中文摘要
尽管人们对网络安全风险的意识不断提高,但用户仍继续采用不安全的密码做法,如重复使用密码、选择弱凭证以及忽视安全建议。本研究通过整合行为经济学的见解,特别是双曲线贴现、现状偏差和当前偏差,探讨影响密码决策的行为和认知因素。我们进行了一项调查,分析人们如何创建、存储和管理密码,考察安全习惯是否随着时间推移因意识提高而改善。我们的发现表明,即时便利性往往超过长期安全考虑,导致用户将可记性置于强度之上。此外,我们识别出导致安全拖延以及抵制采用更安全认证做法(如密码管理器和多因素认证)的关键心理偏差。该研究通过弥合安全意识与行动之间的差距,为以用户为中心的安全做出贡献,提供实用见解以设计符合现实世界决策倾向的用户友好型认证策略。
英文摘要
Despite increasing awareness of cybersecurity risks, users continue to engage in insecure password practices, such as reusing passwords, choosing weak credentials, and neglecting security recommendations. The study explores the behavioral and cognitive factors that influence password decision-making by integrating insights from behavioral economics, particularly hyperbolic discounting, status quo bias, and present bias. We conducted a survey to analyze how people create, store and manage their passwords, examining whether security habits have improved over time in response to greater awareness. Our findings reveal that immediate convenience often outweighs long-term security considerations, leading users to prioritize memorability over strength. Additionally, we identify key psychological biases that contribute to security procrastination and resistance to adopting more secure authentication practices, such as password managers and multi-factor authentication. The study contributes to human-centered security by bridging the gap between security awareness and action, offering practical insights to design user-friendly authentication policies that align with real-world decision-making tendencies.