{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T12:51:20Z","timestamp":1783428680682,"version":"3.54.6"},"reference-count":42,"publisher":"Association for Computing Machinery (ACM)","issue":"7","license":[{"start":{"date-parts":[[2015,6,25]],"date-time":"2015-06-25T00:00:00Z","timestamp":1435190400000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Commun. ACM"],"published-print":{"date-parts":[[2015,6,25]]},"abstract":"<jats:p>Theory on passwords has lagged practice, where large providers use back-end smarts to survive with imperfect technology.<\/jats:p>","DOI":"10.1145\/2699390","type":"journal-article","created":{"date-parts":[[2015,6,25]],"date-time":"2015-06-25T14:36:19Z","timestamp":1435242979000},"page":"78-87","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":204,"title":["Passwords and the evolution of imperfect authentication"],"prefix":"10.1145","volume":"58","author":[{"given":"Joseph","family":"Bonneau","sequence":"first","affiliation":[{"name":"Stanford University, Stanford, CA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Cormac","family":"Herley","sequence":"additional","affiliation":[{"name":"Microsoft Research, Redmond, WA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Paul C.","family":"van Oorschot","sequence":"additional","affiliation":[{"name":"Carleton University, Ottawa, Ontario, Canada"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"given":"Frank","family":"Stajano","sequence":"additional","affiliation":[{"name":"University of Cambridge, Cambridge, U.K."}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2015,6,25]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/322796.322806"},{"key":"e_1_2_1_2_1","first-page":"2","volume":"22","author":"Anderson R.","year":"2006","journal-title":"Computer Security Journal"},{"key":"e_1_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/1595676.1595684"},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/2333112.2333114"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.49"},{"key":"e_1_2_1_6_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_2_1_7_1","volume-title":"Proceedings of the Workshop on the Economics of Information Security","author":"Bonneau J.","year":"2010"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.SP.800-63-2"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2408776.2408790"},{"key":"e_1_2_1_10_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23357"},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.1145\/2207676.2208544"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/2470654.2481329"},{"key":"e_1_2_1_13_1","volume-title":"Proceedings of the 28th Large Installation System Administration Conference","author":"Flor\u00eancio D.","year":"2014"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242661"},{"key":"e_1_2_1_15_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837124"},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1314389.1314391"},{"key":"e_1_2_1_17_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2012.162"},{"key":"e_1_2_1_18_1","volume-title":"Feb.","author":"Hearn M.","year":"2013"},{"key":"e_1_2_1_19_1","doi-asserted-by":"publisher","DOI":"10.1145\/1719030.1719050"},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","DOI":"10.5555\/2360743.2360824"},{"key":"e_1_2_1_21_1","series-title":"Montreal, Canada, Aug. 11","volume-title":"Proceedings of the Fourth USENIX Workshop on Hot Topics in Security","author":"Jakobsson M.","year":"2009"},{"key":"e_1_2_1_22_1","doi-asserted-by":"publisher","DOI":"10.1145\/1572532.1572578"},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.38"},{"key":"e_1_2_1_24_1","volume-title":"Proceedings of the Second USENIX Security Workshop. USENIX Association","author":"Klein D.","year":"1990"},{"key":"e_1_2_1_25_1","doi-asserted-by":"publisher","DOI":"10.1109\/ISIT.1994.394764"},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/359168.359172"},{"key":"e_1_2_1_27_1","volume-title":"The Internet Engineering Task Force","author":"M'Raihi D.","year":"2011"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.1145\/1592451.1592455"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2013.43"},{"key":"e_1_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/1620693.1620708"},{"key":"e_1_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-540-45146-4_36"},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.5555\/647039.715748"},{"key":"e_1_2_1_33_1","volume-title":"Proceedings of the 21st USENIX Security Symposium","author":"Riva O.","year":"2012"},{"key":"e_1_2_1_34_1","volume-title":"Proceedings of the Fifth USENIX Workshop on Hot Topics in Security (Washington, D.C., Aug. 10)","author":"Schechter S.","year":"2010"},{"key":"e_1_2_1_35_1","volume-title":"Proceedings of the USENIX Security Workshop. USENIX Society","author":"Spafford E.","year":"1992"},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-25867-1_6"},{"key":"e_1_2_1_37_1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Ur B.","year":"2012"},{"key":"e_1_2_1_39_1","volume-title":"MD","author":"U.S. National Institute of Standards and Technology. Password Usage.","year":"1985"},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866327"},{"key":"e_1_2_1_41_1","first-page":"2","volume":"4","author":"Williamson G.D.","year":"2006","journal-title":"Journal of Economic Crime Management"},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2004.81"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866328"}],"container-title":["Communications of the ACM"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2699390","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/2699390","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,18]],"date-time":"2025-06-18T06:13:37Z","timestamp":1750227217000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/2699390"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2015,6,25]]},"references-count":42,"journal-issue":{"issue":"7","published-print":{"date-parts":[[2015,6,25]]}},"alternative-id":["10.1145\/2699390"],"URL":"https:\/\/doi.org\/10.1145\/2699390","relation":{},"ISSN":["0001-0782","1557-7317"],"issn-type":[{"value":"0001-0782","type":"print"},{"value":"1557-7317","type":"electronic"}],"subject":[],"published":{"date-parts":[[2015,6,25]]},"assertion":[{"value":"2015-06-25","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}