{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,21]],"date-time":"2026-07-21T04:55:33Z","timestamp":1784609733505,"version":"3.55.0"},"reference-count":85,"publisher":"Association for Computing Machinery (ACM)","issue":"8","license":[{"start":{"date-parts":[[2022,12,28]],"date-time":"2022-12-28T00:00:00Z","timestamp":1672185600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/501100001809","name":"National Science Foundation of China","doi-asserted-by":"crossref","award":["U1713212, 61572330, 61836005, 61702341, 61972263"],"award-info":[{"award-number":["U1713212, 61572330, 61836005, 61702341, 61972263"]}],"id":[{"id":"10.13039\/501100001809","id-type":"DOI","asserted-by":"crossref"}]},{"DOI":"10.13039\/501100003453","name":"Natural Science Foundation of Guangdong Province","doi-asserted-by":"crossref","award":["2019A1515011608"],"award-info":[{"award-number":["2019A1515011608"]}],"id":[{"id":"10.13039\/501100003453","id-type":"DOI","asserted-by":"crossref"}]},{"name":"Stable Support Plan for Higher Education Institutions in Shenzhen","award":["20200810113310001"],"award-info":[{"award-number":["20200810113310001"]}]},{"name":"Technology Planning Project of Shenzhen City","award":["JCYJ20170302143118519, GGFW2018021118145859, JSGG20180507182904693"],"award-info":[{"award-number":["JCYJ20170302143118519, GGFW2018021118145859, JSGG20180507182904693"]}]},{"name":"Guangdong Pearl River Talent Recruitment Program","award":["2019ZT08X603"],"award-info":[{"award-number":["2019ZT08X603"]}]},{"name":"Guangdong Pearl River Talent Plan","award":["2019JC01X235"],"award-info":[{"award-number":["2019JC01X235"]}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2023,8,31]]},"abstract":"<jats:p>Honeyword (or decoy password) based authentication, first introduced by Juels and Rivest in 2013, has emerged as a security mechanism that can provide security against server-side threats on the password-files. From the theoretical perspective, this security mechanism reduces attackers\u2019 efficiency to a great extent as it detects the threat on a password-file so that the system administrator can be notified almost immediately as an attacker tries to take advantage of the compromised file. This paper aims to present a comprehensive survey of the relevant research and technological developments in honeyword-based authentication techniques. We cover twenty-three techniques related to honeyword, reported under different research articles since 2013. This survey paper helps the readers to (i) understand how honeyword based security mechanism works in practice, (ii) get a comparative view on the existing honeyword based techniques, and (iii) identify the existing gaps that have yet to be filled and the emergent research opportunities.<\/jats:p>","DOI":"10.1145\/3552431","type":"journal-article","created":{"date-parts":[[2022,8,3]],"date-time":"2022-08-03T11:32:49Z","timestamp":1659526369000},"page":"1-37","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":9,"title":["Honeyword-based Authentication Techniques for Protecting Passwords: A Survey"],"prefix":"10.1145","volume":"55","author":[{"ORCID":"https:\/\/orcid.org\/0000-0002-3825-8838","authenticated-orcid":false,"given":"Nilesh","family":"Chakraborty","sequence":"first","affiliation":[{"name":"College of Computer Science and Software Engineering, Shenzhen University, Nanshan, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2208-962X","authenticated-orcid":false,"given":"Jianqiang","family":"Li","sequence":"additional","affiliation":[{"name":"College of Computer Science and Software Engineering, Shenzhen University, Nanshan, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-3529-2640","authenticated-orcid":false,"given":"Victor C. M.","family":"Leung","sequence":"additional","affiliation":[{"name":"College of Computer Science and Software Engineering, Shenzhen University, Nanshan, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-5489-5917","authenticated-orcid":false,"given":"Samrat","family":"Mondal","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Indian Institute of Technology Patna, Dist. Bhita, Patna, India"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-2766-3096","authenticated-orcid":false,"given":"Yi","family":"Pan","sequence":"additional","affiliation":[{"name":"Department of Computer Science, Georgia State University, Georgia, Atlanta, USA"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0293-0781","authenticated-orcid":false,"given":"Chengwen","family":"Luo","sequence":"additional","affiliation":[{"name":"College of Computer Science and Software Engineering, Shenzhen University, Nanshan, Shenzhen, Guangdong, China"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-6605-180X","authenticated-orcid":false,"given":"Mithun","family":"Mukherjee","sequence":"additional","affiliation":[{"name":"School of Artificial Intelligence, Nanjing University of Information Science and Technology, Nanjing, China"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2022,12,28]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Oleg Afonin. 2016. Building a Distributed Network in the Cloud: Using Amazon EC2 to Break Passwords. https:\/\/blog.elcomsoft.com\/2016\/07\/building-a-distributed-network-in-the-cloud-using-amazon-ec2-to-break-passwords. (2016). Last Accessed: 2022-03-18."},{"key":"e_1_3_2_3_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2018.2824323"},{"key":"e_1_3_2_4_2","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818015"},{"key":"e_1_3_2_5_2","doi-asserted-by":"publisher","DOI":"10.1145\/2818000.2818014"},{"key":"e_1_3_2_6_2","unstructured":"Lorenzo Franceschi Bicchierai. 2016. Hacker Tries To Sell 427 Million Stolen MySpace Passwords For $2 800. https:\/\/www.vice.com\/en_us\/article\/pgkk8v\/427-million-myspace-passwords-emails-data-breach. (2016). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_7_2","doi-asserted-by":"publisher","DOI":"10.1109\/EuroSP.2016.31"},{"key":"e_1_3_2_8_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00009"},{"key":"e_1_3_2_9_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15497-3_18"},{"key":"e_1_3_2_10_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.49"},{"key":"e_1_3_2_11_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_12_2","doi-asserted-by":"publisher","DOI":"10.1145\/2699390"},{"key":"e_1_3_2_13_2","unstructured":"Ron Bowes. 2015. Passwords: SkullSecurity. https:\/\/wiki.skullsecurity.org\/index.php?title=Passwords. (2015). Last Accessed: 2021-April-10."},{"key":"e_1_3_2_14_2","doi-asserted-by":"publisher","DOI":"10.1145\/1180405.1180427"},{"key":"e_1_3_2_15_2","unstructured":"M. Burnett. 2013. The Pathetic Reality of Adobe Password Hints. https:\/\/xato.net\/windows-security\/adobe-password-hints. (2013). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_16_2","unstructured":"Mark Burnett. 2016. Is there Life After Passwords?https:\/\/medium.com\/@m8urnett\/is-there-life-after-passwords-290d50fc6f7d. (2016). Last Accessed: 2022-03-15."},{"key":"e_1_3_2_17_2","unstructured":"Mark Burnett. 2017. Passwords are Not Lame and they\u2019re Not Dead. https:\/\/www.toolbox.com\/tech\/it-strategy\/blogs\/passwords-are-not-lame-and-theyre-not-dead-heres-why-072417. (2017). Last Accessed: 2022-03-15."},{"key":"e_1_3_2_18_2","doi-asserted-by":"publisher","DOI":"10.1145\/2810103.2813722"},{"key":"e_1_3_2_19_2","doi-asserted-by":"publisher","DOI":"10.1109\/HPCSim.2015.7237039"},{"key":"e_1_3_2_20_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-44966-0_10"},{"key":"e_1_3_2_21_2","doi-asserted-by":"publisher","DOI":"10.1145\/2799979.2799992"},{"key":"e_1_3_2_22_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.procs.2016.07.298"},{"key":"e_1_3_2_23_2","doi-asserted-by":"publisher","DOI":"10.1016\/j.cose.2017.01.011"},{"key":"e_1_3_2_24_2","doi-asserted-by":"publisher","DOI":"10.1049\/iet-ifs.2017.0538"},{"key":"e_1_3_2_25_2","doi-asserted-by":"publisher","DOI":"10.1109\/JIOT.2021.3080676"},{"key":"e_1_3_2_26_2","doi-asserted-by":"publisher","DOI":"10.1109\/TrustCom\/BigDataSE.2018.00071"},{"key":"e_1_3_2_27_2","unstructured":"Eric Chase. 2016. The Password is Dead; Long Live the Password. https:\/\/sbscyber.com\/resources\/the-password-is-dead-long-live-the-password. (2016). Last Accessed: 2022-03-15."},{"key":"e_1_3_2_28_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.53"},{"key":"e_1_3_2_29_2","unstructured":"Catalin Cimpanu. 2020. 26 million LiveJournal Credentials Leaked Online Sold on the Dark Web. https:\/\/www.zdnet.com\/article\/26-million-livejournal-credentials-leaked-online-sold-on-the-dark-web. (2020). Last Accessed: 2022-03-18."},{"key":"e_1_3_2_30_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23357"},{"key":"e_1_3_2_31_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2011.44"},{"key":"e_1_3_2_32_2","first-page":"19","volume-title":"Proceedings of the 7th International Conference on Technology and Practice of Passwords","author":"D\u00fcrmuth Markus","year":"2014","unstructured":"Markus D\u00fcrmuth and Thorsten Kranz. 2014. On password guessing with GPUs and FPGAs. In Proceedings of the 7th International Conference on Technology and Practice of Passwords, Trondheim, Norway, December 8\u201310, 2014. 19\u201338."},{"issue":"5","key":"e_1_3_2_33_2","first-page":"1","article-title":"A Survey of Internet of Things (IoT) authentication schemes","volume":"19","author":"El-hajj Mohammed","year":"2019","unstructured":"Mohammed El-hajj, Ahmad Fadlallah, Maroun Chamoun, and Ahmed Serhrouchni. 2019. A Survey of Internet of Things (IoT) authentication schemes. Sensors, MPDI 19, 5 (2019), 1\u201343.","journal-title":"Sensors, MPDI"},{"key":"e_1_3_2_34_2","doi-asserted-by":"publisher","DOI":"10.1109\/TDSC.2015.2406707"},{"key":"e_1_3_2_35_2","doi-asserted-by":"publisher","DOI":"10.1109\/COMPSAC48688.2020.00-25"},{"key":"e_1_3_2_36_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2016.23240"},{"key":"e_1_3_2_37_2","first-page":"221","volume-title":"Proceedings of the 27th USENIX Security Symposium","author":"Gao Xianyi","year":"2018","unstructured":"Xianyi Gao, Yulong Yang, Can Liu, Christos Mitropoulos, Janne Lindqvist, and Antti Oulasvirta. 2018. Forgetting of passwords: Ecological theory and data. In Proceedings of the 27th USENIX Security Symposium, Baltimore, MD, USA, August 15\u201317, 2018. 221\u2013238."},{"key":"e_1_3_2_38_2","first-page":"25","volume-title":"Proceedings of the 1st International Conference on Advanced Computer Science Applications and Technologies","author":"Gauravaram Praveen","year":"2012","unstructured":"Praveen Gauravaram. 2012. Security analysis of salt \\(||\\) password hashes. In Proceedings of the 1st International Conference on Advanced Computer Science Applications and Technologies, Kuala Lumpur, November 26\u201328, 2012. 25\u201330."},{"key":"e_1_3_2_39_2","doi-asserted-by":"publisher","DOI":"10.1145\/3243734.3243769"},{"key":"e_1_3_2_40_2","first-page":"2672","volume-title":"Proceedings of 28th Conference on Neural Information Processing Systems","author":"Goodfellow Ian","year":"2014","unstructured":"Ian Goodfellow, Jean Pouget-Abadie, Mehdi Mirza, Bing Xu, David Warde-Farley, Sherjil Ozair, Aaron Courville, and Yoshua Bengio. 2014. Generative adversarial nets. In Proceedings of 28th Conference on Neural Information Processing Systems, Montr\u00e9al Canada, December 8\u201313, 2014. 2672\u20132680."},{"key":"e_1_3_2_41_2","unstructured":"Dan Goodin. October 2012. 25-GPU Cluster Cracks Every Standard Windows Password in  \\(\\lt\\) 6 Hours. https:\/\/arstechnica.com\/security\/2012\/12\/25-gpu-cluster-cracks-every-standard-windows-password-in-6-hours\/. (October 2012). Last Accessed: 2021-08-12."},{"key":"e_1_3_2_42_2","first-page":"19","volume-title":"Proceedings of the 5th International Conference on PASSWORDS","author":"Gosney Jeremi","year":"2012","unstructured":"Jeremi Gosney. 2012. On password guessing with GPUs and FPGAs. In Proceedings of the 5th International Conference on PASSWORDS, Oslo, Norway, December 3\u20135, 2012. 19\u201338."},{"issue":"4","key":"e_1_3_2_43_2","article-title":"Superword: A honeyword system for achieving higher security goals","volume":"103","author":"Guo Yimin","year":"2021","unstructured":"Yimin Guo, Zhenfeng Zhang, and Yajun Guo. 2021. Superword: A honeyword system for achieving higher security goals. Computers & Security, Elsevier 103, 4 (2021).","journal-title":"Computers & Security, Elsevier"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.14722\/usec.2017.23043"},{"key":"e_1_3_2_45_2","unstructured":"Robert Hackett. 2016. LinkedIn Lost 167 Million Account Credentials in Data Breach. https:\/\/fortune.com\/2016\/05\/18\/linkedin-data-breach-email-password\/. (2016). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_46_2","unstructured":"Robert Hackett. 2017. Yahoo Raises Breach Estimate to Full 3 Billion Accounts By Far Biggest Known. https:\/\/fortune.com\/2017\/10\/03\/yahoo-breach-mail\/. (2017). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_47_2","first-page":"1","volume-title":"Proceedings of the IEEE International Symposium on Secure Software Engineering","author":"Halfond William G.","year":"2006","unstructured":"William G. Halfond, Jeremy Viegas, Alessandro Orso, et\u00a0al. 2006. A classification of SQL-injection attacks and countermeasures. In Proceedings of the IEEE International Symposium on Secure Software Engineering, McLean, VA, USA, March 13\u201315, 2006. 1\u201311."},{"key":"e_1_3_2_48_2","unstructured":"Patrick Heim. 2016. Dropbox: Resetting Passwords to Keep Your Files Safe. https:\/\/www.databreaches.net\/dropbox-resetting-passwords-to-keep-your-files-safe\/. (2016). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.1016\/S0022-5371(71)80029-4"},{"key":"e_1_3_2_50_2","unstructured":"Scott Ikeda. 2019. The Latest Facebook Password Leak: Hundreds of Millions of User Passwords Exposed to Company Employees. https:\/\/www.cpomagazine.com\/data-protection\/the-latest-facebook-password-leak-hundreds-of-millions-of-user-passwords-exposed-to-company-employees\/. (2019). Last Accessed: 2019-09-04."},{"key":"e_1_3_2_51_2","unstructured":"John the Ripper. 2008. John the Ripper Password Cracker [Online Document][cited 2008 Oct. 07] Available HTTP. http:\/\/www.openwall.com. (2008). Last Accessed: 2021-09-04."},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516671"},{"key":"e_1_3_2_53_2","first-page":"483","volume-title":"Proceedings of the 24th USENIX Security Symposium","author":"Karapanos Nikolaos","year":"2015","unstructured":"Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, and Srdjan Capkun. 2015. Sound-proof: Usable two-factor authentication based on ambient sound. In Proceedings of the 24th USENIX Security Symposium, Washington, D.C., USA, August 12\u201314, 2015. 483\u2013498."},{"key":"e_1_3_2_54_2","first-page":"757","volume-title":"Proceedings of the 25th USENIX Security Symposium","author":"Kharaz Amin","year":"2016","unstructured":"Amin Kharaz, Sajjad Arshad, Collin Mulliner, William Robertson, and Engin Kirda. 2016. UNVEIL: A large-scale, automated approach to detecting ransomware. In Proceedings of the 25th USENIX Security Symposium, Austin, TX, USA, August 10\u201312, 2016. 757\u2013772."},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.18653\/v1\/P19-1228"},{"key":"e_1_3_2_56_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516746"},{"key":"e_1_3_2_57_2","doi-asserted-by":"publisher","DOI":"10.1145\/3178876.3186101"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.5555\/3277203.3277309"},{"key":"e_1_3_2_59_2","unstructured":"David Lukic. 2021. How Under Armour\u2019s App MyFitnessPal Got Hacked. https:\/\/www.idstrong.com\/sentinel\/myfitnesspal-data-breach. (2021). Last Accessed: 2022-03-18."},{"key":"e_1_3_2_60_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2014.50"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516726"},{"key":"e_1_3_2_62_2","first-page":"175","volume-title":"Proceedings of the 26th USENIX Security Symposium","author":"Melicher William","year":"2017","unstructured":"William Melicher, Blase Ur, Saranga Komanduri, Lujo Bauer, Nicolas Christin, and Lorrie Faith Cranor. 2017. Fast, lean, and accurate: Modeling password guessability using neural networks. In Proceedings of the 26th USENIX Security Symposium, Santa Clara, CA, USA, July 12\u201314, 2017. 175\u2013191."},{"key":"e_1_3_2_63_2","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3134082"},{"key":"e_1_3_2_64_2","doi-asserted-by":"publisher","DOI":"10.1145\/1102120.1102168"},{"key":"e_1_3_2_65_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23303"},{"key":"e_1_3_2_66_2","unstructured":"Brid-Aine Parnell. 2012. LinkedIn Admits Site Hack Adds Pinch of Salt to Passwords. https:\/\/www.theregister.com\/2012\/06\/07\/linkedin_admits_data_breach\/. (2012). Last Accessed: 2022-03-18."},{"key":"e_1_3_2_67_2","first-page":"81","volume-title":"Proceedings of the 7th FREENIX Track: 1999 USENIX Annual Technical Conference, June 6-11, 1999, Monterey, California, USA","author":"Provos Niels","year":"1999","unstructured":"Niels Provos and David Mazi\u00e8res. 1999. A future-adaptable password scheme. In Proceedings of the 7th FREENIX Track: 1999 USENIX Annual Technical Conference, June 6-11, 1999, Monterey, California, USA. 81\u201391."},{"key":"e_1_3_2_68_2","unstructured":"Steve Rangan. 2016. Weebly Data Breach Affects 43 Million Customers. https:\/\/www.csoonline.com\/article\/3133031\/weebly-data-breach-affects-43-million-customers.html. (2016). Last Accessed: 2019-09-05."},{"key":"e_1_3_2_69_2","first-page":"1","volume-title":"Proceedings of the 5th USENIX Conference on Hot Topics in Security","author":"Schechter Stuart","year":"2010","unstructured":"Stuart Schechter, Cormac Herley, and Michael Mitzenmacher. 2010. Popularity is everything: A new approach to protecting passwords from statistical-guessing attacks. In Proceedings of the 5th USENIX Conference on Hot Topics in Security, Washington, DC, USA, August 11\u201313, 2010. 1\u20138."},{"key":"e_1_3_2_70_2","first-page":"1983","volume-title":"Proceedings of the 27th International Conference on Human Factors in Computing Systems","author":"Schechter Stuart E.","year":"2009","unstructured":"Stuart E. Schechter, Serge Egelman, and Robert W. Reeder. 2009. It\u2019s not what you know, but who you know. In Proceedings of the 27th International Conference on Human Factors in Computing Systems, Boston, MA, USA, April 4\u20139, 2009. 1983\u20131992."},{"key":"e_1_3_2_71_2","unstructured":"Robert Tait. 2016. Personal Details of 50 Million Turkish Citizens Leaked Online Hackers Claim. https:\/\/www.telegraph.co.uk\/news\/2016\/04\/04\/personal-details-of-50-million-turkish-citizens-leaked-online-ha\/. (2016). Last Accessed: 2020-08-12."},{"key":"e_1_3_2_72_2","unstructured":"Defense Information Systems Agency (DISA) for the Department of Defense (DoD). 2011. Application Security and Development: Security Technical Implementation Guide (STIG) Version 3. (October2011)."},{"key":"e_1_3_2_73_2","unstructured":"Dan U. 2019. How Password Deny Lists can Help Your Users to Make Sensible Password Choices.https:\/\/www.ncsc.gov.uk\/blog-post\/passwords-passwords-everywhere. (2019). Accessed: 2022-April-10."},{"key":"e_1_3_2_74_2","volume-title":"Supporting Password-Security Decisions with Data","author":"Ur Blase","year":"2016","unstructured":"Blase Ur. 2016. Supporting Password-Security Decisions with Data. Ph.D. Dissertation. Forbes Ave, Pittsburgh, PA 15213, United States."},{"key":"e_1_3_2_75_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00003"},{"key":"e_1_3_2_76_2","doi-asserted-by":"publisher","DOI":"10.1109\/MSP.2018.1870866"},{"key":"e_1_3_2_77_2","doi-asserted-by":"publisher","DOI":"10.1109\/tifs.2017.2721359"},{"key":"e_1_3_2_78_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2018.23142"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/DSN.2016.60"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978339"},{"key":"e_1_3_2_81_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP46214.2022.9833598"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2019.23360"},{"key":"e_1_3_2_83_2","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866327"},{"key":"e_1_3_2_84_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2009.8"},{"key":"e_1_3_2_85_2","first-page":"157","volume-title":"Proceedings of the 25th USENIX Security Symposium","author":"Wheeler Daniel Lowe","year":"2016","unstructured":"Daniel Lowe Wheeler. 2016. zxcvbn: Low-budget password strength estimation. In Proceedings of the 25th USENIX Security Symposium, Austin, TX, USA, August 10\u201312, 2016. 157\u2013173."},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/CSMA.2015.12"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3552431","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3552431","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,17]],"date-time":"2025-06-17T16:47:41Z","timestamp":1750178861000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3552431"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2022,12,28]]},"references-count":85,"journal-issue":{"issue":"8","published-print":{"date-parts":[[2023,8,31]]}},"alternative-id":["10.1145\/3552431"],"URL":"https:\/\/doi.org\/10.1145\/3552431","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2022,12,28]]},"assertion":[{"value":"2020-12-03","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-07-18","order":1,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2022-12-28","order":2,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}