{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,8,23]],"date-time":"2025-08-23T00:05:36Z","timestamp":1755907536285,"version":"3.44.0"},"publisher-location":"New York, NY, USA","reference-count":33,"publisher":"ACM","license":[{"start":{"date-parts":[[2024,12,2]],"date-time":"2024-12-02T00:00:00Z","timestamp":1733097600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/creativecommons.org\/licenses\/by\/4.0\/"}],"funder":[{"DOI":"10.13039\/501100006374","name":"Kuwait University","doi-asserted-by":"publisher","id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]},{"DOI":"10.13039\/501100006374","name":"National Science Foundation","doi-asserted-by":"publisher","award":["2055549"],"award-info":[{"award-number":["2055549"]}],"id":[{"id":"10.13039\/501100006374","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":[],"published-print":{"date-parts":[[2024,12,2]]},"DOI":"10.1145\/3658644.3690333","type":"proceedings-article","created":{"date-parts":[[2024,12,9]],"date-time":"2024-12-09T12:19:20Z","timestamp":1733746760000},"page":"4241-4255","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":1,"title":["Unmasking the Security and Usability of Password Masking"],"prefix":"10.1145","author":[{"ORCID":"https:\/\/orcid.org\/0009-0008-0468-9454","authenticated-orcid":false,"given":"Yuqi","family":"Hu","sequence":"first","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, Georgia, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-0454-3742","authenticated-orcid":false,"given":"Suood","family":"Alroomi","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology &amp; Kuwait University, Atlanta, Georgia, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0009-0009-1090-2044","authenticated-orcid":false,"given":"Sena","family":"Sahin","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, Georgia, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/orcid.org\/0000-0003-2242-048X","authenticated-orcid":false,"given":"Frank","family":"Li","sequence":"additional","affiliation":[{"name":"Georgia Institute of Technology, Atlanta, Georgia, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2024,12,9]]},"reference":[{"key":"e_1_3_2_1_1_1","unstructured":"2024. Bruce Schneier. https:\/\/en.wikipedia.org\/wiki\/Bruce_Schneier."},{"key":"e_1_3_2_1_2_1","unstructured":"2024. Jakob Nielsen. https:\/\/en.wikipedia.org\/wiki\/Jakob_Nielsen_(usability_consultant)."},{"key":"e_1_3_2_1_3_1","doi-asserted-by":"publisher","DOI":"10.1145\/3012709.3012730"},{"key":"e_1_3_2_1_4_1","volume-title":"Nabbus","author":"Burr William E.","year":"2011","unstructured":"William E. Burr, Donna F. Dodson, Elaine M. Newton, Ray A. Perlner, W. Timothy Polk, Sarbari Gupta, and Emad A. Nabbus. 2011. Electronic Authentication Guideline. NIST Special Publication 800--63--1 (2011)."},{"key":"e_1_3_2_1_5_1","volume-title":"Nabbus","author":"Burr William E.","year":"2013","unstructured":"William E. Burr, Donna F. Dodson, Elaine M. Newton, Ray A. Perlner, W. Timothy Polk, Sarbari Gupta, and Emad A. Nabbus. 2013. Electronic Authentication Guideline. NIST Special Publication 800--63--2 (2013)."},{"key":"e_1_3_2_1_6_1","unstructured":"Tony Caccavo. 2022. 'Masked?\" Passwords Don't Work the Way You Think. https:\/\/teampassword.com\/blog\/masked-passwords-dont-work."},{"key":"e_1_3_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.53"},{"volume-title":"Basics of Qualitative Research: Grounded Theory Procedures and Techniques","author":"Corbin Juliet","key":"e_1_3_2_1_8_1","unstructured":"Juliet Corbin and Anselm Strauss. 2014. Basics of Qualitative Research: Grounded Theory Procedures and Techniques. Sage Publications."},{"key":"e_1_3_2_1_9_1","unstructured":"MDN Web Docs. 2024. input type=\"password\" https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/HTML\/Element\/input\/password."},{"key":"e_1_3_2_1_10_1","volume-title":"CHI Conference on Human Factors in Computing Systems.","author":"Eiband Malin","year":"2017","unstructured":"Malin Eiband, Mohamed Khamis, Emanuel von Zezschwitz, Heinrich Hussmann, and Florian Alt. 2017. Understanding Shoulder Surfing in the Wild: Stories from Users and Observers. In CHI Conference on Human Factors in Computing Systems."},{"key":"e_1_3_2_1_11_1","volume-title":"Masking Passwords: Help or Hindrance? https:\/\/www.sitepoint.com\/masking-passwords-help-or-hindrance\/.","author":"Enders Jessica","year":"2015","unstructured":"Jessica Enders. 2015. Masking Passwords: Help or Hindrance? https:\/\/www.sitepoint.com\/masking-passwords-help-or-hindrance\/."},{"key":"e_1_3_2_1_12_1","volume-title":"Measuring HTTPS Adoption on the Web. In USENIX Security Symposium.","author":"Felt Adrienne Porter","year":"2017","unstructured":"Adrienne Porter Felt, Richard Barnes, April King, Chris Palmer, Chris Bentzel, and Parisa Tabriz. 2017. Measuring HTTPS Adoption on the Web. In USENIX Security Symposium."},{"key":"e_1_3_2_1_13_1","unstructured":"Google. 2024. Overview of CrUX. https:\/\/developer.chrome.com\/docs\/crux\/."},{"key":"e_1_3_2_1_14_1","volume-title":"Digital Identity Guidelines. NIST Special Publication 800--63C","author":"Grassi P","year":"2017","unstructured":"P Grassi, Michael E Garcia, and James L Fenton. 2017. Digital Identity Guidelines. NIST Special Publication 800--63C (2017)."},{"key":"e_1_3_2_1_15_1","volume-title":"CHI Conference on Human Factors in Computing Systems.","author":"Khamis Mohamed","year":"2019","unstructured":"Mohamed Khamis, Tobias Seitz, Leonhard Mertl, Alice Nguyen, Mario Schneller, and Zhe Li. 2019. Passquerade: Improving Error Correction of Text Passwords on Mobile Devices by using Graphic Filters for Password Masking. In CHI Conference on Human Factors in Computing Systems."},{"key":"e_1_3_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.2307\/2531695"},{"key":"e_1_3_2_1_17_1","unstructured":"Daniel Miessler. 2020. SecLists\/Passwords\/Common-Credentials. https:\/\/github.com\/danielmiessler\/SecLists\/tree\/master\/Passwords\/Common-Credentials"},{"volume-title":"USENIX Security Symposium.","author":"Munyendo Collins W.","key":"e_1_3_2_1_18_1","unstructured":"Collins W. Munyendo, Philipp Markert, Alexandra Nisenoff, Miles Grant, Elena Korkes, Blase Ur, and Adam J. Aviv. 2022. \"The Same PIN, Just Longer\": On the (In)Security of Upgrading PINs from 4 to 6 Digits. In USENIX Security Symposium."},{"key":"e_1_3_2_1_19_1","unstructured":"National Cyber Security Centre (NCSC). 2018. Password administration for system owners. https:\/\/www.ncsc.gov.uk\/collection\/passwords."},{"key":"e_1_3_2_1_20_1","unstructured":"Jakob Nielsen. 2009. Stop Password Masking. https:\/\/www.nngroup.com\/articles\/stop-password-masking\/."},{"key":"e_1_3_2_1_21_1","volume-title":"BREAKING: Password Entry Is Fine. In HCI for Cybersecurity, Privacy and Trust. 67--80.","author":"Pidel Catlin","year":"2019","unstructured":"Catlin Pidel and Stephan Neuhaus. 2019. BREAKING: Password Entry Is Fine. In HCI for Cybersecurity, Privacy and Trust. 67--80."},{"key":"e_1_3_2_1_22_1","unstructured":"The Open Web Application Security Project. 2024. Authentication Cheat Sheet. https:\/\/cheatsheetseries.owasp.org\/cheatsheets\/Authentication_Cheat_Sheet.html."},{"key":"e_1_3_2_1_23_1","unstructured":"Prolific. 2024. Prolific | Quickly find research participants you can trust. https:\/\/www.prolific.com\/."},{"volume-title":"Qualtrics XM: The Leading Experience Management Software. https:\/\/www.qualtrics.com\/.","year":"2024","key":"e_1_3_2_1_24_1","unstructured":"Qualtrics. 2024. Qualtrics XM: The Leading Experience Management Software. https:\/\/www.qualtrics.com\/."},{"key":"e_1_3_2_1_25_1","volume-title":"USENIX Security Symposium.","author":"Roomi Suood Al","year":"2023","unstructured":"Suood Al Roomi and Frank Li. 2023. A Large-Scale Measurement of Website Login Policies. In USENIX Security Symposium."},{"key":"e_1_3_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/3447526.3472058"},{"key":"e_1_3_2_1_27_1","unstructured":"Bruce Schneier. 2009. The Problem with Password Masking. https:\/\/www.schneier.com\/blog\/archives\/2009\/06\/the_problem_wit_2.html."},{"key":"e_1_3_2_1_28_1","unstructured":"Statcounter. 2024. Desktop Browser Market Share Worldwide. https:\/\/gs.statcounter.com\/browser-market-share\/desktop\/worldwide."},{"key":"e_1_3_2_1_29_1","unstructured":"Statcounter. 2024. Mobile Browser Market Share Worldwide. https:\/\/gs.statcounter.com\/browser-market-share\/mobile\/worldwide."},{"key":"e_1_3_2_1_30_1","doi-asserted-by":"publisher","DOI":"10.1145\/3372297.3417882"},{"key":"e_1_3_2_1_31_1","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978363"},{"key":"e_1_3_2_1_32_1","volume-title":"USENIX Security Symposium.","author":"Wheeler Daniel Lowe","year":"2016","unstructured":"Daniel Lowe Wheeler. 2016. zxcvbn: Low-Budget Password Strength Estimation. In USENIX Security Symposium."},{"volume-title":"ACM Conference on Computer and Communications Security (CCS).","author":"Zhang Yinqian","key":"e_1_3_2_1_33_1","unstructured":"Yinqian Zhang, Fabian Monrose, and Michael K. Reiter. 2010. The security of modern password expiration: an algorithmic framework and empirical analysis. In ACM Conference on Computer and Communications Security (CCS)."}],"event":{"name":"CCS '24: ACM SIGSAC Conference on Computer and Communications Security","sponsor":["SIGSAC ACM Special Interest Group on Security, Audit, and Control"],"location":"Salt Lake City UT USA","acronym":"CCS '24"},"container-title":["Proceedings of the 2024 on ACM SIGSAC Conference on Computer and Communications Security"],"original-title":[],"link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690333","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3658644.3690333","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,8,22]],"date-time":"2025-08-22T06:12:22Z","timestamp":1755843142000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3658644.3690333"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2024,12,2]]},"references-count":33,"alternative-id":["10.1145\/3658644.3690333","10.1145\/3658644"],"URL":"https:\/\/doi.org\/10.1145\/3658644.3690333","relation":{},"subject":[],"published":{"date-parts":[[2024,12,2]]},"assertion":[{"value":"2024-12-09","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}