{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2026,7,7]],"date-time":"2026-07-07T11:50:46Z","timestamp":1783425046334,"version":"3.54.6"},"reference-count":99,"publisher":"Association for Computing Machinery (ACM)","issue":"5","license":[{"start":{"date-parts":[[2025,1,24]],"date-time":"2025-01-24T00:00:00Z","timestamp":1737676800000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["ACM Comput. Surv."],"published-print":{"date-parts":[[2025,5,31]]},"abstract":"<jats:p>Passwords remain the primary authentication method in online services, a domain increasingly crucial in our digital age. However, passwords suffer from several well-documented security and usability issues. Addressing these concerns, password managers and two-factor authentication (2FA) have emerged as key solutions. This article examines these methods with a focus on enhancing password security without compromising usability. We utilize an adapted Bonneau et\u00a0al. (IEEE S&amp;P 2012) framework tailored to the specific challenges of password managers and 2FA. This allows us to categorize and evaluate prominent solutions from both academic research and industry practice, with a focus on their security, privacy, and usability. A crucial aspect of our study involves evaluating the effectiveness of a combined PM+2FA system in balancing security and usability. This study not only examines current trends but also suggests potential areas for future research, offering valuable insights to both users and developers in the evolving landscape of digital security.<\/jats:p>","DOI":"10.1145\/3711117","type":"journal-article","created":{"date-parts":[[2025,1,6]],"date-time":"2025-01-06T11:29:56Z","timestamp":1736162996000},"page":"1-32","update-policy":"https:\/\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":12,"title":["An In-Depth Analysis of Password Managers and Two-Factor Authentication Tools"],"prefix":"10.1145","volume":"57","author":[{"ORCID":"https:\/\/orcid.org\/0000-0001-9398-3875","authenticated-orcid":false,"given":"Mohammed","family":"Jubur","sequence":"first","affiliation":[{"name":"Computer Science, Jazan University College of Engineering and Computer Science, Jazan, Saudi Arabia"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0002-7779-6399","authenticated-orcid":false,"given":"Prakash","family":"Shrestha","sequence":"additional","affiliation":[{"name":"Equifax Inc, Atlanta, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]},{"ORCID":"https:\/\/orcid.org\/0000-0001-6083-104X","authenticated-orcid":false,"given":"Nitesh","family":"Saxena","sequence":"additional","affiliation":[{"name":"Texas A&amp;M University College Station, College Station, United States"}],"role":[{"vocabulary":"crossref","role":"author"}]}],"member":"320","published-online":{"date-parts":[[2025,1,24]]},"reference":[{"key":"e_1_3_2_2_2","unstructured":"Infobip. 2020. What is Mobile Number Portability (MNP)? Retrieved from https:\/\/www.infobip.com\/glossary\/mobile-number-portability"},{"key":"e_1_3_2_3_2","unstructured":"Craig Timberg. 2013. NSA slide shows surveillance of undersea cables. Washington Post.Retrieved January 6 2025 from https:\/\/wapo.st\/2HFZBPQ"},{"key":"e_1_3_2_4_2","unstructured":"TechCrunch. 2013. SlickLogin Aims to Kill the Password by Singing a Silent Song to Your Smartphone. Retrieved January 6 2025 from https:\/\/tcrn.ch\/3fC4dos"},{"key":"e_1_3_2_5_2","unstructured":"Barton Gellman and Laura Poitras. 2013. U.S. British intelligence mining data from nine U.S. Internet companies in broad secret program. Washington Post. Retrieved January 6 2025 from https:\/\/wapo.st\/2KSDaqD"},{"key":"e_1_3_2_6_2","unstructured":"Samuel Gibbs. 2016. SS7 hack explained: what can you do about it? Retrieved from https:\/\/www.theguardian.com\/technology\/2016\/apr\/19\/ss7-hack-explained-mobile-phone-vulnerability-snooping-texts-calls"},{"key":"e_1_3_2_7_2","unstructured":"1Password. 2017. Information for Law Enforcement. Retrieved January 6 2025 from https:\/\/bit.ly\/2Fw2JNI"},{"key":"e_1_3_2_8_2","unstructured":"Cisco. 2017. Duo Security Two-Factor Authentication. Retrieved January 6 2025 from https:\/\/goo.gl\/e38UnB"},{"key":"e_1_3_2_9_2","unstructured":"Apple. 2017. Manage Passwords Using Keychains on Mac. Retrieved January 6 2025 from https:\/\/support.apple.com\/en-za\/guide\/mac-help\/mchlf375f392\/mac"},{"key":"e_1_3_2_10_2","unstructured":"Dashlane. 2017. The App That Makes the Internet Easier. Retrieved January 6 2025 from https:\/\/www.dashlane.com\/features"},{"key":"e_1_3_2_11_2","unstructured":"Broadnet. 2020. What is OTP SMS and How It Works. Retrieved January 10 2025 from https:\/\/www.broadnet.me\/what-is-otp-sms-and-how-it-works\/"},{"key":"e_1_3_2_12_2","article-title":"Authy | Two-Factor Authentication (2FA) App and Guides","author":"Twilio","year":"2018","unstructured":"Twilio. 2018. Authy | Two-Factor Authentication (2FA) App and Guides. Retrieved March 30, 2018 from https:\/\/www.authy.com\/","journal-title":"https:\/\/www.authy.com\/"},{"key":"e_1_3_2_13_2","unstructured":"Chris Hoffman. 2018. Criminals Can Steal Your Phone Number. Here\u2019s How to Stop Them. Retrieved January 10 2025 from https:\/\/www.howtogeek.com\/358352\/criminals-can-steal-your-phone-number-heres-how-to-stop-them\/"},{"key":"e_1_3_2_14_2","article-title":"Cross-Site Scripting (XSS)","author":"KirstenS","year":"2018","unstructured":"KirstenS. 2018. Cross-Site Scripting (XSS). Retrieved January 6, 2025 from https:\/\/bit.ly\/1Claka9","journal-title":"https:\/\/bit.ly\/1Claka9"},{"key":"e_1_3_2_15_2","unstructured":"Kim Zetter. 2010. Hacker Spoofs Cell Phone Tower to Intercept Calls. Retrieved January 10 2025 from https:\/\/www.wired.com\/2010\/07\/intercepting-cell-phone-calls\/"},{"key":"e_1_3_2_16_2","article-title":"RSA SecurID Hardware Tokens | Two Factor Authentication","author":"RSA","year":"2018","unstructured":"RSA. 2018. RSA SecurID Hardware Tokens | Two Factor Authentication. Retrieved March 30, 2018 from https:\/\/goo.gl\/rcuQZK","journal-title":"https:\/\/goo.gl\/rcuQZK"},{"key":"e_1_3_2_17_2","unstructured":"University of Washington IT Connect. 2019. Use the \u201cremember me\u201d option. Retrieved January 10 2025 from https:\/\/itconnect.uw.edu\/tools-services-support\/access-authentication\/2fa\/remember-me\/"},{"key":"e_1_3_2_18_2","unstructured":"E. V. Abhilash. 2018. Cookie Profiling. Retrieved January 10 2025 from https:\/\/www.linkedin.com\/pulse\/cookie-profiling-e-v-abhilash"},{"key":"e_1_3_2_19_2","article-title":"Yubico | Trust the Net with YubiKey Strong Two-Factor Authentication","author":"Yubico","year":"2018","unstructured":"Yubico. 2018. Yubico | Trust the Net with YubiKey Strong Two-Factor Authentication. Retrieved March 30, 2018 from https:\/\/www.yubico.com\/","journal-title":"https:\/\/www.yubico.com\/"},{"key":"e_1_3_2_20_2","unstructured":"Google. 2019. 2-Step Verification Phone Prompts. Retrieved January 6 2025 from https:\/\/bit.ly\/2W309oo"},{"key":"e_1_3_2_21_2","unstructured":"Cisco. 2019. Duo Push Notification. Retrieved January 6 2025 from https:\/\/duo.com\/resources\/videos\/duo-push-demonstration"},{"key":"e_1_3_2_22_2","unstructured":"Google. 2019. Google 2-Step Verification. Retrieved January 6 2025 from https:\/\/bit.ly\/1AyTGig"},{"key":"e_1_3_2_23_2","unstructured":"Matt Martin. 2019. Reduce your Duo logins with \u201cRemember me.\u201d Retrieved January 10 2025 from https:\/\/michigan.it.umich.edu\/news\/2019\/09\/17\/reduce-your-duo-logins-with-remember-me\/"},{"key":"e_1_3_2_24_2","unstructured":"Stefan Etienne and Barbara Krasnoff. 2019. How to use a two-factor security key. Retrieved January 10 2025 from https:\/\/www.theverge.com\/2019\/1\/31\/18203905\/two-factor-authentication-security-key-how-to-yubico"},{"key":"e_1_3_2_25_2","unstructured":"Microsoft. 2019. How to Use the Microsoft Authenticator App. Retrieved January 6 2025 from https:\/\/support.microsoft.com\/en-us\/help\/4026727"},{"key":"e_1_3_2_26_2","unstructured":"Microsoft Learn. 2024. Manage the \u201cStay signed in\u201d prompt in Microsoft Entra ID. Retrieved January 10 2025 from https:\/\/learn.microsoft.com\/en-us\/entra\/fundamentals\/how-to-manage-stay-signed-in-prompt"},{"key":"e_1_3_2_27_2","unstructured":"LastPass. 2019. How LastPass Works. Retrieved January 6 2025 from https:\/\/bit.ly\/2OtJN3Y"},{"key":"e_1_3_2_28_2","unstructured":"LastPass. 2019. LastPass Authenticator. Retrieved January 6 2025 from https:\/\/bit.ly\/3nOeulV"},{"key":"e_1_3_2_29_2","unstructured":"Google. 2019. Manage Saved Passwords. Retrieved January 6 2025 from https:\/\/bit.ly\/38N0XUw"},{"key":"e_1_3_2_30_2","unstructured":"Mozilla Support. 2019. Password Manager - Remember delete and edit logins and passwords in Firefox. Retrieved November 25 2019 from https:\/\/support.mozilla.org\/en-US\/kb\/password-manager-remember-delete-edit-logins"},{"key":"e_1_3_2_31_2","unstructured":"Microsoft Support. 2019. Remember passwords and fill out web forms for Internet Explorer 11. Retrieved November 25 2019 from https:\/\/support.microsoft.com\/en-us\/windows\/remember-passwords-and-fill-out-web-forms-for-internet-explorer-11-6883f6ce-0d1c-c2b9-e21e-705976d1c886"},{"key":"e_1_3_2_32_2","unstructured":"RSA Community. 2019. SecurID Hardware Tokens. Retrieved August 29 2019 from https:\/\/community.rsa.com\/s\/article\/SecurID-Tokens-e9b663a7"},{"key":"e_1_3_2_33_2","unstructured":"RSA 2019. RSA Security. Retrieved January 6 2025 from https:\/\/www.rsa.com\/en-us\/index"},{"key":"e_1_3_2_34_2","article-title":"Sound Login","author":"Sound Login","year":"2019","unstructured":"Sound Login. 2019. Sound Login. Retrieved January 6, 2025 from https:\/\/www.soundlogin.com\/","journal-title":"https:\/\/www.soundlogin.com\/"},{"key":"e_1_3_2_35_2","unstructured":"Google Support. 2019. Stay signed in or out of your Google Account. Retrieved January 10 2025 from https:\/\/support.google.com\/accounts\/answer\/54490?hl=en"},{"key":"e_1_3_2_36_2","article-title":"Titan Security Key.","author":"Google Cloud","year":"2019","unstructured":"Google Cloud. 2019. Titan Security Key.Retrieved January 6, 2025 from https:\/\/cloud.google.com\/titan-security-key","journal-title":"https:\/\/cloud.google.com\/titan-security-key"},{"key":"e_1_3_2_37_2","article-title":"U2F Technical Overview","author":"Yubico","year":"2019","unstructured":"Yubico. 2019. U2F Technical Overview. Retrieved January 6, 2025 from https:\/\/bit.ly\/2LC5Aqv","journal-title":"https:\/\/bit.ly\/2LC5Aqv"},{"key":"e_1_3_2_38_2","unstructured":"Google. 2019. Use Your Phone\u2019s Built-In Security Key. Retrieved January 6 2025 from https:\/\/bit.ly\/2JVKnri"},{"key":"e_1_3_2_39_2","unstructured":"RoboForm. 2020. RoboForm Home Page. Retrieved January 6 2025 from https:\/\/www.roboform.com\/"},{"key":"e_1_3_2_40_2","doi-asserted-by":"publisher","DOI":"10.1109\/AICCSA.2009.5069395"},{"key":"e_1_3_2_41_2","article-title":"Local and Remote Notification Programming Guide","year":"2018","unstructured":"Apple.2018. Local and Remote Notification Programming Guide. Retrieved July 1, 2020 from https:\/\/apple.co\/2CY1gRO","journal-title":"https:\/\/apple.co\/2CY1gRO"},{"key":"e_1_3_2_42_2","doi-asserted-by":"publisher","DOI":"10.1109\/RISP.1992.213269"},{"key":"e_1_3_2_43_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-15497-3_18"},{"key":"e_1_3_2_44_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_3_2_45_2","unstructured":"Thanh Bui Siddharth Prakash Rao Markku Antikainen Viswanathan Manihatty Bojan and Tuomas Aura. 2018. Man-in-the-machine: Exploiting ill-secured communication inside the computer. In Proceedings of the 27th USENIX Security Symposium (USENIX Security\u201918). 1511\u20131525."},{"key":"e_1_3_2_46_2","unstructured":"Oliver Burkeman. 2012. Online passwords: Keep it complicated. The Guardian. Retrieved April 5 2019 from https:\/\/bit.ly\/2OQHARr"},{"key":"e_1_3_2_47_2","first-page":"1","volume-title":"Proceedings of the USENIX Security Symposium","author":"Chiasson Sonia","year":"2006","unstructured":"Sonia Chiasson, Paul C. van Oorschot, and Robert Biddle. 2006. A usability study and critique of two password managers. In Proceedings of the USENIX Security Symposium. 1\u201316."},{"key":"e_1_3_2_48_2","doi-asserted-by":"publisher","DOI":"10.1145\/3173574.3174030"},{"key":"e_1_3_2_49_2","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23357"},{"key":"e_1_3_2_50_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-662-45472-5_24"},{"key":"e_1_3_2_51_2","doi-asserted-by":"publisher","DOI":"10.5555\/1791834.1791836"},{"key":"e_1_3_2_52_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-14527-8_1"},{"key":"e_1_3_2_53_2","article-title":"Two-Factor Authentication for Facebook Now Easier to Set Up","year":"2019","unstructured":"Facebook. 2019. Two-Factor Authentication for Facebook Now Easier to Set Up. Retrieved May 10, 2019 from https:\/\/bit.ly\/2MpF3vP","journal-title":"Retrieved May 10, 2019 from https:\/\/bit.ly\/2MpF3vP"},{"key":"e_1_3_2_54_2","doi-asserted-by":"publisher","DOI":"10.1145\/2335356.2335360"},{"key":"e_1_3_2_55_2","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242661"},{"key":"e_1_3_2_56_2","article-title":"Firebase Cloud Messaging | Firebase","year":"2018","unstructured":"Google.2018. Firebase Cloud Messaging | Firebase. Retrieved February 1, 2018 from https:\/\/firebase.google.com\/docs\/cloud-messaging\/","journal-title":"https:\/\/firebase.google.com\/docs\/cloud-messaging\/"},{"key":"e_1_3_2_57_2","article-title":"Bypassing the Windows Lock Screen","year":"2015","unstructured":"Hackaday. 2015. Bypassing the Windows Lock Screen. Retrieved December 10, 2023 from https:\/\/hackaday.com\/blog\/?s=bypassing+the+Windows+lock+screen","journal-title":"https:\/\/hackaday.com\/blog\/?s=bypassing+the+Windows+lock+screen"},{"key":"e_1_3_2_58_2","doi-asserted-by":"publisher","DOI":"10.1145\/1060745.1060815"},{"key":"e_1_3_2_59_2","doi-asserted-by":"publisher","DOI":"10.1145\/3241539.3241574"},{"key":"e_1_3_2_60_2","unstructured":"Threat Intelligence. 2022. Malware Attacks\u2014How They Work Attack Vectors and Prevention. Retrieved December 10 2023 from https:\/\/www.threatintelligence.com\/blog\/malware-attacks-how-they-work-attack-vectors-and-prevention"},{"key":"e_1_3_2_61_2","doi-asserted-by":"publisher","DOI":"10.1145\/3433210.3453084"},{"key":"e_1_3_2_62_2","doi-asserted-by":"publisher","DOI":"10.1145\/2508859.2516671"},{"key":"e_1_3_2_63_2","first-page":"483","volume-title":"Proceedings of the 24th USENIX Security Symposium","author":"Karapanos Nikolaos","year":"2015","unstructured":"Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, and Srdjan Capkun. 2015. Sound-Proof: Usable two-factor authentication based on ambient sound. In Proceedings of the 24th USENIX Security Symposium. 483\u2013498."},{"key":"e_1_3_2_64_2","first-page":"483","volume-title":"Proceedings of the 24th USENIX Security Symposium","author":"Karapanos Nikolaos","year":"2015","unstructured":"Nikolaos Karapanos, Claudio Marforio, Claudio Soriente, and Srdjan Capkun. 2015. Sound-Proof: Usable two-factor authentication based on ambient sound.. In Proceedings of the 24th USENIX Security Symposium. 483\u2013498."},{"key":"e_1_3_2_65_2","first-page":"233","volume-title":"Proceedings of the International Conference on Information Security and Cryptology","author":"Karole Ambarish","year":"2010","unstructured":"Ambarish Karole, Nitesh Saxena, and Nicolas Christin. 2010. A comparative usability evaluation of traditional password managers. In Proceedings of the International Conference on Information Security and Cryptology. 233\u2013251."},{"key":"e_1_3_2_66_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.38"},{"key":"e_1_3_2_67_2","first-page":"405","volume-title":"Proceedings of the International Conference on Financial Cryptography and Data Security","author":"Konoth Radhesh Krishnan","year":"2016","unstructured":"Radhesh Krishnan Konoth, Victor van der Veen, and Herbert Bos. 2016. How anywhere computing just killed your phone-based two-factor authentication. In Proceedings of the International Conference on Financial Cryptography and Data Security. 405\u2013421."},{"key":"e_1_3_2_68_2","first-page":"422","volume-title":"Proceedings of the International Conference on Financial Cryptography and Data Security","author":"Lang Juan","year":"2016","unstructured":"Juan Lang, Alexei Czeskis, Dirk Balfanz, Marius Schilder, and Sampath Srinivas. 2016. Security keys: Practical cryptographic second factors for the modern web. In Proceedings of the International Conference on Financial Cryptography and Data Security. 422\u2013440."},{"key":"e_1_3_2_69_2","doi-asserted-by":"publisher","DOI":"10.21236\/ADA614474"},{"key":"e_1_3_2_70_2","doi-asserted-by":"publisher","DOI":"10.1145\/3274694.3274699"},{"key":"e_1_3_2_71_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP40000.2020.00047"},{"key":"e_1_3_2_72_2","first-page":"10","volume-title":"Proceedings of the 2017 International Symposium on Cyber Security Cryptography and Machine Learning (CSCML\u201917)","author":"Meier Joshua","year":"2017","unstructured":"Joshua Meier, Jesse Zhang, Richard Zou, and James Mickens. 2017. Zero-effort two-factor authentication using audio signals. In Proceedings of the 2017 International Symposium on Cyber Security Cryptography and Machine Learning (CSCML\u201917). 10."},{"key":"e_1_3_2_73_2","article-title":"Windows Push Notification Services (WNS)","year":"2020","unstructured":"Microsoft.2020. Windows Push Notification Services (WNS). Retrieved July 1, 2020 from https:\/\/bit.ly\/3jSSEML. (2020)","journal-title":"https:\/\/bit.ly\/3jSSEML"},{"key":"e_1_3_2_74_2","doi-asserted-by":"crossref","unstructured":"David M\u2019Raihi Mihir Bellare Frank Hoornaert David Naccache and Ohad Ranen. 2005. HOTP: An HMAC-Based One-Time Password Algorithm. RFC 4226. Internet Engineering Task Force.","DOI":"10.17487\/rfc4226"},{"key":"e_1_3_2_75_2","doi-asserted-by":"crossref","unstructured":"David M\u2019Raihi Salah Machani Mingliang Pei and Johan Rydell. 2011. TOTP: Time-Based One-Time Password Algorithm. RFC 6238. Internet Engineering Task Force.","DOI":"10.17487\/rfc6238"},{"key":"e_1_3_2_76_2","article-title":"Lock Screen Bypass Already Discovered for Apple\u2019s iOS 12","author":"News Sophos","year":"2018","unstructured":"Sophos News. 2018. Lock Screen Bypass Already Discovered for Apple\u2019s iOS 12. Retrieved December 10, 2023 from https:\/\/news.sophos.com\/en-us\/2018\/10\/02\/lock-screen-bypass-already-discovered-for-apples-ios-12\/","journal-title":"https:\/\/news.sophos.com\/en-us\/2018\/10\/02\/lock-screen-bypass-already-discovered-for-apples-ios-12\/"},{"key":"e_1_3_2_77_2","article-title":"Android Phones Vulnerable to Lock Screen Bypass Exploit","author":"News Trend Micro","year":"2022","unstructured":"Trend Micro News. 2022. Android Phones Vulnerable to Lock Screen Bypass Exploit. Trend Micro News Retrieved December 10, 2023 from https:\/\/news.trendmicro.com\/2022\/11\/14\/android-phones-lock-screen-vulnerability-bypass-exploit-google-pixel\/","journal-title":"Trend Micro News"},{"key":"e_1_3_2_78_2","article-title":"That was then, this is now: A security evaluation of password generation, storage, and autofill in thirteen password managers","author":"Oesch Sean","year":"2019","unstructured":"Sean Oesch and Scott Ruoti. 2019. That was then, this is now: A security evaluation of password generation, storage, and autofill in thirteen password managers. arXiv preprint arXiv:1908.03296 (2019).","journal-title":"arXiv preprint arXiv:1908.03296"},{"key":"e_1_3_2_79_2","doi-asserted-by":"publisher","DOI":"10.1109\/CW52790.2021.00049"},{"key":"e_1_3_2_80_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2016.28"},{"key":"e_1_3_2_81_2","unstructured":"Jonathan Reed. 2023. LastPass Breaches Cast Doubt on Password Manager Safety. Retrieved January 6 2025 from https:\/\/securityintelligence.com\/news\/lastpass-breaches-cast-doubt-on-password-manager-safety\/l"},{"key":"e_1_3_2_82_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2018.00067"},{"key":"e_1_3_2_83_2","volume-title":"Proceedings of the USENIX Security Symposium","author":"Ross Blake","year":"2005","unstructured":"Blake Ross, Collin Jackson, Nick Miyake, Dan Boneh, and John C. Mitchell. 2005. Stronger password authentication using browser extensions. In Proceedings of the USENIX Security Symposium. 17\u201332."},{"key":"e_1_3_2_84_2","article-title":"Keylogger (keystroke logger or system monitor).","author":"Rouse Margaret","year":"2017","unstructured":"Margaret Rouse. 2017. Keylogger (keystroke logger or system monitor).TechTarget. Retrieved January 6, 2025 from https:\/\/searchsecurity.techtarget.com\/definition\/keylogger","journal-title":"Retrieved January 6, 2025 from https:\/\/searchsecurity.techtarget.com\/definition\/keylogger"},{"key":"e_1_3_2_85_2","doi-asserted-by":"publisher","DOI":"10.1145\/1053291.1053327"},{"key":"e_1_3_2_86_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2017.64"},{"key":"e_1_3_2_87_2","doi-asserted-by":"publisher","DOI":"10.1145\/2976749.2978328"},{"key":"e_1_3_2_88_2","doi-asserted-by":"publisher","DOI":"10.1145\/3212480.3212501"},{"key":"e_1_3_2_89_2","unstructured":"David Silver Suman Jana Dan Boneh Eric Chen and Collin Jackson. 2014. Password managers: Attacks and defenses. In Proceedings of the 23rd USENIX Security Symposium (USENIX Security\u201914). 449\u2013464."},{"key":"e_1_3_2_90_2","doi-asserted-by":"publisher","DOI":"10.1145\/2590296.2590336"},{"key":"e_1_3_2_91_2","first-page":"399","volume-title":"Proceedings of the USENIX Security Symposium","author":"Sunshine Joshua","year":"2009","unstructured":"Joshua Sunshine, Serge Egelman, Hazim Almuhimedi, Neha Atri, and Lorrie Faith Cranor. 2009. Crying wolf: An empirical study of SSL warning effectiveness. In Proceedings of the USENIX Security Symposium. 399\u2013416."},{"key":"e_1_3_2_92_2","doi-asserted-by":"publisher","DOI":"10.1109\/ICDCS.2016.90"},{"key":"e_1_3_2_93_2","doi-asserted-by":"publisher","DOI":"10.1109\/CNS.2018.8433202"},{"key":"e_1_3_2_94_2","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.30"},{"key":"e_1_3_2_95_2","unstructured":"Rob Waugh. 2012. No wonder hackers have it easy: Most of us now have 26 different online accounts\u2014but only five passwords. Daily Mail. Retrieved April 5 2019 from https:\/\/dailym.ai\/2uNS2Qk"},{"key":"e_1_3_2_96_2","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-030-22312-0_10"},{"key":"e_1_3_2_97_2","volume-title":"Proceedings of the Network and Distributed System Security Symposium (NDSS\u201998)","author":"Wu. Thomas D.","year":"1998","unstructured":"Thomas D. Wu.1998. The secure remote password protocol. In Proceedings of the Network and Distributed System Security Symposium (NDSS\u201998). 97\u2013111."},{"key":"e_1_3_2_98_2","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143126"},{"key":"e_1_3_2_99_2","doi-asserted-by":"publisher","DOI":"10.5555\/2695622"},{"key":"e_1_3_2_100_2","doi-asserted-by":"publisher","DOI":"10.1145\/3290607.3313093"}],"container-title":["ACM Computing Surveys"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711117","content-type":"unspecified","content-version":"vor","intended-application":"text-mining"},{"URL":"https:\/\/dl.acm.org\/doi\/pdf\/10.1145\/3711117","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,6,19]],"date-time":"2025-06-19T01:10:26Z","timestamp":1750295426000},"score":1,"resource":{"primary":{"URL":"https:\/\/dl.acm.org\/doi\/10.1145\/3711117"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,1,24]]},"references-count":99,"journal-issue":{"issue":"5","published-print":{"date-parts":[[2025,5,31]]}},"alternative-id":["10.1145\/3711117"],"URL":"https:\/\/doi.org\/10.1145\/3711117","relation":{},"ISSN":["0360-0300","1557-7341"],"issn-type":[{"value":"0360-0300","type":"print"},{"value":"1557-7341","type":"electronic"}],"subject":[],"published":{"date-parts":[[2025,1,24]]},"assertion":[{"value":"2024-01-01","order":0,"name":"received","label":"Received","group":{"name":"publication_history","label":"Publication History"}},{"value":"2024-11-30","order":2,"name":"accepted","label":"Accepted","group":{"name":"publication_history","label":"Publication History"}},{"value":"2025-01-24","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}