Naomi Woods

dblp:190/8946 · DBLP profile ↗
← Back
6ranked-venue papers
5as first author
4since 2021 · last 2025
0000-0002-5692-5163ORCID · corroborated

Domains — the database's venue-derived domains; a paper can count in several

Security and privacy · 3 · 2 first-author · 3 since 2021Human-computer interaction and ubiquitous computing · 3 · 3 first-author · 1 since 2021
YearPublicationVenuePosition
2025 Questioning a security assumption: Are unique passwords harder to remember than reused or modified passwords?
abstract
Many users have serious problems remembering all their passwords. Even with available technologies such as, password managers, many users choose to rely solely on their memory. Managing multiple strong passwords lead many to adopt insecure password practices, for example, reusing and modifying passwords for multiple organizational and personal accounts. These insecure behaviors are widespread, resulting in substantial security breaches and financial losses. Numerous users reuse and modify their passwords believing it will help their password memorability. However, human memory theory would suggest the contrary. Therefore, to test this premise, two longitudinal studies (12 and 10 weeks) were conducted to examine password recall and memory interference from over 20,000 recalled passwords. Our results challenge the common belief that unique passwords are hard to remember; suggesting that they can be more memorable than modified or reused passwords. These findings have important implications as creating unique passwords is considered good security practice, while simultaneously improving password memorability, which could reduce insecure password behaviors and the associated costs.
Naomi Woods, Mikko Siponen
Comput. Secur.1
2024 How memory anxiety can influence password security behavior
abstract
Password reuse and modification are insecure password behaviors that are becoming increasingly prevalent as users are obliged to remember more passwords to access various digital services. Many users adopt these risky behaviors as a memory strategy in the belief that they have too many passwords for their memories to cope with. One important avenue in password research is metamemory, which encompasses the knowledge and understanding of memory capabilities and strategies. Previous research on password metamemory has examined the role that metamemory plays in memory performance (i.e., how well memory performs) and password recall. However, no previous research to date has investigated whether password reuse and modification are adopted as memory strategies due to an increase in knowledge and understanding of metamemory. To address this gap, two survey studies (Study1: N=50, Study 2: N=303) were implemented to examine the role that password metamemory plays in reusing and modifying passwords. Our findings suggest that of all metamemory constructs, users’ anxiety regarding their perceived ability to remember passwords can influence them to reuse and modify their passwords. These findings have potentially important implications because with an enhanced understanding of how users’ anxiety towards remembering passwords influences their security behavior, this could identify means of reducing password reuse and modification, thereby increasing password security and ultimately reduce some of the consequences of insecure password behaviors.
Naomi Woods, Mikko Siponen
Comput. Secur.1
2023 Enhancing the user authentication process with colour memory cues
abstract
The authentication process is the first line of defence against potential impostors, and therefore is an important concern when protecting personal and organisational data. Although there are many options to authenticate digital users, passwords remain the most common authentication mechanism. However, with password numbers increasing, many users struggle with remembering multiple passwords, which affects their security behaviour. Previous researchers and practitioners have attempted to suggest ways to improve password memorability and security simultaneously. We introduce novel approach that utilises colour as a memory cue to increase password memorability and security. A longitudinal study examined in total over 3000 passwords that were created, learnt and recalled (password process) over a period of five-weeks. By adding colour to the password process, our results suggest that password memorability and security can be increased simultaneously. Through giving the user the option of choosing the colours (compared with colours being preselected), encourages users to create more personal and meaningful memory cues when creating their passwords. Additionally, colour also provided another security parameter by increasing password entropy. These unique results have practical implications for researchers and practitioners that could positively impact password security, and the financial losses suffered due to password security breaches.
Naomi Woods, Johanna M. Silvennoinen
Behav. Inf. Technol.1
2022 Accessible authentication: Assessing the applicability for users with disabilities
Steven Furnell, Kirsi Helkala, Naomi Woods
Comput. Secur.3
2019 Improving password memorability, while not inconveniencing the user
Naomi Woods, Mikko Siponen
Int. J. Hum. Comput. Stud.1
2018 Too many passwords? How understanding our memory can increase password memorability
Naomi Woods, Mikko Siponen
Int. J. Hum. Comput. Stud.1