EDBT 2026 Demo / reviewers in the wild / expert
Julie Thorpe
dblp:53/114
· DBLP profile ↗
30ranked-venue papers
7as first author
8since 2021 · last 2025
0000-0002-6629-158XORCID · verified
Domains — the database's venue-derived domains; a paper can count in several
Security and privacy · 28 · 6 first-author · 7 since 2021Human-computer interaction and ubiquitous computing · 4 · 2 first-author · 1 since 2021Applied, interdisciplinary, general and emerging computing · 1 · 1 since 2021
| Year | Publication | Venue | Position |
|---|---|---|---|
| 2025 | Short Training Techniques to Enhance Usability of System-Assigned PINsabstractPersonal Identification Numbers (PINs) are widely used for authentication on mobile devices such as smartphones, which act as gateways to many important accounts (e.g., financial, email, etc.). Unfortunately, people tend to choose easy-to-recall PINs involving birthdays, anniversaries, or keypad patterns that are vulnerable to guessing attacks. System-assigned PINs can improve PIN security in this regard; however, they have usability problems such as feeling the need to store the assigned PIN, longer login times, and difficulty remembering. In this paper, we propose, design, and evaluate a set of short training techniques (16-34 seconds) inspired by implicit learning techniques, to improve the usability of system-assigned PINs. We evaluated our designs in a two-session user study with 184 university students. Our results show that some designs offer significant improvements in the login success rate, login times, and user perceptions. These advantages are in addition to our design’s short single-session training, making it more compatible with typical registration workflows than previously proposed multisession training techniques. Israt Jahan Jui, Amirali Salehi-Abari, Julie Thorpe |
PST | 3 |
| 2024 | Is Crowdsourcing a Puppet Show? Detecting a New Type of Fraud in Online PlatformsabstractCrowdsourcing platforms such as Amazon Mechanical Turk (MTurk) are important tools for researchers seeking to conduct studies with a broad, global participant base. Despite their popularity and demonstrated utility, we present evidence that suggests the integrity of data collected through Amazon MTurk is being threatened by the presence of puppeteers, apparently human workers controlling multiple puppet accounts that are capable of bypassing standard attention checks. If left undetected, puppeteers and their puppets can undermine the integrity of data collected on these platforms. This paper investigates data from two Amazon MTurk studies, finding that a substantial proportion of accounts (33% to 56.4%) are likely puppets. Our findings highlight the importance of adopting multifaceted strategies to ensure data integrity on crowdsourcing platforms. With the goal of detecting this type of fraud, we discuss a set of potential countermeasures for both puppets and bots with varying degrees of sophistication (e.g., employing AI). The problem of single entities (or puppeteers) manually controlling multiple accounts could exist on other crowdsourcing platforms; as such, their detection may be of broader application. While our findings suggest the need to re-evaluate the quality of crowdsourced data, many previous studies likely remain valid, particularly those with robust experimental designs. However, the presence of puppets may have contributed to false null results in some studies, suggesting that unpublished work may be worth revisiting with effective puppet detection strategies. Shengqian Wang, Israt Jahan Jui, Julie Thorpe |
NSPW | 3 |
| 2023 | PiXi: Password Inspiration by Exploring Information
Shengqian Wang, Amirali Salehi-Abari, Julie Thorpe |
ICICS | 3 |
| 2023 | Dissecting Nudges in Password Managers: Simple Defaults are Powerful
Samira Zibaei, Amirali Salehi-Abari, Julie Thorpe |
SOUPS | 3 |
| 2022 | Improving Peer Assessment with Graph Neural Networks
Alireza A. Namanloo, Julie Thorpe, Amirali Salehi-Abari |
EDM | 2 |
| 2021 | Long Passphrases: Potentials and LimitsabstractPassphrases offer an alternative to traditional passwords which aim to be stronger and more memorable. However, users tend to choose short passphrases with predictable patterns that may reduce the security they offer. To explore the potential of long passphrases, we formulate a set of passphrase policies and guidelines aimed at supporting their creation and use. Through a 39-day user study we analyze the usability and security of passphrases generated using our policies and guidelines. Our analysis indicates these policies lead to reasonable usability and promising security for some use cases, and that there are some common pitfalls in free-form passphrase creation. Our results suggest that our policies can support the use of long passphrases. Christopher Bonk, Zach Parish, Julie Thorpe, Amirali Salehi-Abari |
PST | 3 |
| 2021 | A study on priming methods for graphical passwords
Zach Parish, Amirali Salehi-Abari, Julie Thorpe |
J. Inf. Secur. Appl. | 3 |
| 2021 | A Large-Scale Analysis of the Semantic Password Model and Linguistic Patterns in PasswordsabstractIn this article, we present a thorough evaluation of semantic password grammars. We report multifactorial experiments that test the impact of sample size, probability smoothing, and linguistic information on password cracking. The semantic grammars are compared with state-of-the-art probabilistic context-free grammar ( PCFG ) and neural network models, and tested in cross-validation and A vs. B scenarios. We present results that reveal the contributions of part-of-speech (syntactic) and semantic patterns, and suggest that the former are more consequential to the security of passwords. Our results show that in many cases PCFGs are still competitive models compared to their latest neural network counterparts. In addition, we show that there is little performance gain in training PCFGs with more than 1 million passwords. We present qualitative analyses of four password leaks (Mate1, 000webhost, Comcast, and RockYou) based on trained semantic grammars, and derive graphical models that capture high-level dependencies between token classes. Finally, we confirm the similarity inferences from our qualitative analysis by examining the effectiveness of grammars trained and tested on all pairs of leaks. Rafael Veras, Christopher Collins 0001, Julie Thorpe |
ACM Trans. Priv. Secur. | 3 |
| 2019 | Towards models for quantifying the known adversaryabstractThe known adversary threat model has drawn growing attention of the security community. The known adversary is any individual with elevated first-hand knowledge of a potential victim and/or elevated access to a potential victim's devices. However, little attention is given on how to carefully recruit paired participants for user studies, who are qualified as legitimate known adversaries. Also, there is no formal framework for detecting and quantifying the known adversary. We develop three models, inspired by Social Psychology literature, to quantify the known adversary in paired user studies, and test them using a case study. Our results indicate that our proposed adapted-relationship closeness inventory and known adversary inventory models could accurately quantify and predict the known adversary. We subsequently discuss how social network analysis and artificial intelligence can automatically quantify the known adversary using publicly available data. We further discuss how these technologies can help the development of privacy assistants, which can automatically mitigate the risk of sharing sensitive information with potential known adversaries. Alaadin Addas, Julie Thorpe, Amirali Salehi-Abari |
NSPW | 2 |
| 2019 | Geographical Security Questions for Fallback AuthenticationabstractFallback authentication is the backup authentication method used when the primary authentication method (e.g., passwords, biometrics, etc.) fails. Currently, widely-deployed fallback authentication methods (e.g., security questions, email resets, and SMS resets) suffer from documented security and usability flaws that threaten the security of accounts. These flaws motivate us to design and study Geographical Security Questions (GeoSQ), a system for fallback authentication. GeoSQ is an Android application that utilizes autobiographical location data for fallback authentication. We performed security and usability analyses of GeoSQ through an in-person two-session lab study (n=36, 18 pairs). Our results indicate that GeoSQ exceeds the security of its counterparts, while its usability (specifically login time and memorability) has room for improvement. Alaadin Addas, Amirali Salehi-Abari, Julie Thorpe |
PST | 3 |
| 2019 | Geographic Hints for Passphrase AuthenticationabstractWe propose and study the use of geographic hints to aid memorability of passphrase-style authentication secrets. Geographic hints are map locations that are selected by the user at the time of passphrase creation, and shown to the user as a hint at the time of passphrase login. We implement the GeoHints system and analyze how geographic hints impact the usability and security of passphrase-style secrets in a multi-session user study (n=38). The study involved testing for multiple passphrase interference-each participant was asked to recall 4 distinct passphrases. Our study indicates that while geographic hints showed promise for reducing memory interference, GeoHints (as implemented) does not produce a viable authentication system, as the login success rate was 25% 7-11 days after passphrase selection. We analyze the root causes of login errors, finding that most were due to inexact recall of free-form text input. This finding points towards opportunities to improve the system design, and we suggest improvements that we believe will lead to viable systems that employ geographic hints. Alaadin Addas, Julie Thorpe, Amirali Salehi-Abari |
PST | 2 |
| 2019 | On password behaviours and attitudes in different populations
Ruba AlOmari, Julie Thorpe |
J. Inf. Secur. Appl. | 2 |
| 2018 | Reinforcing System-Assigned Passphrases Through Implicit LearningabstractPeople tend to choose short and predictable passwords that are vulnerable to guessing attacks. Passphrases are passwords consisting of multiple words, initially introduced as more secure authentication keys that people could recall. Unfortunately, people tend to choose predictable natural language patterns in passphrases, again resulting in vulnerability to guessing attacks. One solution could be system-assigned passphrases, but people have difficulty recalling them. With the goal of improving the usability of system-assigned passphrases, we propose a new approach of reinforcing system-assigned passphrases using implicit learning techniques. We design and test a system that implements this approach using two implicit learning techniques: contextual cueing and semantic priming. In a 780-participant online study, we explored the usability of 4-word system-assigned passphrases using our system compared to a set of control conditions. Our study showed that our system significantly improves usability of system-assigned passphrases, both in terms of recall rates and login time. Zeinab Joudaki, Julie Thorpe, Miguel Vargas Martin |
CCS | 2 |
| 2017 | System-Assigned Passwords You Can't Write Down, But Don't Need ToabstractWe explore the feasibility of Tacit Secrets: systemassigned passwords that you can remember, but cannot write down or otherwise communicate. We design an approach to creating Tacit Secrets based on Contextual Cueing, an implicit learning method previously studied in the cognitive psychology literature. Our feasibility study involving 30 participants indicates that our approach has strong security properties: resistance to brute-force attacks, online attacks, phishing attacks, and some coercion attacks. It also offers protection against leaks from other verifiers as the secrets are system-assigned. Our approach also has a high login success rate and low false positive rates. We explore the trade-offs of different configurations of our design and provide insight into valuable directions for future work. Zeinab Joudaki, Julie Thorpe, Miguel Vargas Martin |
PST | 2 |
| 2016 | An Exploration of Geographic Authentication SchemesabstractWe design and explore the usability and security of two geographic authentication schemes: GeoPass and GeoPassNotes. GeoPass requires users to choose a place on a digital map to authenticate with (a location password). GeoPassNotes-an extension of GeoPass-requires users to annotate their location password with a sequence of words that they can associate with the location (an annotated location password). In GeoPassNotes, users are authenticated by correctly entering both a location and an annotation. We conducted user studies to test the usability and assess the security of location passwords and annotated location passwords. The results indicate that both the variants are highly memorable, and that annotated location passwords may be more advantageous than location passwords alone due to their increased security and the minimal usability impact introduced by the annotation. Brent MacRae, Amirali Salehi-Abari, Julie Thorpe |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2014 | The presentation effect on graphical passwordsabstractWe provide a simple yet powerful demonstration of how an unobtrusive change to a graphical password interface can modify the distribution of user chosen passwords, and thus possibly the security it provides. The only change to the interface is how the background image is presented to the user in the password creation phase--we call the effect of this change the "presentation effect". We demonstrate the presentation effect by performing a comparative user study of two groups using the same background image, where the image is presented in two different ways prior to password creation. Our results show a statistically different distribution of user's graphical passwords, with no observed usability consequences. Julie Thorpe, Muath Al-Badawi, Brent MacRae, Amirali Salehi-Abari |
CHI | 1 |
| 2014 | On Semantic Patterns of Passwords and their Security Impact
Rafael Veras, Christopher Collins 0001, Julie Thorpe |
NDSS | 3 |
| 2014 | Crypto-assistant: Towards facilitating developer's encryption of sensitive dataabstractThe lack of encryption of data at rest or in motion is one of the top 10 database vulnerabilities [1]. We suggest that this vulnerability could be prevented by encouraging developers to perform encryption-related tasks by enhancing their integrated development environment (IDE). To this end, we created the Crypto-Assistant: a modified version of the Hibernate Tools plug-in for the popular Eclipse IDE. The purpose of the Crypto-Assistant is to mitigate the impact of developers' lack of security knowledge related to encryption by facilitating the use of encryption directives via a graphical user interface that seamlessly integrates with Hibernate Tools. Two preliminary tests helped us to identify items for improvement which have been implemented in Crypto-Assistant. We discuss Crypto-Assistant's architecture, interface, changes in the developers' workflow, and design considerations. Ricardo Rodriguez Garcia, Julie Thorpe, Miguel Vargas Martin |
PST | 2 |
| 2013 | Usability and security evaluation of GeoPass: a geographic location-password schemeabstractWe design, implement, and evaluate GeoPass: an interface for digital map-based authentication where a user chooses a place as his or her password (i.e., a "location-password"). We conducted a multi-session in-lab/at-home user study to evaluate the usability, memorability, and security of location-passwords created with GeoPass. The results of our user study found that 97% of users were able to remember their location-password over the span of 8-9 days and most without any failed login attempts. Users generally welcomed GeoPass; all of the users who completed the study reported that they would at least consider using GeoPass for some of their accounts. We also perform an in-depth usability and security analysis of location-passwords. Our security analysis includes the effect of information that could be gleaned from social engineering. The results of our security analysis show that location-passwords created with GeoPass can have reasonable security against online attacks, even when accounting for social engineering attacks. Based on our results, we suggest GeoPass would be most appropriate in contexts where logins occur infrequently, e.g., as an alternative to secondary authentication methods used for password resets, or for infrequently used online accounts. Julie Thorpe, Brent MacRae, Amirali Salehi-Abari |
SOUPS | 1 |
| 2012 | Video-passwords: advertising while authenticatingabstractWe introduce a new class of authentication schemes called "video-passwords", which require the user to watch and remember parts of a given video (e.g., a sequence of scenes, movements, and/or sounds). We propose four different video-password schemes, describe their prototypes, and analyze their security. Under certain parameters, the security of some of these schemes appears to be theoretically comparable to traditional text passwords. Video-passwords provide more than potentially better security; they also present a unique opportunity for businesses to consider -- advertising through the rich multimedia used in the login task. We suggest that the adoption of new schemes, such as video-passwords may be more likely in the presence of monetary incentives provided through advertising; we also discuss some ethical issues that may arise from such incentives. Julie Thorpe, Amirali Salehi-Abari, Robert Burden |
NSPW | 1 |
| 2012 | Visualizing semantics in passwords: the role of datesabstractWe begin an investigation into the semantic patterns underlying user choice in passwords. Understanding semantic patterns provides insight into how people choose passwords, which in turn can be used to inform usable password policies and password guidelines. As semantic patterns are difficult to recognize automatically, we turn to visualization to aid in their discovery. We focus on dates in passwords, designing an interactive visualization for their detailed analysis, and using it to explore the RockYou dataset of over 32 million passwords. Our visualization enabled us to analyze the dataset in many dimensions, including the relationship between dates and their co-occurring text. We use our observations from the visualization to guide further analysis, leading to our findings that nearly 5% of passwords in the RockYou dataset represent pure dates (either purely numerical or mixed alphanumeric representations) and the presence of many patterns within the dates that people choose (such as repetition, the first days of the month, recent years, and holidays). Rafael Veras, Julie Thorpe, Christopher Collins 0001 |
VizSEC | 2 |
| 2011 | Exploiting predictability in click-based graphical passwordsabstractWe provide an in-depth study of the security of click-based graphical password schemes like PassPoints (Weidenbeck et al., 2005), by exploring popular points (hot-spots), and examining strategies to predict and exploit them in guessing attacks. We report on both short- and long-term user studies: one lab-controlled, involving 43 users and 17 diverse images, the other a field test of 223 user accounts. We provide empirical evidence that hot-spots do exist for many images, some more so than others. We explore the use of “human-computation” (in this context, harvesting click-points from a small set of users) to predict these hot-spots. We generate two “human-seeded” attacks based on this method: one based on a first-order Markov model, another based on an independent probability model. Within 100 guesses, our first-order Markov model-based attack finds 4% of passwords in one image's data set, and 10% of passwords in a second image's data set. Our independent model-based attack finds 20% within 2 33 guesses in one image's data set and 36% within 2 31 guesses in a second image's data set. These are all for a system whose full password space has cardinality 2 43 . We evaluate our first-order Markov model-based attack with cross-validation of the field study data, which finds an average of 7–10% of user passwords within 3 guesses. We also begin to explore some click-order pattern attacks, which we found improve on our independent model-based attacks. Our results suggest that these graphical password schemes (with parameters as originally proposed) are vulnerable to offline and online attacks, even on systems that implement conservative lock-out policies. Paul C. van Oorschot, Julie Thorpe |
J. Comput. Secur. | 2 |
| 2010 | Purely automated attacks on passpoints-style graphical passwordsabstractWe introduce and evaluate various methods for purely automated attacks against PassPoints-style graphical passwords. For generating these attacks, we introduce a graph-based algorithm to efficiently create dictionaries based on heuristics such as click-order patterns (e.g., five points all along a line). Some of our methods combine click-order heuristics with focus-of-attention scan-paths generated from a computational model of visual attention, yielding significantly better automated attacks than previous work. One resulting automated attack finds 7%-16% of passwords for two representative images using dictionaries of approximately 226entries (where the full password space is 243). Relaxing click-order patterns substantially increased the attack efficacy albeit with larger dictionaries of approximately 235entries, allowing attacks that guessed 48%-54% of passwords (compared to previous results of 1% and 9% on the same dataset for two images with 235guesses). These latter attacks are independent of focus-of-attention models, and are based on image-independent guessing patterns. Our results show that automated attacks, which are easier to arrange than human-seeded attacks and are more scalable to systems that use multiple images, require serious consideration when deploying basic PassPoints-style graphical passwords. Paul C. van Oorschot, Amirali Salehi-Abari, Julie Thorpe |
IEEE Trans. Inf. Forensics Secur. | 3 |
| 2008 | On Purely Automated Attacks and Click-Based Graphical PasswordsabstractWe present and evaluate various methods for purely automated attacks against click-based graphical passwords. Our purely automated methods combine click-order heuristics with focus-of-attention scan-paths generated from a computational model of visual attention. Our method results in a significantly better automated attack than previous work, guessing 8-15% of passwords for two representative images using dictionaries of less than 224.6entries, and about 16% of passwords on each of these images using dictionaries of less than 231.4entries (where the full password space is 243). Relaxing our click-order pattern substantially increased the efficacy of our attack albeit with larger dictionaries of 234.7entries, allowing attacks that guessed 48-54% of passwords (compared to previous results of 0.9% and 9.1% on the same two images with 235guesses). These latter automated attacks are independent of focus-of-attention models, and are based on image-independent guessing patterns. Our results show that automated attacks, which are easier to arrange than human-seeded attacks and are more scalable to systems that use multiple images, pose a significant threat. Amirali Salehi-Abari, Julie Thorpe, Paul C. van Oorschot |
ACSAC | 2 |
| 2008 | On predictive models and user-drawn graphical passwordsabstractIn commonplace text-based password schemes, users typically choose passwords that are easy to recall, exhibit patterns, and are thus vulnerable to brute-force dictionary attacks. This leads us to ask whether other types of passwords (e.g., graphical) are also vulnerable to dictionary attack because of users tending to choose memorable passwords. We suggest a method to predict and model a number of such classes for systems where passwords are created solely from a user's memory. We hypothesize that these classes define weak password subspaces suitable for an attack dictionary. For user-drawn graphical passwords, we apply this method with cognitive studies on visual recall. These cognitive studies motivate us to define a set of password complexity factors (e.g., reflective symmetry and stroke count), which define a set of classes. To better understand the size of these classes and, thus, how weak the password subspaces they define might be, we use the “Draw-A-Secret” (DAS) graphical password scheme of Jermyn et al. [1999] as an example. We analyze the size of these classes for DAS under convenient parameter choices and show that they can be combined to define apparently popular subspaces that have bit sizes ranging from 31 to 41—a surprisingly small proportion of the full password space (58 bits). Our results quantitatively support suggestions that user-drawn graphical password systems employ measures, such as graphical password rules or guidelines and proactive password checking. Paul C. van Oorschot, Julie Thorpe |
ACM Trans. Inf. Syst. Secur. | 2 |
| 2007 | Human-Seeded Attacks and Exploiting Hot-Spots in Graphical Passwords
Julie Thorpe, Paul C. van Oorschot |
USENIX Security Symposium | 1 |
| 2005 | Highlights from the 2005 New Security Paradigms WorkshopabstractThis panel highlights a selection of the most interesting and provocative papers from the 2005 New Security Paradigms Workshop. This workshop was held September 2005 - the URL for more information is http://www.nspw.org. The panel consists of authors of the selected papers, and the session is moderated by the workshop's general chairs. We present selected papers focusing on exciting major themes that emerged from the workshop. These are the papers that will provoke the most interesting discussion at ACSAC. Simon N. Foley, Abe Singer, Michael E. Locasto, Stelios Sidiroglou-Douskos, Angelos D. Keromytis, John P. McDermott, Julie Thorpe, Paul C. van Oorschot, Anil Somayaji, Richard Ford, Mark Bush, Alex Boulatov |
ACSAC | 7 |
| 2005 | Pass-thoughts: authenticating with our mindsabstractWe present a novel idea for user authentication that we call pass-thoughts. Recent advances in Brain-Computer Interface (BCI) technology indicate that there is potential for a new type of human-computer interaction: a user thoughts directly to a computer. The goal of a pass-thought system would be to extract as much entropy as possible from a user's brain signals upon transmitting a thought. Provided that these brain signals can be recorded and processed in an accurate and repeatable way, a pass-thought system might provide a quasi two-factor, changeable, authentication method resistant to shoulder-surfing. The potential size of the space of a pass-thought system would seem to be unbounded in theory, although in practice it will be finite due to system constraints. In this paper, we discuss the motivation and potential of pass-thought authentication, the status quo of BCI technology, and outline the design of what we believe to be a currently feasible pass-thought system. We also briefly mention the need for general exploration and open debate regarding ethical considerations for such technologies. Julie Thorpe, Paul C. van Oorschot, Anil Somayaji |
NSPW | 1 |
| 2004 | Towards Secure Design Choices for Implementing Graphical PasswordsabstractWe study the impact of selected parameters on the size of the password space for "Draw-A-Secret" (DAS) graphical passwords. We examine the role of and relationships between the number of composite strokes, grid dimensions, and password length in the DAS password space. We show that a very significant proportion of the DAS password space depends on the assumption that users will choose long passwords with many composite strokes. If users choose passwords having 4 or fewer strokes, with passwords of length 12 or less on a 5 /spl times/ 5 grid, instead of up to the maximum 12 possible strokes, the size of the DAS password space is reduced from 58 to 40 bits. Additionally, we found a similar reduction when users choose no strokes of length 1. To strengthen security, we propose a technique and describe a representative system that may gain up to 16 more bits of security with an expected negligible increase in input time. Our results can be directly applied to determine secure design choices, graphical password parameter guidelines, and in deciding which parameters deserve focus in graphical password user studies. Julie Thorpe, Paul C. van Oorschot |
ACSAC | 1 |
| 2004 | Graphical Dictionaries and the Memorable Space of Graphical Passwords
Julie Thorpe, Paul C. van Oorschot |
USENIX Security Symposium | 1 |