- Password fatigue
Password fatigue describes the
syndrome where people are required to remember an excessive number ofpassword s as part of their daily living.The increasing prominence of
information technology and theInternet in employment, finance, recreation and other aspects of people's lives, and the ensuing introduction of secure transaction technology, has led to people accumulating a proliferation of accounts and passwords. According to British online-security consultant NTA Monitor the typical intensive computer user has 21 accounts that require apassword .Aside from contributing to stress password fatigue may encourage people to adopt habits that reduce the security of their protected information. For example, an account holder might use the same password for several different accounts, deliberately choose easy to remember passwords that are vulnerable to
cracking , or rely on written records of their passwords.Other factors causing password fatigue are
* unexpected demands that a user create a new password
* unexpected demands that a user create a new password that uses particular pattern of letters, digits, and special characters
*demand that the user type the new password twice.
* blind typing, both when responding to a password prompt and when setting a new password.Single sign-on software (SSO) can help mitigate this problem by only requiring users to remember one password to an application that in turn will automatically give access to several other accounts. This is a feature provided by the service providers themselves, the end user does not need to install any software on their system. A potential disadvantage is that loss of a single password will prevent access to all services using the SSO system, and theft or misuse of such a password presents a criminal or attacker with many targets.Many
OS 's provide a mechanism to store and retrieve passwords by using the users login password to unlock an encrypted password database.Mac OS X has a Keychain feature that provides this functionality, and similar functionality is present in theGNOME andKDE open source desktops.Microsoft Windows does not have an explicit function for this, howeverweb browser developers have added similar functionality to all of the major Windows browsers, and password management software such asKeePass andPassword Safe can help mitigate the problem of password fatigue by storing passwords in a database encrypted with a single password.Additionally the majority of password protected web services provide a password recovery feature that will allow users to recover their passwords via the email address (or other information) tied to that account.
These tools pose the problem that if the user's system is corrupted, stolen or compromised, apart from problems of the data being misused, they can also lose access to sites where they rely on the password store or recovery features to remember their login data. For this reason it is often advised to keep a separate record of sites, usernames and passwords that is physically independent of the system.
ee also
*
Identity management
*Password
*Password strength
*Password Manager
*External links
* [http://www.washingtonpost.com/wp-dyn/content/article/2006/09/22/AR2006092201612_pf.html Access Denied] By Yuki Noguchi, Washington Post September 23, 2006.
* [http://www.readwriteweb.com/archives/majority_use_same_password.php Bad Form: 61% Use Same Password for Everything] by Josh Catone, January 17, 2008.
Wikimedia Foundation. 2010.