I'm too busy to reset my LinkedIn password: On the effectiveness of password reset emails

  • Jun Ho Huh
  • , Hyoungshick Kim
  • , Swathi S.V.P. Rayala
  • , Rakesh B. Bobba
  • , Konstantin Beznosov

Research output: Chapter in Book/Report/Conference proceedingConference contributionpeer-review

20 Scopus citations

Abstract

A common security practice used to deal with a password breach is locking user accounts and sending out an email to tell users that they need to reset their password to unlock their account. This paper evaluates the effectiveness of this security practice based on the password reset email that LinkedIn sent out around May 2016, and through an online survey conducted on 249 LinkedIn users who received that email. Our evaluation shows that only about 46% of the participants reset their passwords. The mean time taken to reset password was 26.3 days, revealing that a significant proportion of the participants reset their password a few weeks, or even months after first receiving the email. Our findings suggest that more effective persuasive measures need to be added to convince users to reset their password in a timely manner, and further reduce the risks associated with delaying password resets.

Original languageEnglish
Title of host publicationCHI 2017 - Proceedings of the 2017 ACM SIGCHI Conference on Human Factors in Computing Systems
Subtitle of host publicationExplore, Innovate, Inspire
PublisherAssociation for Computing Machinery
Pages387-391
Number of pages5
ISBN (Electronic)9781450346559
DOIs
StatePublished - 2 May 2017
Event2017 ACM SIGCHI Conference on Human Factors in Computing Systems, CHI 2017 - Denver, United States
Duration: 6 May 201711 May 2017

Publication series

NameConference on Human Factors in Computing Systems - Proceedings
Volume2017-May

Conference

Conference2017 ACM SIGCHI Conference on Human Factors in Computing Systems, CHI 2017
Country/TerritoryUnited States
CityDenver
Period6/05/1711/05/17

Keywords

  • LinkedIn
  • Password breach
  • Password reset
  • Reset email

Fingerprint

Dive into the research topics of 'I'm too busy to reset my LinkedIn password: On the effectiveness of password reset emails'. Together they form a unique fingerprint.

Cite this