'Your password is invalid': Improving website password practices

Jan 31, 2012

Internet users are increasingly asked to register with a user name and password before being able to access the content of many sites. In their upcoming Ergonomics in Design article, "A Passport to UX – Design of Password Practices," human factors/ergonomics researchers Soolmaz Moshfeghian and Young Sam Ryu identify impediments to efficient password creation and provide design strategies for enhancing the user experience.

Because there is no standard method for setting up passwords, each Web site employs its own set of requirements and restrictions. After investigating the pros and cons of design-related features of the requirement and restriction practices of 90 popular Web sites, the authors found that more than half the sites failed to display password guidance prior to the first attempt. Users may receive multiple error messages if their chosen passwords do not line up with system requirements, which can lead to confusion and frustration for the user and increased operating expenses for system administrators.

The authors offer a number of recommendations for Web designers seeking to improve the : Provide users with password requirements prior to their first attempt; use clear and concise language to communicate the password requirements; present, at a minimum, length and character requirements; and avoid placing password requirements in the entry box.

"This study helps us gain more insight into the current state of password practices and helps create more intuitive and empathic interactions," said Moshfeghian. "Intuitive password practices lead to increased user trust and thus user sustainability. In short, the optimal goal is to humanize interfaces, make them as intuitive as possible, and bridge the gap between users and interfaces."

Enhancing user experience through effective password practices can have many benefits. A more user-friendly registration process may produce a larger number of successfully registered accounts, which can translate into increased sales and a more recognizable brand. Fewer failed registration attempts can result in reduced system maintenance, security, and recovery costs.

Explore further: New comic book stars Facebook COO Sheryl Sandberg

Provided by Human Factors and Ergonomics Society

2 /5 (1 vote)
add to favorites email to friend print save as pdf

Related Stories

Better passwords get with the beat

May 17, 2011

No password is 100% secure. There are always ways and means for those with malicious intent to hack, crack or socially engineer access to a password. Indeed, there are more and more websites and databases compromised on a ...

Tired of Passwords? Replace Them With Your Fingerprint

Sep 14, 2004

If you're like most people, you have more than a dozen passwords and user names to remember. Whether you're checking your e-mail for new messages, catching up on the news, posting to a Web discussion group, ...

Apple patent sends password secrets to adapters

Jan 06, 2012

(PhysOrg.com) -- First-time computer users in the early days, pre-hacking security traumas, were confronted with a new life requirement: creating and remembering system passwords. Not too easy, users were ...

Recommended for you

Privacy groups take 2nd hit on license plate data

Sep 19, 2014

A California judge's ruling against a tech entrepreneur seeking access to records kept secret in government databases detailing the comings and goings of millions of cars in the San Diego area via license plate scans was ...

Scots' inventions are fuel for independence debate

Sep 17, 2014

What has Scotland ever done for us? Plenty, it turns out. The land that gave the world haggis and tartan has produced so much more, from golf and television to Dolly the Sheep and "Grand Theft Auto."

White House backs use of body cameras by police

Sep 16, 2014

Requiring police officers to wear body cameras is one potential solution for bridging deep mistrust between law enforcement and the public, the White House said, weighing in on a national debate sparked by the shooting of ...

User comments : 1

Adjust slider to filter visible comments by rank

Display comments: newest first

Twin
not rated yet Jan 31, 2012
I hate being told that my password is "not complex enough" or my first name is invalid (J.) I wouldn't mind a warning, but after that, it should be my option.
The fact is that hackers seldom break into individual accounts. They would much rather reach mass data that resides at levels deeper than passwords.