Password sharing: implications for security design based on social practice

  • Authors:
  • Supriya Singh;Anuja Cabraal;Catherine Demosthenous;Gunela Astbrink;Michele Furlong

  • Affiliations:
  • RMIT University, Melbourne, Australia;RMIT University, Melbourne, Australia;Griffith University, Brisbane, Australia;GSA Information Consulants, Brisbane, Australia;GSA Information Consulants, Brisbane, Australia

  • Venue:
  • Proceedings of the SIGCHI Conference on Human Factors in Computing Systems
  • Year:
  • 2007

Quantified Score

Hi-index 0.01

Visualization

Abstract

Current systems for banking authentication require that customers not reveal their access codes, even to members of the family. A study of banking and security in Australia shows that the practice of sharing passwords does not conform to this requirement. For married and de facto couples, password sharing is seen as a practical way of managing money and a demonstration of trust. Sharing Personal Identification Numbers (PINs) is a common practice among remote indigenous communities in Australia. In areas with poor banking access, this is the only way to access cash. People with certain disabilities have to share passwords with carers, and PIN numbers with retail clerks. In this paper we present the findings of a qualitative user study of banking and money management. We suggest design criteria for banking security systems, based on observed social and cultural practices of password and PIN number sharing.