CRJun 19

An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites

arXiv:2511.101115.01 citationsh-index: 15
Predicted impact top 69% in CR · last 90 daysOriginality Incremental advance
AI Analysis

For web developers and security researchers, this work identifies critical usability and automation gaps in password update processes that undermine security recommendations.

This paper presents the first systematic analysis of 111 password update processes on top-ranked websites, revealing that they are often complex, inconsistent, and poorly supported by password managers, with security measures frequently hindering automation.

Password updates are a critical part of the password lifecycle and are recommended following exposure of reused passwords or suspected compromise. However, password update processes are often cumbersome, require manual password creation, and involve inconsistent website workflows that hinder reliable automation by password managers. In this work, we conduct the first in-depth, systematic analysis of 111 password update processes deployed on top-ranked websites. We provide novel insights into their overall security, usability, and automation capabilities, and contribute to authentication security research by improving the understanding of password update processes. Websites often deploy highly diverse, complex, and confusing password update processes that are not supported by password managers. Processes are often challenging to use, and end-users struggle to transfer experience and knowledge across websites. Notably, security measures designed to enhance security often hinder password manager automation. We conclude our work by discussing our findings and giving recommendations for web developers, the web standardization community, and security researchers.

Foundations

The foundational work for this paper's niche, ranked by how specifically the neighbourhood builds on it — not by global fame.

Your Notes