Passworld: A Serious Game to Promote Password Awareness and Diversity in an Enterprise Gokul Chettoor Jayakrishnan, Gangadhara Reddy Sirigireddy, Sukanya Vaddepalli, Vijayanand Banahatti, and Sachin Premsukh Lodha, TCS Research, Tata Consultancy Services Limited, Pune, India; Sankalp Suneel Pandit, Former employee of TCS Research, Tata Consultancy Services Limited, Pune, India https://www.usenix.org/conference/soups2020/presentation/jayakrishnan This paper is included in the Proceedings of the Sixteenth Symposium on Usable Privacy and Security. August 10–11, 2020 978-1-939133-16-8 Open access to the Proceedings of the Sixteenth Symposium on Usable Privacy and Security is sponsored by USENIX. Passworld: A Serious Game to Promote Password Awareness and Diversity in an Enterprise Gokul Chettoor Jayakrishnan, Gangadhara Reddy Sirigireddy, Sukanya Vaddepalli, Vijayanand Banahatti, Sachin Premsukh Lodha, Sankalp Suneel Pandit1 TCS Research, Tata Consultancy Services Limited, Pune, India (1former employee) {gokul.cj, gangadhara.sirigireddy, sukanya.vaddepalli, vijayanand.banahatti, sachin.lodha}@tcs.com,
[email protected] Abstract still prevalent [54, 57]. Even the method of two-factor Usage of weak passwords for authentication within an authentication generally consists of passwords as one of its organization can be exploited during cyberattacks leading factors [3, 40]. The human element involved in password to unauthorized account access, denial of service, data and creation is one of the major factors affecting password identity theft, sabotage etc. Such attacks could bring strength [35]. Studies show that people are more likely to financial and reputational losses apart from legal use weaker and easily memorable passwords because of the consequences. Organizational password policies came into lack of knowledge in creating stronger passwords [20] or being in an attempt to encourage users to create more due to the limitations in memorizing passwords [56].