{"status":"ok","message-type":"work","message-version":"1.0.0","message":{"indexed":{"date-parts":[[2025,9,26]],"date-time":"2025-09-26T00:20:51Z","timestamp":1758846051585,"version":"3.44.0"},"reference-count":77,"publisher":"Association for Computing Machinery (ACM)","issue":"3","license":[{"start":{"date-parts":[[2025,9,3]],"date-time":"2025-09-03T00:00:00Z","timestamp":1756857600000},"content-version":"vor","delay-in-days":0,"URL":"https:\/\/2.zoppoz.workers.dev:443\/http\/www.acm.org\/publications\/policies\/copyright_policy#Background"}],"funder":[{"DOI":"10.13039\/100000001","name":"NSF","doi-asserted-by":"publisher","award":["2226404"],"award-info":[{"award-number":["2226404"]}],"id":[{"id":"10.13039\/100000001","id-type":"DOI","asserted-by":"publisher"}]}],"content-domain":{"domain":["dl.acm.org"],"crossmark-restriction":true},"short-container-title":["Proc. ACM Interact. Mob. Wearable Ubiquitous Technol."],"published-print":{"date-parts":[[2025,9,3]]},"abstract":"<jats:p>Users continue to authenticate on a wide range of devices. Logging into such devices is often complex due to f actors related to the variety of devices used and because of passwords. While passwords can present a challenge for users---especially in creating secure passwords---password managers can help users generate and store passwords. However, research has shown that users avoid generating passwords, often giving the rationale that it is difficult to enter generated passwords on devices without a password manager. In this paper, we conduct a survey (n = 999) of i ndividuals f rom the US, UK, and Europe, exploring the range of devices on which they enter passwords and the challenges associated with password entry on those devices. WWe find that password entry on devices without password managers is a common occurrence and comes with significant usability challenges that often lead users to weaken their passwords to increase the ease of entry. We conclude this paper by discussing how future research could address these challenges and encourage users to adopt generated passwords.<\/jats:p>","DOI":"10.1145\/3749491","type":"journal-article","created":{"date-parts":[[2025,9,3]],"date-time":"2025-09-03T17:15:45Z","timestamp":1756919745000},"page":"1-30","update-policy":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/crossmark-policy","source":"Crossref","is-referenced-by-count":0,"title":["A Large-Scale Survey of Password Entry Practices on Non-Desktop Devices"],"prefix":"10.1145","volume":"9","author":[{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0009-0007-8988-5501","authenticated-orcid":false,"given":"John","family":"Sadik","sequence":"first","affiliation":[{"name":"The University of Tennessee, Knoxville, TN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]},{"ORCID":"https:\/\/2.zoppoz.workers.dev:443\/https\/orcid.org\/0000-0002-6917-4186","authenticated-orcid":false,"given":"Scott","family":"Ruoti","sequence":"additional","affiliation":[{"name":"The University, Knoxville, TN, USA"}],"role":[{"role":"author","vocabulary":"crossref"}]}],"member":"320","published-online":{"date-parts":[[2025,9,3]]},"reference":[{"key":"e_1_2_1_1_1","doi-asserted-by":"publisher","DOI":"10.1145\/3314111.3319837"},{"key":"e_1_2_1_2_1","doi-asserted-by":"publisher","DOI":"10.3390\/fi12110189"},{"key":"e_1_2_1_3_1","unstructured":"Apple. 2020. Apple\/password-manager-resources: A place for creators and users of password managers to collaborate on resources to make password management better. https:\/\/2.zoppoz.workers.dev:443\/https\/github.com\/apple\/password-manager-resources."},{"key":"e_1_2_1_4_1","doi-asserted-by":"publisher","DOI":"10.1145\/1935701.1935740"},{"key":"e_1_2_1_5_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-642-22950-3_9"},{"key":"e_1_2_1_6_1","volume-title":"Counting clicks and beeps: Exploring numerosity based haptic and audio PIN entry. Interacting with computers 24, 5","author":"Bianchi Andrea","year":"2012","unstructured":"Andrea Bianchi, Ian Oakley, and Dong Soo Kwon. 2012. Counting clicks and beeps: Exploring numerosity based haptic and audio PIN entry. Interacting with computers 24, 5 (2012), 409--422."},{"key":"e_1_2_1_7_1","doi-asserted-by":"publisher","DOI":"10.1145\/2602299.2602315"},{"key":"e_1_2_1_8_1","doi-asserted-by":"publisher","DOI":"10.1109\/SP.2012.44"},{"key":"e_1_2_1_9_1","doi-asserted-by":"publisher","DOI":"10.1145\/2049536.2049561"},{"key":"e_1_2_1_10_1","unstructured":"Mike Coleman. 2001. Weegie Home Page. https:\/\/2.zoppoz.workers.dev:443\/https\/weegie.sourceforge.net\/."},{"key":"e_1_2_1_11_1","doi-asserted-by":"publisher","DOI":"10.14722\/ndss.2014.23357"},{"key":"e_1_2_1_12_1","doi-asserted-by":"publisher","DOI":"10.1145\/1556262.1556312"},{"key":"e_1_2_1_13_1","doi-asserted-by":"publisher","DOI":"10.1109\/infcom.2010.5461951"},{"key":"e_1_2_1_14_1","doi-asserted-by":"publisher","DOI":"10.1016\/j.ijhcs.2012.02.008"},{"key":"e_1_2_1_15_1","volume-title":"Mohammad Maifi Hasan Khan, and Ross Buck","author":"Fagan Michael","year":"2017","unstructured":"Michael Fagan, Yusuf Albayram, Mohammad Maifi Hasan Khan, and Ross Buck. 2017. An investigation into users' considerations towards using password managers. Human-centric computing and information sciences 7, 1 (2017), 1--20."},{"key":"e_1_2_1_16_1","doi-asserted-by":"publisher","DOI":"10.1145\/1242572.1242661"},{"key":"e_1_2_1_17_1","volume-title":"Proceedings of the 18th Symposium on Usable Privacy and Security. USENIX.","author":"Gautam Anuj","year":"2022","unstructured":"Anuj Gautam, Shan Lalani, and Scott Ruoti. 2022. Improving password generation through the design of a password composition policy description language. In Proceedings of the 18th Symposium on Usable Privacy and Security. USENIX."},{"key":"e_1_2_1_18_1","doi-asserted-by":"publisher","DOI":"10.1145\/1143120.1143127"},{"key":"e_1_2_1_19_1","volume-title":"The constant comparative method of qualitative analysis. Social problems 12, 4","author":"Glaser Barney G","year":"1965","unstructured":"Barney G Glaser. 1965. The constant comparative method of qualitative analysis. Social problems 12, 4 (1965), 436--445."},{"key":"e_1_2_1_20_1","doi-asserted-by":"publisher","unstructured":"Paul Grassi James Fenton Elaine Newton Ray Perlner Andrew Regenscheid William Burr Justin Richer Naomi Lefkovitz Jamie Danker Yee-Yin Choong Kristen Greene and Mary Theofanos. 2020. Digital Identity Guidelines: Authentication and Lifecycle Management [includes updates as of 03-02- 2020]. https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.6028\/NIST.SP.800-63b","DOI":"10.6028\/NIST.SP.800-63b"},{"key":"e_1_2_1_21_1","volume-title":"Using and managing multiple passwords: A week to a view. Interacting with computers 23, 3","author":"Grawemeyer Beate","year":"2011","unstructured":"Beate Grawemeyer and Hilary Johnson. 2011. Using and managing multiple passwords: A week to a view. Interacting with computers 23, 3 (2011), 256--267."},{"key":"e_1_2_1_22_1","unstructured":"Kristen Greene Joshua M Franklin and John M Kelsey. 2015. Tap on tap off: onscreen keyboards and mobile password entry. (2015)."},{"key":"e_1_2_1_23_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07620-1_15"},{"key":"e_1_2_1_24_1","doi-asserted-by":"publisher","DOI":"10.1145\/2435349.2435373"},{"key":"e_1_2_1_25_1","volume-title":"10th symposium on usable privacy and security (SOUPS","author":"Harbach Marian","year":"2014","unstructured":"Marian Harbach, Emanuel Von Zezschwitz, Andreas Fichtner, Alexander De Luca, and Matthew Smith. 2014. {It's} a hard lock life: A field study of smartphone ({Un) Locking} behavior and risk perception. In 10th symposium on usable privacy and security (SOUPS 2014). 213--230."},{"key":"e_1_2_1_26_1","doi-asserted-by":"publisher","DOI":"10.1145\/1978942.1979326"},{"key":"e_1_2_1_27_1","doi-asserted-by":"publisher","DOI":"10.1145\/2638728.2641697"},{"key":"e_1_2_1_28_1","doi-asserted-by":"publisher","DOI":"10.4135\/9781848607941.n13"},{"key":"e_1_2_1_29_1","doi-asserted-by":"publisher","DOI":"10.1145\/1028014.1028031"},{"key":"e_1_2_1_30_1","volume-title":"Proc. IEEE MoST","author":"Jakobsson Markus","year":"2012","unstructured":"Markus Jakobsson and Ruj Akavipat. 2012. Rethinking passwords to adapt to constrained keyboards. Proc. IEEE MoST (2012), 1--11."},{"key":"e_1_2_1_31_1","volume-title":"HAISA 2021, Virtual Event, July 7-9, 2021, Proceedings 15","author":"Jones John M","year":"2021","unstructured":"John M Jones, Reyhan Duezguen, Peter Mayer, Melanie Volkamer, and Sanchari Das. 2021. A literature review on virtual reality authentication. In Human Aspects of Information Security and Assurance: 15th IFIP WG 11.12 International Symposium, HAISA 2021, Virtual Event, July 7-9, 2021, Proceedings 15. Springer, 189--198."},{"key":"e_1_2_1_32_1","doi-asserted-by":"publisher","DOI":"10.1145\/302979.303160"},{"key":"e_1_2_1_33_1","doi-asserted-by":"publisher","DOI":"10.1145\/2851581.2892314"},{"key":"e_1_2_1_34_1","doi-asserted-by":"publisher","DOI":"10.1145\/1268517.1268536"},{"key":"e_1_2_1_35_1","volume-title":"Security of virtual reality authentication methods in metaverse: An overview. arXiv preprint arXiv:2209.06447","author":"K\u00fcrt\u00fcnl\u00fco\u011flu P\u0131nar","year":"2022","unstructured":"P\u0131nar K\u00fcrt\u00fcnl\u00fco\u011flu, Beste Akdik, and Enis Karaarslan. 2022. Security of virtual reality authentication methods in metaverse: An overview. arXiv preprint arXiv:2209.06447 (2022)."},{"key":"e_1_2_1_36_1","doi-asserted-by":"publisher","DOI":"10.1145\/1518701.1518750"},{"key":"e_1_2_1_37_1","doi-asserted-by":"publisher","DOI":"10.1109\/CAIDCD.2010.5681262"},{"key":"e_1_2_1_38_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-28166-7_22"},{"key":"e_1_2_1_39_1","volume-title":"Proceedings of the 28th USENIX Security Symposium. USENIX.","author":"Lyastani Sanam Ghorbani","year":"2018","unstructured":"Sanam Ghorbani Lyastani, Michael Schilling, Sascha Fahl, Michael Backes, and Sven Bugiel. 2018. Better managed than memorized? Studying the impact of managers on password strength and reuse. In Proceedings of the 28th USENIX Security Symposium. USENIX."},{"key":"e_1_2_1_40_1","doi-asserted-by":"publisher","DOI":"10.1207\/S15327051HCI172&3_2"},{"key":"e_1_2_1_41_1","volume-title":"Twelfth symposium on usable privacy and security (SOUPS","author":"Mare Shrirang","year":"2016","unstructured":"Shrirang Mare, Mary Baker, and Jeremy Gummeson. 2016. A study of authentication in daily life. In Twelfth symposium on usable privacy and security (SOUPS 2016). 189--206."},{"key":"e_1_2_1_42_1","doi-asserted-by":"publisher","DOI":"10.1145\/3334480.3382827"},{"key":"e_1_2_1_43_1","doi-asserted-by":"publisher","DOI":"10.1145\/1502800.1502802"},{"key":"e_1_2_1_44_1","doi-asserted-by":"publisher","DOI":"10.1145\/2858036.2858384"},{"key":"e_1_2_1_45_1","volume-title":"Twentieth Symposium on Usable Privacy and Security (SOUPS","author":"Moh Phoebe","year":"2024","unstructured":"Phoebe Moh, Andrew Yang, Nathan Malkin, and Michelle L Mazurek. 2024. Understanding how people share passwords. In Twentieth Symposium on Usable Privacy and Security (SOUPS 2024). 219--237."},{"key":"e_1_2_1_46_1","volume-title":"AISC","volume":"9","author":"Notoatmodjo Gilbert","year":"2009","unstructured":"Gilbert Notoatmodjo and Clark D Thomborson. 2009. Passwords and Perceptions.. In AISC, Vol. 9. Citeseer, 71--78."},{"key":"e_1_2_1_47_1","volume-title":"Proceedings of the 30th USENIX Security Symposium. USENIX.","author":"Oesch Sean","year":"2020","unstructured":"Sean Oesch and Scott Ruoti. 2020. That was then, this is now: a security evaluation of password generation, storage, and autofill in browser-based password managers. In Proceedings of the 30th USENIX Security Symposium. USENIX."},{"key":"e_1_2_1_48_1","doi-asserted-by":"publisher","DOI":"10.1145\/3491102.3517534"},{"key":"e_1_2_1_49_1","volume-title":"Typing speed: How fast is average: 4,000 typing scores statistically analyzed and interpreted","author":"Ostrach Teresia R","year":"1997","unstructured":"Teresia R Ostrach. 1997. Typing speed: How fast is average: 4,000 typing scores statistically analyzed and interpreted. Orlando, FL: Five Star Staffing (1997), 46."},{"key":"e_1_2_1_50_1","doi-asserted-by":"publisher","DOI":"10.1145\/3133956.3133973"},{"key":"e_1_2_1_51_1","volume-title":"Proceedings of the 15th Symposium On Usable Privacy and Security. USENIX.","author":"Pearman Sarah","year":"2019","unstructured":"Sarah Pearman, Shikun Aerin Zhang, Lujo Bauer, Nicolas Christin, and Lorrie Faith Cranor. 2019. Why people don't use password managers effectively. In Proceedings of the 15th Symposium On Usable Privacy and Security. USENIX."},{"volume-title":"Proceedings of the 30th USENIX Security Symposium. USENIX. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/ray","author":"Ray Hirak","key":"e_1_2_1_52_1","unstructured":"Hirak Ray, Flynn Wolf, Ravi Kuber, and Adam J. Aviv. 2021. Why older adults (don't) use password managers. In Proceedings of the 30th USENIX Security Symposium. USENIX. https:\/\/2.zoppoz.workers.dev:443\/https\/www.usenix.org\/conference\/usenixsecurity21\/presentation\/ray"},{"key":"e_1_2_1_53_1","volume-title":"Password security: What users know and what they actually do. Usability News","author":"Riley Shannon","year":"2006","unstructured":"Shannon Riley. 2006. Password security: What users know and what they actually do. Usability News (2006)."},{"key":"e_1_2_1_54_1","doi-asserted-by":"publisher","DOI":"10.1145\/2984511.2984580"},{"key":"e_1_2_1_55_1","doi-asserted-by":"publisher","DOI":"10.1007\/978-3-319-07308-8_23"},{"key":"e_1_2_1_56_1","volume-title":"Statistics: Cybersecurity Data Breaches on the Rise. https:\/\/2.zoppoz.workers.dev:443\/https\/securityscorecard.com\/blog\/cybersecurity-data-breaches-statistics-on-the-rise. Accessed: 2019-02-22.","author":"Scorecard Security","year":"2018","unstructured":"Security Scorecard. 2018. Statistics: Cybersecurity Data Breaches on the Rise. https:\/\/2.zoppoz.workers.dev:443\/https\/securityscorecard.com\/blog\/cybersecurity-data-breaches-statistics-on-the-rise. Accessed: 2019-02-22."},{"key":"e_1_2_1_57_1","doi-asserted-by":"publisher","DOI":"10.1145\/3319535.3354192"},{"key":"e_1_2_1_58_1","doi-asserted-by":"publisher","DOI":"10.1145\/1837110.1837113"},{"key":"e_1_2_1_59_1","doi-asserted-by":"publisher","DOI":"10.1145\/3485832.3485889"},{"key":"e_1_2_1_60_1","doi-asserted-by":"publisher","DOI":"10.5120\/10782-5764"},{"key":"e_1_2_1_61_1","doi-asserted-by":"publisher","DOI":"10.6028\/NIST.IR.7983"},{"key":"e_1_2_1_62_1","doi-asserted-by":"publisher","DOI":"10.1145\/3183341"},{"volume-title":"Basics of qualitative research","author":"Strauss Anselm","key":"e_1_2_1_63_1","unstructured":"Anselm Strauss and Juliet Corbin. 1990. Basics of qualitative research. Sage publications."},{"volume-title":"Grounded theory in practice","author":"Strauss Anselm","key":"e_1_2_1_64_1","unstructured":"Anselm Strauss and Juliet M Corbin. 1997. Grounded theory in practice. Sage."},{"key":"e_1_2_1_65_1","doi-asserted-by":"publisher","DOI":"10.1080\/01449290903121386"},{"key":"e_1_2_1_66_1","volume-title":"Eighteenth symposium on usable privacy and security (SOUPS","author":"Tang Jenny","year":"2022","unstructured":"Jenny Tang, Eleanor Birrell, and Ada Lerner. 2022. Replication: How well do my results generalize now? The external validity of online privacy and security surveys. In Eighteenth symposium on usable privacy and security (SOUPS 2022). 367--385."},{"volume-title":"Typing Speed: How to Set Your Words-Per-Minute (WPM) Goal. https:\/\/2.zoppoz.workers.dev:443\/https\/www.typing.com\/blog\/typing-speed\/. Accessed: 2023-05-04.","year":"2022","key":"e_1_2_1_67_1","unstructured":"typing.com. 2022. Typing Speed: How to Set Your Words-Per-Minute (WPM) Goal. https:\/\/2.zoppoz.workers.dev:443\/https\/www.typing.com\/blog\/typing-speed\/. Accessed: 2023-05-04."},{"key":"e_1_2_1_68_1","unstructured":"Verizon. 2021. Data breach investigations report. https:\/\/2.zoppoz.workers.dev:443\/https\/www.verizon.com\/business\/resources\/reports\/dbir\/. Accessed: 2021-07-18."},{"key":"e_1_2_1_69_1","doi-asserted-by":"publisher","DOI":"10.1145\/2639189.2639218"},{"key":"e_1_2_1_70_1","doi-asserted-by":"publisher","DOI":"10.1093\/cybsec\/tyab012"},{"key":"e_1_2_1_71_1","volume-title":"Twelfth Symposium on Usable Privacy and Security (SOUPS","author":"Wash Rick","year":"2016","unstructured":"Rick Wash, Emilee Rader, Ruthie Berman, and Zac Wellmer. 2016. Understanding password choices: How frequently entered passwords are re-used across websites. In Twelfth Symposium on Usable Privacy and Security (SOUPS 2016). 175--188."},{"key":"e_1_2_1_72_1","doi-asserted-by":"publisher","DOI":"10.1145\/1866307.1866327"},{"key":"e_1_2_1_73_1","doi-asserted-by":"publisher","DOI":"10.1145\/1124772.1124844"},{"key":"e_1_2_1_74_1","doi-asserted-by":"crossref","unstructured":"Jacob O Wobbrock Brad A Myers and Htet Htet Aung. 2004. Writing with a joystick: A comparison of date stamp selection keyboard and EdgeWrite. (2004).","DOI":"10.1145\/985921.986126"},{"key":"e_1_2_1_75_1","doi-asserted-by":"publisher","DOI":"10.1145\/964696.964703"},{"key":"e_1_2_1_76_1","volume-title":"The LASER Workshop: Learning from Authoritative Security Experiment Results (LASER","author":"Yang Yulong","year":"2014","unstructured":"Yulong Yang, Janne Lindqvist, and Antti Oulasvirta. 2014. Text entry method affects password security. In The LASER Workshop: Learning from Authoritative Security Experiment Results (LASER 2014)."},{"key":"e_1_2_1_77_1","doi-asserted-by":"publisher","DOI":"10.1109\/APCCAS.2016.7804002"}],"container-title":["Proceedings of the ACM on Interactive, Mobile, Wearable and Ubiquitous Technologies"],"original-title":[],"language":"en","link":[{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3749491","content-type":"application\/pdf","content-version":"vor","intended-application":"syndication"},{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/pdf\/10.1145\/3749491","content-type":"unspecified","content-version":"vor","intended-application":"similarity-checking"}],"deposited":{"date-parts":[[2025,9,25]],"date-time":"2025-09-25T16:29:33Z","timestamp":1758817773000},"score":1,"resource":{"primary":{"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/dl.acm.org\/doi\/10.1145\/3749491"}},"subtitle":[],"short-title":[],"issued":{"date-parts":[[2025,9,3]]},"references-count":77,"journal-issue":{"issue":"3","published-print":{"date-parts":[[2025,9,3]]}},"alternative-id":["10.1145\/3749491"],"URL":"https:\/\/2.zoppoz.workers.dev:443\/https\/doi.org\/10.1145\/3749491","relation":{},"ISSN":["2474-9567"],"issn-type":[{"type":"electronic","value":"2474-9567"}],"subject":[],"published":{"date-parts":[[2025,9,3]]},"assertion":[{"value":"2025-09-03","order":3,"name":"published","label":"Published","group":{"name":"publication_history","label":"Publication History"}}]}}