arXiv · 2511.10111
An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites
Abstract
Password updates are a critical part of the password lifecycle and are recommended following exposure of reused passwords or suspected compromise. However, password update processes are often cumbersome, require manual password creation, and involve inconsistent website workflows that hinder reliable automation by password managers. In this work, we conduct the first in-depth, systematic analysis of 111 password update processes deployed on top-ranked websites. We provide novel insights into their overall security, usability, and automation capabilities, and contribute to authentication security research by improving the understanding of password update processes. Websites often deploy highly diverse, complex, and confusing password update processes that are not supported by password managers. Processes are often challenging to use, and end-users struggle to transfer experience and knowledge across websites. Notably, security measures designed to enhance security often hinder password manager automation. We conclude our work by discussing our findings and giving recommendations for web developers, the web standardization community, and security researchers.
Explore related subjects
Keep this discovery
Explore connections, maps & timelines
Alexander Krause, Jacques Suray, Lea Schmüser, Marten Oltrogge, Oliver Wiese, Maximilian Golla, Sascha Fahl. 2025-11-13. An Analysis of the Security, Usability, and Automation Capabilities of Password Update Processes on Top-Ranked Websites. https://arxiv.org/abs/2511.10111
Cite the original work for its findings. Save a collection to share your selection of sources.