Examining User Behavior and Cognitive Biases in Personal Password Security
arxiv.org
Aug. 8, 2026, 7:23 a.m.
This arXiv study examines why users persist in insecure password practices despite heightened cybersecurity awareness. Researchers conducted a survey analyzing password creation, storage, and management habits while investigating behavioral and cognitive factors influencing these decisions. Drawing on behavioral economics concepts including hyperbolic discounting, status quo bias, and present bias, the research reveals that users consistently prioritize immediate convenience over long-term security, favoring memorable passwords over strong ones. Key psychological biases drive security procrastination and resistance to adopting password managers and multi-factor authentication. The findings are particularly timely given the FBI's Internet Crime Complaint Center reported 1,000,597 complaints in 2025 versus 859,532 in 2024, with a 26 percent increase in losses and over 3.6 million dollars in ransomware-related losses. The FBI recommends implementing NIST password standards, eliminating default credentials, and deploying multi-factor authentication alongside non-password-based security controls. This research bridges the critical gap between security awareness and user action, providing practical insights for designing human-centered authentication policies that align with real-world decision-making tendencies.