IELTS Reading · Summary Completion

The Science of Password Memorability

Read the passage and the 8 Summary Completion questions below. To attempt the drill, log in free: it opens in the BandLadder test player with instant scoring.
  • 8 questions
  • 778 words
  • About 10 minutes
  • Free account

Reading passage

The Science of Password Memorability

Skip to the questions ↓

Modern digital security remains largely reliant on text-based strings chosen directly by individual users. When the concept of personal authentication first emerged in early networked computing, early theorists assumed that users would treat security codes with strict computational rigor. However, the cognitive architecture of the human brain is fundamentally ill-suited to the demands of contemporary cryptographic protocols. While automated systems can effortlessly generate and store long sequences of mathematically random characters, human memory relies on meaning, associative links, and narrative structure. Under everyday conditions, people simply cannot retain dozens of arbitrary permutations. Consequently, the intersection between technological security requirements and human psychology has produced a persistent vulnerability across global networks, as individuals continuously seek convenient strategies to reduce their cognitive load when accessing digital accounts.

When left to their own devices, individuals exhibit predictable biases during the creation process. Rather than selecting truly arbitrary characters, people habitually draw upon structured heuristics to formulate credentials. Longitudinal studies of compromised credential databases demonstrate that a substantial majority of users rely on familiar biographical anchors, such as personal names, memorable calendar dates, or domestic pets. When organizational policies enforce the inclusion of special symbols and numbers, users rarely distribute these elements evenly across the string. Instead, they adhere to predictable spatial conventions, almost invariably placing capital letters at the very beginning and numerical sequences or punctuation at the extreme end. Furthermore, many employ spatial patterns across the physical keyboard, tracing geometric shapes or straight lines, a phenomenon known to security analysts as keyboard walking. These systematic habits mean that credentials which appear complex to the user actually possess very low computational randomness.

In an effort to mitigate these predictable choices, network administrators historically instituted mandatory expiration rules, forcing users to generate new credentials at regular intervals, often every sixty to ninety days. However, empirical investigations have revealed that these policies frequently backfire, actively degrading system security rather than enhancing it. When compelled to alter credentials frequently, individuals rarely devise fundamentally new strings. Instead, they apply minor adjustments to their existing formulations, such as incrementing an existing number, altering a single vowel, or cycling through the names of the seasons. Security researchers refer to these predictable modifications as transformations, and automated cracking software can anticipate such iterations with remarkable efficiency. As a result, forced rotation often yields credentials that are more vulnerable than those they replaced, while significantly increasing user frustration and support costs.

To circumvent the limitations of textual recall, cognitive scientists and engineers have investigated visual alternatives, commonly referred to as graphical passwords. These systems leverage the human capacity for spatial memory and visual recognition, which is evolutionarily older and often more robust than the ability to recall abstract textual sequences. In a typical recognition-based system, users are presented with a grid of images and must identify a specific subset that was previously assigned to them. In cued-recall systems, individuals might be asked to touch specific coordinates on a chosen photograph in a designated order. Laboratory trials indicate that users can remember complex visual patterns over extended periods with significantly lower error rates than text strings. However, graphical approaches introduce novel vulnerabilities, including shoulder surfing, where an onlooker observes the selection, and the physical smudges left on touchscreen displays.

Another promising compromise between computational entropy and human recall involves the use of multi-word passphrases. Instead of a short, convoluted sequence of symbols, users combine four or five unrelated words chosen at random from a dictionary. Because the total character length of such phrases is substantial, they offer formidable resistance to brute-force attacks, where automated programs attempt every possible combination. At the same time, because each component is a real lexical item, the sequence is vastly easier for the human brain to encode and retrieve. Retention is further improved when the selected terms possess high mental imagery, allowing the user to construct a vivid mental picture or narrative that links the disparate concepts together. Experimental evidence suggests that passphrases constructed via these associative techniques can remain accessible in long-term memory for months without regular reinforcement.

Ultimately, the ongoing struggle with authentication highlights a fundamental design flaw: expecting human beings to behave like cryptographic databases. Recent shifts in technological standards advocate moving the burden of authentication away from human memory entirely. Automated credential managers, which generate and store mathematically robust strings behind a single master key, represent one practical mitigation. Simultaneously, modern computing ecosystems are increasingly adopting hardware tokens and asymmetric cryptography, eliminating the transmission and storage of shared secrets altogether. By aligning system expectations with human cognitive realities, software designers are gradually replacing the fragile memorisation model with architectures that provide robust protection without imposing unmanageable mental demands on everyday users.

Questions 1–8

Complete the summary below. Choose NO MORE THAN TWO WORDS AND/OR A NUMBER from the passage for each answer.

Word limit: NO MORE THAN TWO WORDS AND/OR A NUMBER

User Patterns and Alternative Authentication

When creating credentials without assistance, users rely on 1 rather than picking random characters. Analysis of compromised data indicates a strong tendency to use 2 like names or dates. Furthermore, people often trace linear or geometrical routes across keyboards in an action known as 3. To counter poor user choices, administrators introduced regular 4, yet studies demonstrate this practice actually weakens security. Instead of inventing new codes, users usually execute simple 5 on their existing phrases.

To address memory difficulties, researchers have developed 6 that utilise the human ability for image identification and 7. However, these visual mechanisms are susceptible to threats such as 8, in which bystanders watch what is being entered.

Ready to answer these 8 questions?

Log in to attempt this drill in the BandLadder test player, with instant scoring when you finish.

Ready for a full Reading test?

Three passages, 40 questions of every type and 60 minutes on the clock, with your band score the moment you finish. Your free account also gets AI-scored Writing and Speaking.

Take a full timed test free →

Keep practising

More Summary Completion drills

Get your band, not just a score

  • ✓Full timed Reading and Listening tests
  • ✓AI-scored Writing with band feedback
  • ✓AI-scored Speaking with an AI examiner
Take a full timed test free

Free account · no card

© 2026 BandLadder. Written and checked by the BandLadder team. You may quote or cite this page with credit to BandLadder and a link to it; republishing it in full needs our written permission. Content use policy

Log in to attempt — free