| Thread Tools |
9th September 2013, 08:59 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 153,575
| Microsoft's picture passwords unsafe Microsoft has been touting picture passwords as the next top trend in security, but researchers have discovered that these are not as difficult to crack as the company thinks. Microsoft offered a Picture Gesture Authentication (PGA) system on Windows 8 and many thought it was a wizard idea. But a paper issued to the USENIX Security Conference has proved that some setups are easier to crack than others. The paper, penned by Arizona State University, Delaware State University and GFS Technology researchers with the catchy title "On the Security of Picture Gesture Authentication", said that unique picture password gestures may not be so unique. Using a picture of a person and then three taps as your gestures - with one of them on the eyes - is equivalent of making your text password "password". The researchers also developed an attack framework and attack models which can take out PGA. All you have to do is work out a user's password selection process to crack a considerable portion of collected picture passwords under different settings. One of the problems is that most people choose to upload one of their own photos to setup their picture gesture password, instead of using one that Microsoft provides. Obviously there is a relationship between background pictures and a user's identity, personality or interests with 60.3 percent of them selecting areas on an image where "special objects" are located. http://news.techeye.net/security/mic...sswords-unsafe |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Google's Plans To Do Away With Passwords | Stefan Mileschin | WebNews | 0 | 21st January 2013 09:16 |
Steam Big Picture Available Now | Stefan Mileschin | WebNews | 1 | 4th December 2012 14:30 |
Windows 8 to implement picture passwords | Stefan Mileschin | WebNews | 0 | 20th December 2011 07:31 |
Microsoft, Flight Simulator developer use images to paint misleading picture | jmke | WebNews | 0 | 26th November 2007 19:49 |
Managing Your Passwords Securely | Sidney | WebNews | 0 | 20th November 2007 03:16 |
Enter Passwords Using Only Eye Movements | jmke | WebNews | 0 | 21st August 2007 19:32 |
how unsafe is RAID0 | koensa | General Madness - System Building Advice | 4 | 15th July 2006 12:21 |
Gates: End to passwords in sight | Sidney | WebNews | 0 | 15th February 2006 04:12 |
Microsoft Picture It! Premium 10 | Sidney | WebNews | 0 | 27th September 2004 03:47 |
Thread Tools | |
| |