| Thread Tools |
9th September 2013, 07:59 | #1 |
[M] Reviewer Join Date: May 2010 Location: Romania
Posts: 148,618
| Microsoft's picture passwords unsafe Microsoft has been touting picture passwords as the next top trend in security, but researchers have discovered that these are not as difficult to crack as the company thinks. Microsoft offered a Picture Gesture Authentication (PGA) system on Windows 8 and many thought it was a wizard idea. But a paper issued to the USENIX Security Conference has proved that some setups are easier to crack than others. The paper, penned by Arizona State University, Delaware State University and GFS Technology researchers with the catchy title "On the Security of Picture Gesture Authentication", said that unique picture password gestures may not be so unique. Using a picture of a person and then three taps as your gestures - with one of them on the eyes - is equivalent of making your text password "password". The researchers also developed an attack framework and attack models which can take out PGA. All you have to do is work out a user's password selection process to crack a considerable portion of collected picture passwords under different settings. One of the problems is that most people choose to upload one of their own photos to setup their picture gesture password, instead of using one that Microsoft provides. Obviously there is a relationship between background pictures and a user's identity, personality or interests with 60.3 percent of them selecting areas on an image where "special objects" are located. http://news.techeye.net/security/mic...sswords-unsafe |
Similar Threads | ||||
Thread | Thread Starter | Forum | Replies | Last Post |
Google's Plans To Do Away With Passwords | Stefan Mileschin | WebNews | 0 | 21st January 2013 08:16 |
Steam Big Picture Available Now | Stefan Mileschin | WebNews | 1 | 4th December 2012 13:30 |
Windows 8 to implement picture passwords | Stefan Mileschin | WebNews | 0 | 20th December 2011 06:31 |
Microsoft, Flight Simulator developer use images to paint misleading picture | jmke | WebNews | 0 | 26th November 2007 18:49 |
Managing Your Passwords Securely | Sidney | WebNews | 0 | 20th November 2007 02:16 |
Enter Passwords Using Only Eye Movements | jmke | WebNews | 0 | 21st August 2007 18:32 |
how unsafe is RAID0 | koensa | General Madness - System Building Advice | 4 | 15th July 2006 11:21 |
Gates: End to passwords in sight | Sidney | WebNews | 0 | 15th February 2006 03:12 |
Microsoft Picture It! Premium 10 | Sidney | WebNews | 0 | 27th September 2004 02:47 |
Thread Tools | |
| |