|
|||||||
![]() |
|
|
Thread Tools |
|
|
#1 |
|
Player Character
bit-tech Staff
Join Date: Apr 2007
Posts: 7,977
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
New format proposes images to replace passwords
http://www.bit-tech.net/news/2007/11...ce_passwords/1
A graffiti-like approach to passwords has been proposed to aid in system security by using unique images as passwords.
__________________
|
|
|
|
|
|
#2 |
|
Trango in the Mango
Join Date: Feb 2005
Location: Cambridge, UK
Posts: 192
![]() |
I can already imagine some hilarious Helpdesk calls involving users drawing certain body parts for passwords.
__________________
[b]Really needs updating! - http://www.kosch.co.uk/ |
|
|
|
|
|
#3 | |
|
Web Developer
Join Date: Jun 2005
Location: West Palm Beach, Florida
Posts: 3,840
![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Quote:
__________________
Current Computer: eVGA 780i Motherboard | Q6600 Core2Quad | eVGA GTX260 896Mbs 216-core | 2x Seagate 500Gbs | 8Gbs OCZ Platinum DDR2 800 | Creative XtremeGamer X-Fi | Thermaltake Armor Case Custom WordPress, ZenCart, Joomla, vBulletin, etc installs and skinning, PM/E-Mail for a quote
|
|
|
|
|
|
|
#4 |
|
Trust the Computer
Join Date: Jan 2004
Location: Bournemouth
Posts: 4,797
![]() |
Sounds viable, if not a bit crazy. Fortunately for me, my laptop remembers my passwords when I type them into a website for a first time and just lets me swipe the fingerprint reader to login on future occasions.
<A88> |
|
|
|
|
|
#5 |
|
Supermodder
Join Date: Apr 2007
Location: NC, USA
Posts: 548
![]() |
ugh, as an it guy, i'd hate to have to explain to new users "you need to draw in a complex password using more than 7 colours, not including your picture and it must have oil, water, pastel, and/or ascii art included"
![]() the other problem is, i can remember the image but i'm no renoir so don't expect me to draw even a similar picture twice which means it'd have to be something relatively simple and that would be hackable using the same brute force tactics as now, ie a picture of mickey mouse, etc.
__________________
Asus P5N32-SLi Extreme, Intel Conroe E6600 @ 2.4GHz, 4GB Corsair XMS2 @ 1060MHz, eVGA GeForce 8800 GTX @ 621MHz, 2 WD 250GB 7200RPM HDD's, Creative Soundblaster Fatal1ty pro |
|
|
|
|
|
#6 |
|
Player Character
bit-tech Staff
Join Date: Apr 2007
Posts: 7,977
![]() ![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Surely: If pictures are easier for the human brain to remember and generate then it's easier for a person to hack and guess? Especially if the picture just has to be CLOSE to similar, not identical?
Also, how complex do they have to be? In order to provide decent protection it would have to have a fair bit of detail in, right? I don't want to be hampered with drawing stuff for 2 or 3 minutes everytime I log on...
__________________
|
|
|
|
|
|
#7 |
|
Web Developer
Join Date: Jun 2005
Location: West Palm Beach, Florida
Posts: 3,840
![]() ![]() ![]() ![]() ![]() ![]() ![]() |
Wouldn't just switching to fingerprint readers be more viable? It's not like they're expensive nowadays..
__________________
Current Computer: eVGA 780i Motherboard | Q6600 Core2Quad | eVGA GTX260 896Mbs 216-core | 2x Seagate 500Gbs | 8Gbs OCZ Platinum DDR2 800 | Creative XtremeGamer X-Fi | Thermaltake Armor Case Custom WordPress, ZenCart, Joomla, vBulletin, etc installs and skinning, PM/E-Mail for a quote
|
|
|
|
|
|
#8 |
|
Supermodder
Join Date: Apr 2007
Location: NC, USA
Posts: 548
![]() |
Biometrics has its good points and bad points like everything else.
Good: Extremely hard to hack, easy to use (not like you're going to forget your finger or eye) Bad: it's a stone cold bitch to change the enrollment when your password changes, administrator/group accounts that are accessed by more than one person would not be able to use biometrics, or then only a max of 10 people (1 for each finger) plus if you have a local admin account on each domain computer for IT guys, you'd have to enroll your finger print on every computer, that'd suck. The current multiple authentication mash up is really where everybody needs to go. Smartcard, strong password, biometrics, RFID, etc. drawings would really only be used as a complement to the other authentication methods, and like CardJoe said, i'd hate to have to draw in my stupid mickey mouse picture for 2-3 minutes just to be able to start work, that'd be a bad thing Monday morning pre-coffee.
__________________
Asus P5N32-SLi Extreme, Intel Conroe E6600 @ 2.4GHz, 4GB Corsair XMS2 @ 1060MHz, eVGA GeForce 8800 GTX @ 621MHz, 2 WD 250GB 7200RPM HDD's, Creative Soundblaster Fatal1ty pro |
|
|
|
|
|
#9 | |
|
Supermodder
Join Date: Mar 2005
Location: Dundee
Posts: 306
![]() |
Quote:
first of all would the whole point of using biometric identification (like fingerprints) not make changing "passwords" unnecessary and if you did.. what are you going to do after they have used all their 10 fingers..(ask them to use toes?). Since biometric identification is so difficult to hack I see no reason why you could not have several "passwords/fingerprints" for one account (that's if you want to limit the number of admin accounts) or all IT admins could have their own account. I guess depending on your network the number of people needing access to a local account will wary, but even then i think the security advantage is worth the slight hassle of getting local accounts set up for admins where needed. Also there is no reason why the biometric data cannot be copied (although it might prove a security problem) so that people can have local accounts set up without the actual user being present.
__________________
If it isn’t broken, fix it. If it is broken, mod it till it looks like it's meant to be broken. |
|
|
|
|
| Dr. Strangelove |
| View Public Profile |
| Find More Posts by Dr. Strangelove |
|
|
#10 | |
|
I'm not a modder.
Join Date: Jan 2007
Location: Bury St Edmunds/Durham Uni
Posts: 1,845
![]() ![]() |
Quote:
__________________
i7 920, 8800GTS 512, 6GB Corsair all in an Intel DX58SO; 3*320GB RAID5; CM Stacker ![]() Samsung Q45. |
|
|
|
|
|
|
#11 | |
|
Supermodder
Join Date: Apr 2007
Location: NC, USA
Posts: 548
![]() |
Quote:
As to the local accounts, say i'm the it admin that set everything up; my finger print is enrolled on all the systems. I die in a car crash/get fired for watching porn. My replacement will not be able to log in with the biometrics, only with the password. he will then need to go to every system and enroll his finger print. This IT guy is in charge of 600 computers, 200 of which are laptops with remote sales guys. It'd be near impossible for him to unenroll me and reenroll his prints I'm not sure if you can copy the biometric data, i'm not sure where the hashed file would be or what else it contains, say it holds the fingerprints for all enrolled users on that computer, you copy that file onto somebody elses computer that already has enrollments and you're either not going to log on or they're not going to be able to...or the software corrupts and you're both screwed ![]() Like I said, it has it's good points and bad points. It's ideal for a sales guy thats the only one using the computer, but it's hard to administer from a domain or enterprise level.
__________________
Asus P5N32-SLi Extreme, Intel Conroe E6600 @ 2.4GHz, 4GB Corsair XMS2 @ 1060MHz, eVGA GeForce 8800 GTX @ 621MHz, 2 WD 250GB 7200RPM HDD's, Creative Soundblaster Fatal1ty pro |
|
|
|
|
|
|
#12 |
|
Multimodder
Join Date: Jun 2003
Location: Yermo, CA, USA
Posts: 174
![]() |
One word for this idea: DUMB
|
|
|
|
|
|
#13 |
|
I also ride trials :¬)
Join Date: Apr 2004
Location: Fallowfield, Manchester
Posts: 2,233
![]() |
I have to say I'm a bit confused. I used to use a scribble to identify myself when I bought things in shops. But apparently that wasn't safe enough so I then had to use a 4-number PIN. And now we're going back to scribbles?
Oh lordy.
__________________
Carrot cake cheesecake Shuttle SN85G4V2 | A64 3200+ / Apple PowerBook 12 |
|
|
|
|
|
#14 | ||||
|
Mod Master
Join Date: Mar 2005
Location: Aberdeen, Scotland
Posts: 2,088
![]() |
I think some people are confused about the exact way some of this works.
AFAIK, biometric fingerprint readers store a hash of your fingerprint data in the reader itself and when software asks for authentication, you swipe the finger and the reader passes the password to the application. The software will still accept a password I think and as such, biometric fingerprint readers are only as strong as the password you use. It just means instead of having to remember a 20char password, you can swipe your finger. I'm not sure if you get corporate versions of this, where you can tie personal info/biometrics to a domain user account and allow that account to access the domain on any machine with a compatible reader. If not, then it pretty much reduces biometrics to a useful way to remember your passwords, in much the same way as your browser might remember your passwords for you. This picture idea however sounds interesting. I can't see a way for hackers to brute-force this method other than have a robotic arm drawing millions of random images. Assuming the algorithms behind the method are robust and not susceptible to cryptanalysis (like WEP for example). And they have refined the method slightly from giving you a blank canvas. They provide a sample image which might be a 3x3 grid of boxes for example. All you need to do is draw a circle in box one, a cross in box 4 and a squiggle in box 8 and I'd assume you'd have a pretty strong password. I don't think you'd need to re-create the mona-lisa just to log into the bit forums... ![]() And if you consider that having the pre-provided image effectively allows you to create passwords (or should that be passpictures? ) much more accurately and with, on average, 10 extra bits, you can start to see the appeal.10 bit is in effect an 18 char password instead of an 8 char one. So several orders of magnitude more secure. I think it'll be interesting to see where this goes. ![]() Quote:
Now ask us to try and guess what the other drew and re-create it without seeing it and I think we'd be there til the end of time. Only problem I can see is if someone saw you drawing your secret, but its no worse than someone watching you enter your password/pin etc now. Quote:
If you think of my example above with the 3x3 grid, you might only need to draw something in three of the boxes to have a strong password/picture thing. Quote:
Also, that method relied on a human comparison to what you wrote to what's on the card. This will rely on a computer alanysis, so even though the pictures will allow some tolerance for differences, it'll still be much more accurate. Pin numbers for security is a joke IMO and I think signatures were probably more secure...
__________________
Laptop:C2D P8600 2.4GHz, 4GB, 9800GTS, 120GB SSD, 15" 1680x1050, Vista64 Projects: 1.2TB Fileserver housed in a cardboard box!|Retro HTPC for my GF. Quote:
Last edited by airchie; 5th Nov 2007 at 17:00. Reason: adding quotes |
||||
|
|
|
|
|
#15 | |||
|
Supermodder
Join Date: Mar 2005
Location: Dundee
Posts: 306
![]() |
Quote:
Quote:
Quote:
![]() as for a network with as many computers as you describe I would certainly hope that there was more than one admin.. or he would be one hell of a busy man. At least for windows networks remote/laptop users still use their network account to log in. Finally I have no idea of whether there is software available that can do what I suggest at the moment, my point is that I don't see why biometric data could not be rolled out as the login method of enterprise sized networks.
__________________
If it isn’t broken, fix it. If it is broken, mod it till it looks like it's meant to be broken. |
|||
|
|
|
| Dr. Strangelove |
| View Public Profile |
| Find More Posts by Dr. Strangelove |
|
|
#16 | |
|
Supermodder
Join Date: Apr 2007
Location: NC, USA
Posts: 548
![]() |
Quote:
As a side note, I was watching Myth busters the other week and they were able to fool a fingerprint reader quite easily, they just got a dotmatrix printer to print out a fingerprint and then read it through the reader, kinda like the movies
__________________
Asus P5N32-SLi Extreme, Intel Conroe E6600 @ 2.4GHz, 4GB Corsair XMS2 @ 1060MHz, eVGA GeForce 8800 GTX @ 621MHz, 2 WD 250GB 7200RPM HDD's, Creative Soundblaster Fatal1ty pro |
|
|
|
|
|
|
#17 |
|
Supermodder
Join Date: Jun 2007
Posts: 315
![]() |
I'd be worried about what happens when the computer crashes and the repair guy can't reproduce the scribble-as-password. One work-around would be to have the owner set up an unpassworded admin account before taking it in, but if it's really messed up he/she may not be able to do that. The other option would be to have the owner come in and physically enter the password at the appropriate point in the repair process - can you say pain in the neck?
It's still an interesting idea, though. Maybe it'd be good for web-based logins. Although if you give people a background image to draw on, I'll bet that 90% will just trace some of the major visible lines, which would be incredibly easy to hack.
__________________
Current status: Modding on
|
|
|
|
|
|
#18 | |
|
Supermodder
Join Date: May 2002
Location: Santo Domingo, Dom. Rep.
Posts: 380
![]() |
Quote:
When it comes to setting up local accounts for admin staff, most companies have an image of how every type of computer they use should be like so they don't have to actually install everything from scratch in case an HDD or similar breaks down. Those images have the admin account already set up with a custom password that was created a the time of creating the image. I guess it would work with biometrics as well. The only problem would be when implementing it for the first time when you would surely have to go to every computer to set it up, but would be a one time thing, unless there was some way to set up the local accounts through the network as a one time thing or something.
__________________
Proud member of WarNet Inc. WarNet Rulez!! |
|
|
|
|
|
|
#19 | ||||
|
Mod Master
Join Date: Mar 2005
Location: Aberdeen, Scotland
Posts: 2,088
![]() |
Quote:
Entering passwords and drawing passpics both require the OS/software/app to be functioning in some way. If it's functioning enough to accept passwords, it's likely be functioning enough to allow the removal of the password for maintenance. If the PC is badly b0rked, it likely won't accept either form of authentication and will need a reinstall etc. But there is a lot of grey areas for scenarios like this... :/ Quote:
Even if you just traced the lines provided, the order they were traced in could also be taken into account. Plus, if that was the person's attitude to security they'd deserve to get hacked. They'd probably have set their password as 'god' or 'sex' anyway... ![]() Quote:
__________________
Laptop:C2D P8600 2.4GHz, 4GB, 9800GTS, 120GB SSD, 15" 1680x1050, Vista64 Projects: 1.2TB Fileserver housed in a cardboard box!|Retro HTPC for my GF. Quote:
|
||||
|
|
|
|
|
#20 |
|
/dev/null
Join Date: Aug 2005
Location: Belgium
Posts: 4,102
![]() ![]() |
If this becomes standard, I for one can never log in after a weekend of partying
__________________
There Are 10 Types Of People, Those Who Know Binary and Those Who Don't |
|
|
|
![]() |
| Thread Tools | |
|
|