IPB
X   Site Message
(Message will auto close in 2 seconds)

Welcome Guest ( Log In | Register )

 
Reply to this topicStart new topic
> [RL] Icon-based Passwording System, I'm SO using this as a setting detail.
RunnerPaul
post Jan 19 2006, 04:34 AM
Post #1


Neophyte Runner
*****

Group: Members
Posts: 2,086
Joined: 26-February 02
Member No.: 364



I came across the following link that describes GUI-based passwording systems:
http://blogs.zdnet.com/emergingtech/?p=137

In particular, the second system described by the article, which involves a field of randomly chosen shifting icons, really caught my attention. The system has a large library of icons, and the user picks a small handful to be password icons. The twist is, you never actually have to click one of your password icons on the login GUI, which keeps the password secret.

The logon screen consists of a grid of randomly chosen icons, with four of your password icons distributed somewhere on the grid. You locate the icons, and visualize that they're at the corners of an imaginary shape. You click inside that shape, and then the system randomly arranges the icons again. You then repeat the process, figuring out which four icons are from their set of password icons, and clicking inside the borders of the new invisible shape.

After a set number of clicks in the correct areas, the system can determine with a reasonable level of confidence that you actually know which icons are password icons and aren't just hitting the imaginary shapes by random chance. However, someone watching your clicks has no easy way of determining which icons actually make up the corners of your shapes. Depending on the size of the icon library, and the size of grid used for login, it's possible that if someone shoulder surfed a huge number of logins, pattern analysis would eventually pick out out the password icons, but it would not be an easy task.

Anyway, I figure a visually oriented, yet shoulder-surfing resistant password entry system is a perfect fit for the SR setting, especially with how widespread AR overlay is.
Go to the top of the page
 
+Quote Post
FrankTrollman
post Jan 19 2006, 05:58 AM
Post #2


Prime Runner
*******

Group: Banned
Posts: 3,732
Joined: 1-September 05
From: Prague, Czech Republic
Member No.: 7,665



That is indeed really cool. And of course the way to hack it is to set up a series of "logins" that are plausibly masked as passing irrelevent traffic that submit no password attempt at all. With enough of them logged, you could check to see which icons are always there and your first "deliberate" login would be correct all the way through.

-Frank
Go to the top of the page
 
+Quote Post
BishopMcQ
post Jan 19 2006, 06:11 AM
Post #3


The back-up plan
**********

Group: Retired Admins
Posts: 8,423
Joined: 15-January 03
From: San Diego
Member No.: 3,910



Anyone seen Johnny Mnemonic recently?
Go to the top of the page
 
+Quote Post
Crusher Bob
post Jan 19 2006, 06:24 AM
Post #4


Runner
******

Group: Members
Posts: 2,598
Joined: 15-March 03
From: Hong Kong
Member No.: 4,253



Well, you can increase the security there by having the user choose, say, 6 valid icons, but only ever having 4 of the valid icons appear on the login attempts. Also, if you have a semi-smart 'other icon chooser', to make sure that some non-password icons always appear as well that would probably defeat all attempts at frequency analysis.

This would also appear to give you high resistance to the more 'extreme' froms of shoulder surinf, like key-logging and Van Eck phreaking.
Go to the top of the page
 
+Quote Post
RunnerPaul
post Jan 19 2006, 07:02 AM
Post #5


Neophyte Runner
*****

Group: Members
Posts: 2,086
Joined: 26-February 02
Member No.: 364



BTW, one of the links in the article lets you download a demo program that shows it off. It's worth the download to see the thing in action live.

Crusher Bob's right, just because it uses 4 icons at a time to define the imaginary shape, doesn't mean you're limited to using 4 icons in your set of password icons. (In fact, the demo program uses 6 icons out of a total library of 125 for it's sample password.)

As for bringing up the password grid multiple times to be able to see what icons always show up, just set a policy in place that a particular account's password grid can only be brought up x number of times without a successful click on the imaginary shape. After that, lock the account down similar to how an alphanumeric-based password system locks down an account after x number of failed password entries.

The neat thing about this system is that while the article presents it as an iconic system, there's nothing locking you into graphic images instead of other distinguishable symbology, like say, using differently colored alphanumeric characters. Your symbols could be the letters D, U, M, P in brown and S, H, O, C, K in electric blue.
Go to the top of the page
 
+Quote Post
Azralon
post Jan 19 2006, 03:57 PM
Post #6


Shooting Target
****

Group: Members
Posts: 1,651
Joined: 23-September 05
From: Marietta, GA
Member No.: 7,773



I like it; good web find, RP.
Go to the top of the page
 
+Quote Post
hobgoblin
post Jan 19 2006, 11:44 PM
Post #7


panda!
**********

Group: Members
Posts: 10,331
Joined: 8-March 02
From: north of central europe
Member No.: 2,242



another interesting thing is that this works in favor of the human brain.
we are preprogramed to locate shapes and similar, but are worse at rembering random rows of letters and numbers.

on the other hand, computers have a bad time with pattern recognition, but can do rapid bruteforce attacks on strings of letters and numbers...
Go to the top of the page
 
+Quote Post

Reply to this topicStart new topic

 



RSS Lo-Fi Version Time is now: 12th April 2022 - 03:36 PM

Topps, Inc has sole ownership of the names, logo, artwork, marks, photographs, sounds, audio, video and/or any proprietary material used in connection with the game Shadowrun. Topps, Inc has granted permission to the Dumpshock Forums to use such names, logos, artwork, marks and/or any proprietary materials for promotional and informational purposes on its website but does not endorse, and is not affiliated with the Dumpshock Forums in any official capacity whatsoever.