Fourteen Years of Service
Posts: 1,539
Threads: 143
RE: PixelPin - A new way of logging in (NO PASSWORD) 10-26-2017, 11:38 AM
#2
It is decent until the Russians or Asians start using projectors to put your face on the wall and stealing or shit loo...
I do like give phrase log ins. Like how wikr has the feature to take a user to provide voice sample for verification.
•
Fourteen Years of Service
Posts: 74,287
Threads: 317
RE: PixelPin - A new way of logging in (NO PASSWORD) 10-26-2017, 02:03 PM
#4
The technology has been around for a while- since the release of Windows 8. It's also Included In Windows 10 appropriately named "Picture Password".
You basically select 3 gestures on a given Image, and that's what's used when logging In. It's not as secure as many users may think and can be cracked based on "predictability". For example If the Image Is a face (any face, cartoon or otherwise), a commonality for users Is to select the eyes and mouth (or eyes and nose and so forth) as their 3 coordinates. As such, It's pretty simple to predict.
The same can be said for a flower. If It has a few leaves attached to the stem, the coordinates may well be one on the stem and the remaining two on random leaves. And so on.
•
Ten Years of Service
Posts: 670
Threads: 35
RE: PixelPin - A new way of logging in (NO PASSWORD) 10-26-2017, 05:41 PM
#7
Similar logging way already exist in Blackberry phones for years which is called `Picture Password`
•
Twelve Years of Service
Posts: 108
Threads: 5
RE: PixelPin - A new way of logging in (NO PASSWORD) 10-26-2017, 06:26 PM
#8
Seems as if it would be easier for many people than text passwords. The average person has a far easier time remembering small amounts of visual data than strings of text or numbers. That said (and I see this has been discussed in the thread) I question how secure this can be.
It seems that if you can only choose up to 4 gestures on the image, there are fewer combinations to attempt in a brute-force attempt than with a text password (depending on the length and complexity of the password of course). And to top that off, considering that selecting points on the image is not going to be pixel-perfect, you have some leeway in nailing the correct password in a brute-force attempt. Of course, throwing different gestures in such as swipes across regions of pixels and perhaps double taps would mostly solve brute-forcing as it makes any attempt exponentially more difficult.
I suppose, as discussed above, it really does come down to how obvious a user makes their password. Just like how text passwords sometimes are easy cracks using pattern matching against a wordlist, all it would take would be someone taking a photo of their loved one and tapping each eye twice.
One of these image-based passwords could potentially be just as strong as a text password if the image were sufficiently abstract and if a variety of gestures were used. But at that point, we start to lose the value of easy memorization image-based passwords can give us. I like the idea. I just wonder if it's worth it to use over text passwords. I imagine it is a personal preference thing.
•
Eight Years of Service
Posts: 74
Threads: 9
RE: PixelPin - A new way of logging in (NO PASSWORD) 10-27-2017, 02:10 PM
#10
This sounds like a great idea, but I myself wouldn't use it.
I feel like trying to log into multiple devices will require me to have that same picture on multiple devices instead of just simply remembering a password
I wonder how the "forgot password" function will work
(This post was last modified: 10-27-2017, 02:14 PM by Oblivious.)
•