![]() |
|
PixelPin - A new way of logging in (NO PASSWORD) - Printable Version +- Sinisterly (https://sinister.li) +-- Forum: General (https://sinister.li/Forum-General) +--- Forum: World News (https://sinister.li/Forum-World-News) +--- Thread: PixelPin - A new way of logging in (NO PASSWORD) (/Thread-PixelPin-A-new-way-of-logging-in-NO-PASSWORD) Pages:
1
2
|
PixelPin - A new way of logging in (NO PASSWORD) - Bish0pQ - 10-26-2017 Hello everyone, This is a pretty interesting concept. Instead of logging in with your password you can login with using a picture. This could potentially replace the ordinary password logins. Anyway, if you want to read up on this or more information you can visit their website by clicking here. What are your opinions about this guys and do you think this will be secure? RE: PixelPin - A new way of logging in (NO PASSWORD) - Slacker - 10-26-2017 It is decent until the Russians or Asians start using projectors to put your face on the wall and stealing or shit loo... I do like give phrase log ins. Like how wikr has the feature to take a user to provide voice sample for verification. RE: PixelPin - A new way of logging in (NO PASSWORD) - Bish0pQ - 10-26-2017 (10-26-2017, 11:38 AM)Slacker Wrote: It is decent until the Russians or Asians start using projectors to put your face on the wall and stealing or shit loo... Keep in mind, this will NOT use an image of your face. You can set it to any image you like, so if you have a private picture which isn't shared anywhere online, you should be pretty safe I think. Yeah voice authentication would be nice as well. RE: PixelPin - A new way of logging in (NO PASSWORD) - mothered - 10-26-2017 The technology has been around for a while- since the release of Windows 8. It's also Included In Windows 10 appropriately named "Picture Password". You basically select 3 gestures on a given Image, and that's what's used when logging In. It's not as secure as many users may think and can be cracked based on "predictability". For example If the Image Is a face (any face, cartoon or otherwise), a commonality for users Is to select the eyes and mouth (or eyes and nose and so forth) as their 3 coordinates. As such, It's pretty simple to predict. The same can be said for a flower. If It has a few leaves attached to the stem, the coordinates may well be one on the stem and the remaining two on random leaves. And so on. RE: PixelPin - A new way of logging in (NO PASSWORD) - Bish0pQ - 10-26-2017 @mothered True, I agree with you 100% BUT the same can be said for text passwords. Based on interests, DOB, name, location... you can easily generate a list of possible passwords. If the user is stupid it used a combination of known data, it's still a weak password, if you would do selecting on the obvious spots of a photo, it would be the same thing basically. If you have a difficult picture without obvious points on it, it might be more secure than a text password based on the user's data. RE: PixelPin - A new way of logging in (NO PASSWORD) - mothered - 10-26-2017 (10-26-2017, 02:20 PM)Bish0pQ Wrote: @mothered True, I agree with you 100% BUT the same can be said for text passwords. Yes, It all comes down to how the end user applies himself/herself when selecting a password (Image or text). Some websites don't help either. They allow the use of commonly-used, sequential, easy to guess passwords and also those based on familiarity and/or personal entities. A password complexity requirement should always be Implemented, thereby "forcing" the user to create a strong password. RE: PixelPin - A new way of logging in (NO PASSWORD) - Altair - 10-26-2017 Similar logging way already exist in Blackberry phones for years which is called `Picture Password` RE: PixelPin - A new way of logging in (NO PASSWORD) - Llebacc - 10-26-2017 Seems as if it would be easier for many people than text passwords. The average person has a far easier time remembering small amounts of visual data than strings of text or numbers. That said (and I see this has been discussed in the thread) I question how secure this can be. It seems that if you can only choose up to 4 gestures on the image, there are fewer combinations to attempt in a brute-force attempt than with a text password (depending on the length and complexity of the password of course). And to top that off, considering that selecting points on the image is not going to be pixel-perfect, you have some leeway in nailing the correct password in a brute-force attempt. Of course, throwing different gestures in such as swipes across regions of pixels and perhaps double taps would mostly solve brute-forcing as it makes any attempt exponentially more difficult. I suppose, as discussed above, it really does come down to how obvious a user makes their password. Just like how text passwords sometimes are easy cracks using pattern matching against a wordlist, all it would take would be someone taking a photo of their loved one and tapping each eye twice. One of these image-based passwords could potentially be just as strong as a text password if the image were sufficiently abstract and if a variety of gestures were used. But at that point, we start to lose the value of easy memorization image-based passwords can give us. I like the idea. I just wonder if it's worth it to use over text passwords. I imagine it is a personal preference thing. RE: PixelPin - A new way of logging in (NO PASSWORD) - mothered - 10-27-2017 (10-26-2017, 06:26 PM)Llebacc Wrote: I like the idea. I just wonder if it's worth it to use over text passwords. I imagine it is a personal preference thing. I certainly agree that It comes down to personal preference. I for one, prefer text passwords simply for It's easy of use when logging Into a given account. The time It took me to type the above paragraph (round figures of 160 bytes), would've been the equivalent of entering 10x 16 char text passwords. Roughly the same amount of time would be taken to match all coordinates (with the probability of failure) and login with "one" picture password. RE: PixelPin - A new way of logging in (NO PASSWORD) - Oblivious - 10-27-2017 This sounds like a great idea, but I myself wouldn't use it. I feel like trying to log into multiple devices will require me to have that same picture on multiple devices instead of just simply remembering a password I wonder how the "forgot password" function will work |