Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen
techcrunch.com
techcrunch.com
I could understand the aversion to passwords if people had to remember a pile of them, but they don't. You only need to memorize one: the password to unlock your personal system. Can people really not remember one secure password?
Answer: No - and then you're asking to get fully compromised when the (good and secure!) password gets revealed from some service somewhere not following best practices.
Unfortunately, I can't find the research and sample that I remember reading about a while back--Google is spammed with Windows 8 stuff when I search for it and I'm terminally lazy. However, I definitely recall reading about research in this vein.
Like it or not, I like the innovation. The best would be if you had a choice of lock screens and one chooses the style you like.
As several comments suggested, we also considered shrinking the size of the image and displaying it at random positions and slight rotations on the screen to minimize any risk from smudges. We knew from usability feedback that decreasing the size of the image both increased the difficulty of properly entering the gesture and made the login experience feel less immersive; however, if there were a significant improvement to security, we wanted to consider the costs and benefits. What we discovered was that while shifting the image could reduce the buildup of smudges in specific spots, there were even more prominent “clouds” of taps, lines and circles that were identical relative to each other. With this information, an attacker could easily figure out the gestures relative to each other. With that information, it was a simple exercise to move them around the picture until they appeared to coincide with significant elements of the picture. There wasn’t a noticeable improvement in security and we were able to measure significant degradations to the fast and fluid user experience. In reality, using smudges is very difficult.
I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.
Anyway, this is already the case – fingerprints are used as evidence of criminal liability. If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
At the end of the day a finger or an iris is a physical object you can make. Since it's impossible to keep the "key" secret, you can always copy it and make one - how hard you have to work to make it depends on how good the design is, but fundamentally there is no secret and without a secret it's useless for authentication.
> If someone forges my fingerprints, they could get me into a huge amount of trouble, in theory.
Yes, they can, and sometimes they do. But it's not common enough for police to worry about it.
But with biometrics there are no guesses - you know exactly what it should look like. There is difficulty in implementation certainly, but a basic principle of security is that each increment of difficulty in the securer (like a longer password) should increase the difficulty of the attacker by an order of magnitude.
Biometrics does not have this properly.
Fingerprint or iris recognition would require additional hardware. Most of the customer probably would not be willing to pay extra for these. Also they might be difficult to implement well on mobile device. And the unlocking must be very easy to use and reliable.
Japan has had fingerprint scanners on phones for a while. E.g. http://www.nfcrumors.com/11-15-2011/fujitsu-launches-nfc-pho...
Would be a great feature to have on my iPhone.
At least in Apple's case, perhaps the problem is the added cost of the scanner combined with Apple's one-size-fits-all model (as opposed to offering different models, so fingerprint scanners only for those who need the extra security and don't mind the added cost).
There are three types: What you know, what you have, and what you are.
What you know is the most secure in theory, but suffers from the limitation on human memory. But it can not be stolen from someone without them knowing. (Yes I know it can be stolen from a device, but that a problem in implementation and not fundamental.)
What you have is very secure - except that it's possible for it to be lost or stolen, and possibly without the person even realizing (at least not at first).
What you are is the least secure - all the detected features can be copied remotely without the person even knowing that someone copied them, and can not be changed once copied.
Biometrics sounds very secure - but is actually very very insecure.
Isn't the fact that scanned fingerprints are still used by immigration control and criminal investigators evidence against this?
Lets also say that you somehow become aware of them having a copy of your fingerprints and you remember that your phone requires your fingerprints to unlock; what do you do?
It's the fact that you can't permanently change your fingerprints nor restrict access to them which make them bad for authentication. Those two qualities also make them good for forensics.
Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.
Yes, it's pretty easy. However the immigration officer might notice.
> Anyway, if copying fingerprints is possible, then they are useless for forensics, contrary to your final point.
Well, it is possible to copy them, and they are not useless, therefor your conclusion has an error. And that error is that forensics does not require certainty, they require evidence. Evidence is probabilistic, and accumulating various forms of it can eventually be convincing, but each piece on its own is insufficient.
Not at all - they use it for identification not authentication.
It's a completely different application.
The next difference is that for authentication it's important to be able to change the password (as it were), and with biometrics that's impossible. Once copied an attacker has access forever.
But I do see your point, and there are a lot of things in common. But going back to your earlier post, just because immigration control does it that way doesn't mean it's best - it just means they don't have a better way.
I don't have a smartphone so I don't know how it works, but it seems from what I've seen that modern cellphones prevent people from using them for emergency calls unless they know the swipe/unlock code. Is that correct?
edit: just googled, looks like android and iphone have an 'emergency call' button on the lock screen. Fair enough.
What we've got isn't working.
http://blogs.msdn.com/b/b8/archive/2011/12/16/signing-in-wit...
The important thing is that this feature is completely optional and can be disabled in organizations by group policy.
I read the title and instantly though how cool it would be to do exactly what the article described.
I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances.
The simple lock (just to prevent pocket-dialing) should be like a slider. The intermediate lock could be this drag pattern thing (which is just a friendly version of the Android drag lock). The strong lock could be a coded sequence with buttons that change location.