I would be interested to see the mathematics behind their claim that a picture password is more complex than (what I assume is) a typical android log in password. I would imagine it would be a little more tricky for any malware to capture a password. Capturing and determining which mouse clicks (for the PC case) are significant is considerably more difficult that analysing the output of a keylogger.