Live data from Hacker News

Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

techcrunch.com

11–20 of 46 posts

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#11
Sounds like a great way to remember your gesture. But it also sounds like a great way to pick an extremely obvious gesture (e.g. outline of the house) that someone else can guess. If your gesture is based on prominent features in the picture, that greatly limits the search space for an attacker.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#12

I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…

I like that idea especially building it into the operating system. I also want to point out that you should be able to choose the level of unlocking based on your input to the first lock screen. Androids gesture unlock system would actually work pretty well for that

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#13
post #11

Sounds like a great way to remember your gesture. But it also sounds like a great way to pick an extremely obvious gesture (e.g. outline of the house) that someone else can guess. If your gesture is based on prominent features in the picture, that greatly limits the search space for an attacker.

Exactly. This seems even less secure than the Android "lock pattern" mechanism, which at least provides a grid of nine features and no obvious reason to choose any particular set. (Despite that, I suspect many people use the same patterns.) The examples given in the article provide little to no security, while giving a novice user the illusion of security. Ideally, this ought to have gone through extensive practical security testing: what pictures and patterns do users pick, and how easily can others guess those patterns?

I could understand the aversion to passwords if people had to remember a pile of them, but they don't. You only need to memorize one: the password to unlock your personal system. Can people really not remember one secure password?

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#14
post #11

Sounds like a great way to remember your gesture. But it also sounds like a great way to pick an extremely obvious gesture (e.g. outline of the house) that someone else can guess. If your gesture is based on prominent features in the picture, that greatly limits the search space for an attacker.

Exactly. This seems even less secure than the Android "lock pattern" mechanism, which at least provides a grid of nine features and no obvious reason to choose any particular set. (Despite that, I suspect many people use the same patterns.) The examples given in the article provide little to no security, while giving a novice user the illusion of security. Ideally, this ought to have gone through extensive practical…

>Can people really not remember one secure password?

Answer: No - and then you're asking to get fully compromised when the (good and secure!) password gets revealed from some service somewhere not following best practices.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#16

Earlier quoted context omitted.

Exactly. This seems even less secure than the Android "lock pattern" mechanism, which at least provides a grid of nine features and no obvious reason to choose any particular set. (Despite that, I suspect many people use the same patterns.) The examples given in the article provide little to no security, while giving a novice user the illusion of security. Ideally, this ought to have gone through extensive practical…

>Can people really not remember one secure password? Answer: No - and then you're asking to get fully compromised when the (good and secure!) password gets revealed from some service somewhere not following best practices.

No service should ever have your secure password. It should unlock your personal system, which can then remember all the (different, random, and secure) passwords or keys for any other service you use.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#17
post #9

I think one way to mitigate the smudge factor is just to rotate the picture each time. I am willing to bet (despite being totally uninformed :)) that a person will remember where to touch on the picture rather than the screen, so rotating the picture will not make it much more difficult to enter the password.

Or use a random picture from a set which the user has set up with different "passwords".

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#18

Serious question: why aren't we using biometrics, e.g., fingerprints or iris detection? I want authentication that: (1) identifies me, not a key-holder, and (2) requires only things that I will always have with me.

You can't change biometrics, so once someone forges your identity they will always have access to anything that requires only biometric identification.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#19

I find it annoying that we're innovating different ways of doing the exact same thing: switching from completely locked to completely unlocked. I want near-instant access to a notepad for jotting down thoughts. I want more locking for reading existing notes. Still more for accessing email. I want a strong lock protecting apps related to finances. The simple lock (just to prevent pocket-dialing) should be like a slide…

One of my absolute favorite iOS features in iOS5 before I switched to Android was the new "take a photo from the lock screen" button. I felt understood when they added that.

Re: Microsoft’s “Picture Password”: A Breath Of Fresh Air On The Lock Screen

#20
The smudge hack is only relevant if you have a continuous swype on the screen. If you allow lifting your finger and poke several things you have limited this hacks effectiveness, as people may see where you poked but not the order. So "tap your dogs in a certain order" weakens this hack. Also it seems to assume you are doing nothing else n the phone. When I open the phone I generally do something which leaves additional smudges. So someone will not know if they are the password or activity.

Like it or not, I like the innovation. The best would be if you had a choice of lock screens and one chooses the style you like.

Post reply on HN