Anmelden

Archiv verlassen und diese Seite im Standarddesign anzeigen : [Szene] Future online password could be a map



meckl
21.09.2010, 09:42
Future online password could be a map

Researcher says it would elude hackers' keystroke recording software

http://msnbcmedia3.msn.com/j/MSNBC/Components/Photo/_new/100920-mappassword-hmed-230p.grid-6x2.jpg

NEW YORK — Between super-powered hacker computers and keystroke recording malware, traditional passwords may no longer be secure enough. To overcome these problems, computer scientist Bill Cheswick has devised a new method for logging into secure areas: clicking on a map.

Speaking at the New York Institute of Technology Cyber Security Conference this past Wednesday, Cheswick described how users could memorize the exact spot on a satellite photo (http://www.technewsdaily.com/lasers-used-to-create-3-d-model-of-new-york-city-0548/), with the longitude and latitude serving as the access code. By zooming down through the map to the high level of resolution, users can graphically produce a nearly unbreakable password that neither people nor viruses could track.

“The key idea is that you have a data set with very deep data, and you have to drill down. You could drill down on a map of anything. Probably better if it’s a map of someplace you’ve never been, so you’re not tempted to pick your childhood home,” said Cheswick, a scientists at AT&T research. “You could have a 10 digit latitude, and a 10-digit longitude, then you have a 20-digit password (http://www.technewsdaily.com/how-to-write-the-perfect-password-100128-0118/).”

Computer security protocols that involve clicking on a picture instead of typing a password have existed for 15 years. While clicking on a photo does defeat hacking programs (http://www.technewsdaily.com/the-accidental-spammer-1213/) that use dictionaries to break passwords, specially designed programs have evolved over the last decade that track mouse location specifically to break picture-based passwords.

By using a map with zoom, this new method renders those mouse-tracking programs useless. Sure, the virus will know where the mouse clicks, but unless it knows what map the user is looking at, and how deeply zoomed in they are, the hacking program can’t record the longitude and latitude that serve as the password.

To date, Cheswick has not done any usability studies on this technique, so he’s unsure whether or not it is easy enough for use by the general public. However, with threat of password cracking hackers increasing by the day, convenience of use may have to take a back seat to security.

Quelle: msnbc.msn.com (http://www.msnbc.msn.com/id/39276642/ns/technology_and_science-security/)

wacked
21.09.2010, 17:35
Ich habe jetzt keine ahnung wie genau die Bilder von den google servern geladen werden. Wir tuen mal so als wäre es

http://pictures.maps.google.com/?long1=1234567890&long2=1234567895&lat1=0987654321&lat2=0987654315&zoom=10
Dann müßte man nur diese URL loggen und kann dann mit der größe der karte im fenster und der mausposition längen & breitengrad berechen.

kthxbai

shoei
23.09.2010, 21:15
aha, ich bleib bei den alten passwörtern D:

v0Dka.
23.09.2010, 22:04
dan reicht doch ein screenshot mit dem breiten grad usw.. zoomfaktor schon ist man drinn oder wie ? .. und auserdem für jede seite dann auf ner blöden mappe etwas suchen finde ich doch etwas blöd...

naja ich durchschaue den sinn vielleicht nicht zu 100%..

SFX
23.09.2010, 22:52
der Sinn wäre dass es mehr mögliche Punkt auf der Erde gibt als Kombinationen bei einem standard Passwort mit 6 Zeichen..