Slashdot Mirror


Tactile Passwords vs Shoulder Surfing

holy_calamity writes "Entering passwords using a tactile interface would remove two of the main vulnerabilities of using keyboards and alphanumeric passwords say UK researchers. They're using sequences of tactile icons on a VTPlayer tactile mouse instead. Shapes are displayed using the 16-pin tactile displays under the user's fore and middle fingers. As well as being almost impossible for anyone else to observe, tactile passwords can't be guessable in the same way as many conventional ones, they say. A video shows it all in action." Not that the video really helps explain it very well.

8 of 115 comments (clear)

  1. special tactile mouse needed .. by rs232 · · Score: 3, Interesting

    You don't need any special tactile mouse. The same could be achieved using a clickable image map showing a keypad with the numbers in random locations. You get a different map each time you enter the site. So keyloggers wouldn't be of any use.

    --
    davecb5620@gmail.com
    1. Re:special tactile mouse needed .. by The+Evil+Couch · · Score: 3, Insightful

      However it would be clearly visible to anyone looking over your shoulder. Even more so that the tradition keyboard password entry.

  2. How could the video explain it? by badfish99 · · Score: 5, Funny

    No wonder that the video does not help to explain it very well. TFA says "it is almost impossible for anyone else to observe"

  3. Shoulder surfing? by AnimeDTA · · Score: 4, Funny

    Being bored at work, I took up using the Dvorak keyboard layout. My passwords however retain the same unconcious keyboard patterns as they did on a standard keyboard. Without even thinking of what my password is I can type it. For a while I didn't even know my own passwords were... this proved to be a problem when i had to check email and wasn't at my computer. But it definately ends the shoulder surfing for passwords.

    I ended up typing my passwords a few times in notepad and memorized the gibberish that is my password now. Other than that I'd have to be trying to know what my fingers are pressing when i go into password mode.

  4. My Solution by thorkyl · · Score: 3, Funny

    Let's just put small DNA testers on each PC.

    Then all you have to do is stick something in the hole to donate a blood sample.

    --
    Stupid people breeding has lead us to the current government

    --
    -- I am the NRA, enough said...
  5. Easier solution by 3Suns · · Score: 3, Interesting

    I've always made sure that my passwords contain a string of easily-typable letters consisting primarily of alternating-hand homerow keys, to complement the numbers, punctuation, and capitalization elsewhere in the password. Since you can tap out those letters so quickly without moving your hands around dramatically, it makes it much more difficult for anyone to eyeball your password.

    I've seen countless stories about dedicated password-entry hardware, but none of them (with the minor example of insecure fingerprint scanners) have made an impression. Purpose-dedicated hardware rarely does.

    --

    -3Suns

    ~~~~
    The Revolution will be Slashdotted
  6. Got rhythm? by bromoseltzer · · Score: 3, Funny

    As a radio amateur (old school, 20 words per minute Morse), I would be very happy to key in my password entirely on the "J" key.

    --
    Fiat Lux.
  7. Re:Impossible? by durnurd · · Score: 3, Insightful

    If you've got Superman trying to steal your password, I think you've got bigger problems than an insecure password.

    --
    --Edward Dassmesser