Slashdot Mirror


Microsoft Wants To Give You A Rorschach

Preedit writes "Microsoft has set up a website that uses inkblot images to help users create passwords. The site asks users view a series of inkblots and write down the first and last letters of whatever word they associate with each inkblot. Then they combine the letters to form a password. Microsoft claims it's a way to create passwords that are easy to remember but hard to crack. But a word of warning, the story notes that Microsoft is collecting and storing users' word associations."

44 of 223 comments (clear)

  1. Not sure this will help by Qzukk · · Score: 5, Funny

    view a series of inkblots and write down the first and last letters of whatever word they associate with each inkblot. Then they combine the letters to form a password.

    I got vavavapsva.

    More seriously, if they're saving the word associations, doesn't that mean that they have the password you've just generated?

    --
    If I have been able to see further than others, it is because I bought a pair of binoculars.
    1. Re:Not sure this will help by skeevy · · Score: 3, Funny

      vulva vulva vulva penis vulva?

      I'm not sure whether I should be afraid of your mind or the site...

    2. Re:Not sure this will help by BarryJacobsen · · Score: 5, Funny

      vulva vulva vulva penis vulva? I'm not sure whether I should be afraid of your mind or the site... Really? I'm not sure whether I should be afraid of his mind or immediately go to the site...
    3. Re:Not sure this will help by Chapter80 · · Score: 2, Funny

      view a series of inkblots and write down the first and last letters of whatever word they associate with each inkblot. Then they combine the letters to form a password.

      I got ********.

      Mine is h2h2h2h2.
    4. Re:Not sure this will help by Marc+Desrochers · · Score: 2, Funny
      bbbbbbbbbb

      That all look like butterflies.

    5. Re:Not sure this will help by Clandestine_Blaze · · Score: 3, Funny

      I got vavavapsva. That's amazing! I've got the same combination on my luggage!
    6. Re:Not sure this will help by mithras+invictus · · Score: 3, Funny

      Ballmers new password: dsdsdsdsds

    7. Re:Not sure this will help by DeepHurtn! · · Score: 2, Funny

      A /.er, scared of genitalia...? I guess this proves the saying about people being scared of the unknown!

    8. Re:Not sure this will help by Vulva+R.+Thompson,+P · · Score: 2, Funny

      Feel free to pop in any time you like.

    9. Re:Not sure this will help by floki · · Score: 2, Funny
      --
      from the to-stupid-for-words dept.
    10. Re:Not sure this will help by NoPantsJim · · Score: 2, Funny

      I'd go immediately, 4 to 1 is the best ratio I've ever seen.

  2. I'm shocked!!! by b17bmbr · · Score: 4, Funny

    microsoft is collecting and storing the data. holy crap, batman, what next. the joker has plans to take over gotham city?

    --
    My problem? I was perfectly gruntled, until some numbnuts came by and dissed me.
    1. Re:I'm shocked!!! by calebt3 · · Score: 2, Insightful

      Even if MS said that they weren't keeping the data, I'm not sure anybody would believe them.

  3. Slight problem with this approach by Enlarged+to+Show+Tex · · Score: 4, Insightful

    This method will not create passwords that are strong enough. A truly strong password should have at least three of the following, if not all four:

    Uppercase letters
    Lowercase letters
    Numbers
    Non-Latin characters (i.e. symbols)

    Every password I use has at least three, even for free-registration-required sites...

    1. Re:Slight problem with this approach by oahazmatt · · Score: 5, Funny

      This method will not create passwords that are strong enough.
      That's why I use the inkblot test, run it through a script that converts random letter combinations to MD5, convert 25% of that end result to l33t, and then randomly add a non-latin character at two locations within that result. I then write it down on my desk calendar.
      --
      Those who believe the Internet is private,
      find their privates are on the Internet.
    2. Re:Slight problem with this approach by TubeSteak · · Score: 4, Insightful

      A truly strong password should have at least three of the following, if not all four: Only if there's a maximum character limit on the password.

      Or are you going to tell me that
      "atrulystrongpasswordshouldhaveatleastthreeofthefollowingifnotallfour"
      is not a strong password?

      I'm not suggesting everyone should use such a long pass, but what's so hard about implementing passphrases instead of passwords?
      --
      [Fuck Beta]
      o0t!
    3. Re:Slight problem with this approach by Rakishi · · Score: 2, Insightful

      A truly strong password should have at least three of the following, if not all four: Not really, you can just make you password longer and you are just as secure.
    4. Re:Slight problem with this approach by eldavojohn · · Score: 2, Informative
      That's not the only problem. If you read the research paper[PDF Warning] from 2004 (pretty old stuff actually), they state:

      In both experiments, users missed at most one association, even after having not used the system for one week. Thus it may be advisable to modify the system to allow for successful authentications when k out of a possible n associations are correct. Assuming that all blots produce an equal distribution on responses, this reduces the security of passwords to the level of the original system with only k blots. Therefore, it might be advantageous for users to have to enter associations for more blots. A disadvantage of this approach, however, is that authentication would take longer. As of interest may also be their conclusion:

      Our preliminary data suggest that inkblot authentication offers a potentially significant improvement over existing widely-deployed user authentication mechanisms. In addition to gathering our quantitative results, we also asked users who had taken part in our experiments for their comments on the system. In almost all cases we received the same response: the users were happily shocked that they could remember such a "huge password." In fact, many users asked if there were any plans to allow the use of the system in their production environment. This kind of positive user experience is arguably as important to the eventual adoption, acceptance and scrupulous use of an alternative password system as any measure of security. More experiments would help confirm or discount our security and memorability results, and could answer such questions as: How many inkblots (that is, how much entropy) can be used before the resulting passwords are no longer memorable? What is the best way to help users retain their inkblot associations? What inkblot-to-character hash function generates the most entropy without sacrificing ease of use? And what inkblot generation algorithms create inkblots with the highest-entropy (or the fewest low-entropy) association spaces?
      While inkblot authentication should be quite easy to deploy in a wide variety of settings, there exist some environments (such as devices with tiny screens) where it is unworkable, and alternatives are needed. Adapting the inkblot password scheme to other password-using contexts, such as those in which the user interface is under the control of a (possibly uncooperative or legacy) application, may also require some innovative thinking.
      --
      My work here is dung.
    5. Re:Slight problem with this approach by PresidentEnder · · Score: 2, Insightful

      26^10 > 95^5. Even if you restrict your password to only a few characters, you can get the same level of security as with many characters. You just need far more of them. Think about it: when we strip off all of our abstractions, everything is stored as 1s and 0s, right? (Note: Parent's point is good and right, if your password must be short, or you don't want to spend time doing the inkblot test, or you don't want to have to remember 90 characters.)

      --
      I used to carry a bottle of whiskey for snake bite. And two snakes. -Nefarious Wheel
    6. Re:Slight problem with this approach by ChatHuant · · Score: 3, Insightful

      This method will not create passwords that are strong enough. A truly strong password should have at least three of the following, if not all four:
      Uppercase letters
      Lowercase letters
      Numbers
      Non-Latin characters (i.e. symbols)


      That's just not true. Admins request this kind of nonsense to force a bigger password space with shorter passwords. Informally, the security of your password is given by the number of random bits you have. With ASCII passwords using only lowercase letters, you're adding less than 5 bits of randomness per character. Even worse, most people use real words as passwords, so they can remember them easily. That reduces the randomness even more and makes dictionary attacks feasible. Adding uppercase, numbers and symbols gives you an extra bit or two of randomness per character, but makes the password much more difficult to remember.

      Microsoft's method works around the password memorization by using the inkblots. The security is given by the much larger size of the resulting password. They get a password of 20 lowercase characters, say about 100 bits of randomness (less than that, because not all letter combinations are equiprobable - very few words I know begin and end with a q for example). A totally random password consisting of a mix of 10 symbols, numbers and different cased letters only gives you a bit less than 70 bits of randomness.

    7. Re:Slight problem with this approach by zsouthboy · · Score: 5, Interesting

      I also highly suggest, right now, that everyone change your passwords to currentpassword x 3 or 4, or more:

      For example, is passwordpasswordpassword any harder to remember than just password?

      But it greatly expands the key space to be searched for anyone trying to brute force...

    8. Re:Slight problem with this approach by AeroIllini · · Score: 2, Insightful

      Because many people have trouble typing their own names correctly without using the backspace key a few times, and typing a password in a box gives no visual feedback. Higher letter count gives a higher chance of typos, and a higher chance of getting locked out after typing "atrulystrongpasswordshouldhaveatleastthreeoftehfollowingifnotallfour" five times in a row.

      Chances of a typo are even higher if someone routinely types in MS Word with AutoComplete turned on and is now physically incapable of typing "the", "from", or any number of words correctly the first time. Double bonus points if they work in a major corporation and hunt'n'peck.

      --
      For security, the MD5 hash of this message and sig is 09f911029d74e35bd84156c5635688c0.
    9. Re:Slight problem with this approach by twifosp · · Score: 2, Interesting

      but what's so hard about implementing passphrases instead of passwords?

      I agree with you, but the problem for the average user is that they are not touch typers. They are constantly looking at the keyboard and screen to confirm what they have typed. As the length of the password increases, the odds that a typing error is going to be made also goes up. As passwords are blocked out, it would be very frusterating to a person who has to look at the screen to confirm what they have typed and backspaces often. This gets worse if you are trying to login to a domain with strict policies, I.E. most large companies. If you make too many mistakes trying to login, your account is locked.

  4. Hmmmm .... by gstoddart · · Score: 4, Interesting
    From TFA:

    "A century of psychological literature indicates that inkblot associations are intimately personal, and our own user studies verify that users almost always describe the same inkblots quite differently"

    So, psyche 101 was a long time ago, and that's the extent of my exposure to it.

    Do individual people respond to the same inkblots, the same way over time? Or might I see the same splotch in 3 months and associate something else with it? If there's drift over time, this wouldn't be such a good idea.

    Anyone with a better schooling in human psychology care to chime in?

    Cheers

    --
    Lost at C:>. Found at C.
    1. Re:Hmmmm .... by dgatwood · · Score: 2, Interesting

      I don't know, but about three years ago, I recall suggesting the use of non-abstract images and measuring the brain's electrical response to determine a map of the user's response to a given stimulus. After the system was trained properly, you could use that to be a really, really solid passphrase; while your brain may react a bit differently to images over time, it isn't likely to react dramatically differently for the most part (except maybe after head trauma or something similarly extreme). This seems like a somewhat more practical way of doing the same basic thing.

      I would expect your reactions to differ over time, but I would not expect them to change dramatically in a short period of time, and that's the key to such a system. As I said way back then, as long as you log in periodically, such a system can use a learning algorithm to conclude with a high degree of probability whether it is the same person and then adjust its notion of the password as it goes along. Whether Microsoft will do this or not remains to be seen.

      --

      Check out my sci-fi/humor trilogy at PatriotsBooks.

  5. Don't do it... by daninspokane · · Score: 5, Funny

    The blots are coded to shut your brain down if you don't have a valid regkey.

    --
    Slashdot is too nerdy for me.
  6. random? by clarkn0va · · Score: 2, Funny
    Respond with "butterfly" and share your password with half the english-speaking planet.

    db

    --
    I am literally 3000 tokens away from the chaotic crossbow --Stephen
  7. Ballmer's unencrypted file by Eberlin · · Score: 5, Funny

    Anyone wanna bet Ballmer's word list looks a bit like this:
    chair
    developers
    chair
    banana
    ooohshiny
    developers!
    developers!
    developers!

  8. Storing and insecure by tkdtaylor · · Score: 5, Informative
    It's a research project so of course it's storing the responses.
    From the actual site:

    Security and privacy of this service

    InkblotPassword.com is a research project deployed by Microsoft Research. It is for demonstration and research purposes only. You are welcome to try it out, but we make absolutely no promise that our implementation will protect your password. Don't use your account here to protect any data you care about, from money to your reputation. We also make no promise that the site will continue running. Should the service prove successful, Microsoft may consider offering the service as a commercial product or service. For now, consider it an unreliable, insecure service run by a couple research coneheads in their spare time, and trust it accordingly.
  9. Wait... by ucblockhead · · Score: 4, Interesting

    So they have created a method for creating hard to crack passwords while simultaneously collecting the data to more easily crack them?

    --
    The cake is a pie
  10. No way.... by Bobfrankly1 · · Score: 2, Funny

    Microsoft Wants To Give You A Rorschach

    If this is anything like a wet willy, I don't want one, and you can't make me.
    *runs away screaming*
  11. Reusing the password by Culture20 · · Score: 4, Insightful

    "Nothing prevents a user from learning a strong password on Inkblotpassword.com and then reusing it at other sites," Microsoft's researchers said.
    Common sense might.
  12. All I keep seeing... by Cytlid · · Score: 4, Funny

    ...is penguins.

    --
    FLR
  13. Captcha by GreggBz · · Score: 4, Interesting

    That site has one of the best captcha's I've ever seen.

    Please select all the cats. Pictures supplied (and sponsored) by petfinder.com. Brilliant. Even HAL-9000 might not be able to do that.

    1. Re:Captcha by linumax · · Score: 2, Informative

      This website was designed for people who are not visually disabled, otherwise how the hell are they gonna see the inkblots? Save your Microsoft bashing for when they implement it on MSN or sth.

  14. Vanillia? Viagra? Volousia? Pens? Va....oh wait by StressGuy · · Score: 2, Funny

    ...you really need a girlfriend

    --
    A goal is a dream with a deadline
  15. Re:P**n by ShieldW0lf · · Score: 5, Interesting

    I usually suggest to people that they come up with a positive self talk phrase, take the first letter of each word, then replace a letter with a number that resembles it.

    Something like "I am a happy person who loves their life." turns into "Iaahpwlt1", which is long, contains numbers and letters and no dictionary words whatsoever.

    You end up repeating it to yourself every time you log in, which serves double duty as both a mnemonic device and a way to preserve your positive attitude.

    --
    -1 Uncomfortable Truth
  16. I get it by EmbeddedJanitor · · Score: 2, Funny
    WIuVIftWGA2p0:"When I use Vista I feel the Windows Genuine Advantage 2 point 0"

    You're right I feel better already! Wow everything feels faster! Any more exclamaitions and I'd be using Yahoo!!

    --
    Engineering is the art of compromise.
  17. Re:Oblig Watchmen by Lurker2288 · · Score: 2, Funny

    It looks like a pretty butterfly. Or maybe some nice flowers. Or a dog with a cleaved brain, either way.

  18. Obligatory Emo Philips by LoverOfJoy · · Score: 4, Funny

    "Emo, what does this inkblot look like to you?"

    I said, "Oh, it's kind of embarrassing."

    He said, "Emo, everyone sees something, so don't be embarrassed. Tell me what the inkblot looks like to you."

    I said, "Well, to me it looks like standard pattern #3 in the Rorschach series to test obsessive compulsiveness." And he gets kind of depressed.

    I said, "Okay, it's a butterfly." And he cheers up.

    He said, "What does this inkblot look like?"

    I said, "It looks like a horrible ugly blob of pure evil that sucks the souls of man into a vortex of sin and degradation."

    He said, "No, um, the inkblot's over there. That's a photo of my wife you're looking at."

    "Oh," I said, "was I far off?" He said, "No. That's the sad part."

  19. Ob. Schneier by Anonymous Coward · · Score: 3, Funny

    "Most people use passwords. Some people use passphrases. Bruce Schneier uses an epic passpoem, detailing the life and works of seven mythical Norse heroes."

  20. Re:P**n by flabbergasted · · Score: 3, Funny

    I usually suggest to people that they come up with a positive self talk phrase, take the first letter of each word, then replace a letter with a number that resembles it.

    Something like "I am a happy person who loves their life." turns into "Iaahpwlt1", which is long, contains numbers and letters and no dictionary words whatsoever.

    I use mnemonic devices also, but perhaps I should rethink my current "Nobody loves me, I wish I were dead" password. Oh, what's the use. It wouldn't matter anyway.

  21. Silly... try a leet password generator by cenonce · · Score: 2, Informative

    That is just silly... I spend too much time trying to think of what these inkblots look like, and some of them really don't look like anything.

    Try a leet password generator... way easier to remember!

  22. Re:P**n by RealGrouchy · · Score: 3, Funny

    A self-motivational phrase whose initials double as a secure password? That's a great idea!

    Here, let me try one:

    People Always Say Something's Wrong Or Really Depressing.

    Awesome! I'll use it on all my accounts!

    - RG>

    --
    Hey pal, this isn't a pleasantforest, so don't waste my time with pleasantries!