Windows 8 Picture Passwords Easy to Crack, say Researchers

Latest Videos FromTom's Hardware
Kevin Parrish
Contributor

Kevin Parrish has over a decade of experience as a writer, editor, and product tester. His work focused on computer hardware, networking equipment, smartphones, tablets, gaming consoles, and other internet-connected devices. His work has appeared in Tom's Hardware, Tom's Guide, Maximum PC, Digital Trends, Android Authority, How-To Geek, Lifewire, and others.

  • DRosencraft
    I would say the first obvious step would be to require more than just three points of interest for the gesture entry. I don't know that you really need a research paper to point out that someone who is lazy about their password settings is going to pick the three most noticeable spots on the picture. Having five or six points should help a significant amount.

    Further from that, however, alpha numeric passwords still seem to be the most logical and functional password protection so long as the user is smart about it and not putting in the obvious strings (QWERTY, 12345, Password, etc.).

    But, this is mostly a moot point anyway since I don't know that most criminals are bothering with trying to crack your Windows password. I suspect that this story is meant less about Windows specifically, and more as a general warning to any company looking to use gesture input as an authentication method for any type of account (i.e bank, credit cards).
    Reply
  • althaz
    If a password has only 7-8 digits it's the exact opposite of secure. 12+ characters are a requirement for a secure password (there's a lot more, but 8 or less characters is absolutely worthless as it can be easily brute forced, which isn't realistically feasible for 12 character passwords yet).
    Reply
  • John Bauer
    Still took longer to crack than the iPhone's fingerprint scanner.
    Reply
  • Bloob
    So basically the problem is between the screen and the chair, as always.
    Reply
  • jalek
    The NSA supports this.
    Reply
  • I find it rather silly to first use 800 subjects to study their patterns and then execute ill intent conclusions.

    Firstly, if anyone with ill intention had access to 800 Win 8 machines why in their right mind would they care to crack a password. This is like saying that 60% of 800 bank customers use a pin consisting of "1234", and then go on to conclude that bank X has a poor security system. If a crook knew that there is a 60% chance that a bank debit card has 1234 pin then why would the crooks resort to steeling pin codes with various contraptions.
    Reply
  • Grandmastersexsay
    Log on passwords are relics of a bygone era when multiple people used one computer. Today, one person uses multiple computers. Most work computers are actually company issued laptops that are brought home each day.

    Log on passwords are useless and ineffective. If you are one of the few people today who leave their computer vulnerable to physical attack, you would be better served with a drive encryption based password setup.

    For the other 99% of us I recommend auto login. If your computer gets stolen, the criminal doesn't care about your work projects that you should have backed up anyway or your minecraft saves. Anyone who keeps sensitive information on their computer or information they can't easily replace is doing it wrong, and will probably get screwed over by a virus long before a physical attack on their computer would.
    Reply
  • _Cosmin_
    Just because anyone can guess your "special objects" on login image of Kate Upton naked... does not mean that login system has a flaw!
    Reply
  • apache_lives
    not as if passwords are secure either - normal Windows passwords can be stripped in under two minutes (XP - 8.1), Windows XP password protection is a joke
    Reply
  • juan83
    jajajajajaja how much cost this new windows OS?
    Reply