Vulnerabilities / Threats

8/29/2013
07:53 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Windows 8 Picture Passwords Easily Cracked

Microsoft's picture gesture authentication system isn't that secure, security researchers say.

10 Hidden Benefits of Windows 8.1
10 Hidden Benefits of Windows 8.1
(click image for larger view)
Microsoft Windows 8 offers gesture-based passwords, in addition to traditional text-based passwords, in the hope that tracing a pattern on a familiar photograph is "secure but also a lot of fun to use."

It appears that picture gesture authentication (PGA) achieves only one of the two. Security researchers at Arizona State University and Delaware State University have found that Windows 8 picture passwords can be cracked with relative ease.

In a paper presented at the Usenix Conference earlier this month, "On the Security of Picture Gesture Authentication," Ziming Zhao, Gail-Joon Ahn and Jeong-Jin Seo from Arizona State, and Hongxin Hu from Delaware State, claim that their experimental model and attack framework allowed them to crack 48% of passwords for previously unseen pictures in one dataset and 24% in another.

[ Can you see the cyber warning shots? Read NY Times Caught In Syrian Hacker Attack. ]

This is with 219 guesses in a password space of 230 possibilities. Within the Windows 8 limit of five login attempts, the success rate is less: 216 out of 10,000 gesture passwords in one data set and 94 of 10,000 in the other one. The success rate improved with additional training data. Using a purely automated attack without supporting information, 0.9% of passwords could be cracked within five guesses.

Though that may not seem like a significant vulnerability, the fact remains that gesture-based passwords aren't as secure as Microsoft had hoped. In an email, Ahn said he expected the results could be improved with a larger training set and stronger picture categorization and computer vision techniques.

Setting up a gesture-based password involves choosing a photo from one's Picture Library folder and drawing three points on the image. The system accepts taps, lines and circles. Windows 8 subdivides the image into a 100 x 100 grid and stores the input points as grid coordinates.

Unfortunately, users aren't very good at selecting random points on their images; they tend to pick common points of interest, such as eyes, faces or discrete objects. As a result, passwords derived from this constrained set have much less variability than randomly generated passwords. So they're easier to crack.

Ahn says you only need to look at Microsoft's Windows 8 ads, which show users selecting obvious points of interest to form PGA passwords, to see that Microsoft's approach needs improvement.

The research paper suggests that Microsoft implement a picture-password-strength meter, similar to systems that prevent people from choosing weak text-based passwords. It also suggests that Microsoft integrate the researchers' PGA attack framework to inform users of the potential number of guesses it would take to access their system.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ferrcpb
50%
50%
Ferrcpb,
User Rank: Apprentice
9/26/2016 | 4:44:12 AM
re: Windows 8 Picture Passwords Easily Cracked
I tried several times but it not working properly on my computer. When i created the password reset disk, it even can't boot my computer. It is so weird. Luckily, my friend suggested me a tool called UUkeys Windows Password Recovery. It only took me a few minutes to reset the password.
Zerious
50%
50%
Zerious,
User Rank: Apprentice
9/21/2016 | 3:25:54 AM
re: Windows 8 Picture Passwords Easily Cracked
There is no option to remove password if your system is in domain joined.If your PC are in work group you can disable the password option from control panal-->user accounts then you can have only Picture password option.Please let me know if you are not able to do this.I will help you. You can try iseePassword windows password recoery tool to reset your password.
ganebob
50%
50%
ganebob,
User Rank: Apprentice
4/13/2014 | 9:37:09 PM
re: Windows 8 Picture Passwords Easily Cracked
Picture password is encrypted using the reversible encryption algorithms. With the freeware Mimikatz you can recover Windows 8 Picture password instantly.
justiny99
100%
0%
justiny99,
User Rank: Apprentice
12/13/2013 | 4:32:07 AM
re: Windows 8 Picture Passwords Easily Cracked
To crack Windows 8 picture password, I find out another article about it from a smart key page, I think it is helpful as well, read it in http://www.recoverlostpassword.com/article/crack-windows-8-password.html
asadovnik
50%
50%
asadovnik,
User Rank: Apprentice
10/2/2013 | 3:45:59 PM
re: Windows 8 Picture Passwords Easily Cracked
Here is another article with a similar flavor:

http://chenlab.ece.cornell.edu...
anon9517146816
100%
0%
anon9517146816,
User Rank: Apprentice
9/16/2013 | 9:26:49 AM
re: Windows 8 Picture Passwords Easily Cracked
how to crack Windows 8 picture password if forgot? I got this article to help me: http://t.co/uUXrRqUaFC
Trish MacDonald
50%
50%
Trish MacDonald,
User Rank: Apprentice
9/5/2013 | 5:26:29 PM
re: Windows 8 Picture Passwords Easily Cracked
I always thought it'd be easier to crack a picture password in-person anyway because the screen would show a 'trail' of finger swipes.
dlessard611
50%
50%
dlessard611,
User Rank: Apprentice
9/3/2013 | 1:26:42 PM
re: Windows 8 Picture Passwords Easily Cracked
I love the title "Windows 8 Picture Passwords Easily Cracked" as usual I have to read the entire InformationWeek article to discover that the title again is misleading. Not that I'm defending W8 (I actually like it though) but I find InfoWeek has editorials written by folks at Apple or Google I guess.
Please but some comparative data into your articles, stating some figures is fine but put it up against something that means something to all of us and it will be more useful. And correct your attention getting article names, less informed folks are more impressionable that some.
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
8/30/2013 | 7:13:58 PM
re: Windows 8 Picture Passwords Easily Cracked
Unfortunately, all too often the user is the weak link in the security chain,
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Strategist
8/30/2013 | 3:59:50 PM
re: Windows 8 Picture Passwords Easily Cracked
I like the idea of a password strength meter because let's face it this is probably still stronger than a 1234 or ABCD password alternative. For a lot of use cases it's probably plenty strong and more likely to be used.
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Current Issue
The Year in Security 2018
This Dark Reading Tech Digest explores the biggest news stories of 2018 that shaped the cybersecurity landscape.
Flash Poll
How Enterprises Are Attacking the Cybersecurity Problem
How Enterprises Are Attacking the Cybersecurity Problem
Data breach fears and the need to comply with regulations such as GDPR are two major drivers increased spending on security products and technologies. But other factors are contributing to the trend as well. Find out more about how enterprises are attacking the cybersecurity problem by reading our report today.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-19019
PUBLISHED: 2019-01-22
A type confusion vulnerability exists when processing project files in CX-Supervisor (Versions 3.42 and prior). An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application.
CVE-2019-6260
PUBLISHED: 2019-01-22
The ASPEED ast2400 and ast2500 Baseband Management Controller (BMC) hardware and firmware implement Advanced High-performance Bus (AHB) bridges, which allow arbitrary read and write access to the BMC's physical address space from the host (or from the network in unusual cases where the BMC console u...
CVE-2018-19011
PUBLISHED: 2019-01-22
CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.
CVE-2018-19013
PUBLISHED: 2019-01-22
An attacker could inject commands to delete files and/or delete the contents of a file on CX-Supervisor (Versions 3.42 and prior) through a specially crafted project file.
CVE-2018-19017
PUBLISHED: 2019-01-22
Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privil...