Vulnerabilities / Threats
8/29/2013
07:53 PM
Connect Directly
Google+
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Windows 8 Picture Passwords Easily Cracked

Microsoft's picture gesture authentication system isn't that secure, security researchers say.

10 Hidden Benefits of Windows 8.1
10 Hidden Benefits of Windows 8.1
(click image for larger view)
Microsoft Windows 8 offers gesture-based passwords, in addition to traditional text-based passwords, in the hope that tracing a pattern on a familiar photograph is "secure but also a lot of fun to use."

It appears that picture gesture authentication (PGA) achieves only one of the two. Security researchers at Arizona State University and Delaware State University have found that Windows 8 picture passwords can be cracked with relative ease.

In a paper presented at the Usenix Conference earlier this month, "On the Security of Picture Gesture Authentication," Ziming Zhao, Gail-Joon Ahn and Jeong-Jin Seo from Arizona State, and Hongxin Hu from Delaware State, claim that their experimental model and attack framework allowed them to crack 48% of passwords for previously unseen pictures in one dataset and 24% in another.

[ Can you see the cyber warning shots? Read NY Times Caught In Syrian Hacker Attack. ]

This is with 219 guesses in a password space of 230 possibilities. Within the Windows 8 limit of five login attempts, the success rate is less: 216 out of 10,000 gesture passwords in one data set and 94 of 10,000 in the other one. The success rate improved with additional training data. Using a purely automated attack without supporting information, 0.9% of passwords could be cracked within five guesses.

Though that may not seem like a significant vulnerability, the fact remains that gesture-based passwords aren't as secure as Microsoft had hoped. In an email, Ahn said he expected the results could be improved with a larger training set and stronger picture categorization and computer vision techniques.

Setting up a gesture-based password involves choosing a photo from one's Picture Library folder and drawing three points on the image. The system accepts taps, lines and circles. Windows 8 subdivides the image into a 100 x 100 grid and stores the input points as grid coordinates.

Unfortunately, users aren't very good at selecting random points on their images; they tend to pick common points of interest, such as eyes, faces or discrete objects. As a result, passwords derived from this constrained set have much less variability than randomly generated passwords. So they're easier to crack.

Ahn says you only need to look at Microsoft's Windows 8 ads, which show users selecting obvious points of interest to form PGA passwords, to see that Microsoft's approach needs improvement.

The research paper suggests that Microsoft implement a picture-password-strength meter, similar to systems that prevent people from choosing weak text-based passwords. It also suggests that Microsoft integrate the researchers' PGA attack framework to inform users of the potential number of guesses it would take to access their system.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
ganebob
50%
50%
ganebob,
User Rank: Apprentice
4/13/2014 | 9:37:09 PM
re: Windows 8 Picture Passwords Easily Cracked
Picture password is encrypted using the reversible encryption algorithms. With the freeware Mimikatz you can recover Windows 8 Picture password instantly.
justiny99
100%
0%
justiny99,
User Rank: Apprentice
12/13/2013 | 4:32:07 AM
re: Windows 8 Picture Passwords Easily Cracked
To crack Windows 8 picture password, I find out another article about it from a smart key page, I think it is helpful as well, read it in http://www.recoverlostpassword.com/article/crack-windows-8-password.html
asadovnik
50%
50%
asadovnik,
User Rank: Apprentice
10/2/2013 | 3:45:59 PM
re: Windows 8 Picture Passwords Easily Cracked
Here is another article with a similar flavor:

http://chenlab.ece.cornell.edu...
anon9517146816
100%
0%
anon9517146816,
User Rank: Apprentice
9/16/2013 | 9:26:49 AM
re: Windows 8 Picture Passwords Easily Cracked
how to crack Windows 8 picture password if forgot? I got this article to help me: http://t.co/uUXrRqUaFC
Trish MacDonald
50%
50%
Trish MacDonald,
User Rank: Apprentice
9/5/2013 | 5:26:29 PM
re: Windows 8 Picture Passwords Easily Cracked
I always thought it'd be easier to crack a picture password in-person anyway because the screen would show a 'trail' of finger swipes.
dlessard611
50%
50%
dlessard611,
User Rank: Apprentice
9/3/2013 | 1:26:42 PM
re: Windows 8 Picture Passwords Easily Cracked
I love the title "Windows 8 Picture Passwords Easily Cracked" as usual I have to read the entire InformationWeek article to discover that the title again is misleading. Not that I'm defending W8 (I actually like it though) but I find InfoWeek has editorials written by folks at Apple or Google I guess.
Please but some comparative data into your articles, stating some figures is fine but put it up against something that means something to all of us and it will be more useful. And correct your attention getting article names, less informed folks are more impressionable that some.
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Moderator
8/30/2013 | 7:13:58 PM
re: Windows 8 Picture Passwords Easily Cracked
Unfortunately, all too often the user is the weak link in the security chain,
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Apprentice
8/30/2013 | 3:59:50 PM
re: Windows 8 Picture Passwords Easily Cracked
I like the idea of a password strength meter because let's face it this is probably still stronger than a 1234 or ABCD password alternative. For a lot of use cases it's probably plenty strong and more likely to be used.
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-2208
Published: 2014-12-28
CRLF injection vulnerability in the LightProcess protocol implementation in hphp/util/light-process.cpp in Facebook HipHop Virtual Machine (HHVM) before 2.4.2 allows remote attackers to execute arbitrary commands by entering a \n (newline) character before the end of a string.

CVE-2014-2209
Published: 2014-12-28
Facebook HipHop Virtual Machine (HHVM) before 3.1.0 does not drop supplemental group memberships within hphp/util/capability.cpp and hphp/util/light-process.cpp, which allows remote attackers to bypass intended access restrictions by leveraging group permissions for a file or directory.

CVE-2014-5386
Published: 2014-12-28
The mcrypt_create_iv function in hphp/runtime/ext/mcrypt/ext_mcrypt.cpp in Facebook HipHop Virtual Machine (HHVM) before 3.3.0 does not seed the random number generator, which makes it easier for remote attackers to defeat cryptographic protection mechanisms by leveraging the use of a single initial...

CVE-2014-6123
Published: 2014-12-28
IBM Rational AppScan Source 8.0 through 8.0.0.2 and 8.5 through 8.5.0.1 and Security AppScan Source 8.6 through 8.6.0.2, 8.7 through 8.7.0.1, 8.8, 9.0 through 9.0.0.1, and 9.0.1 allow local users to obtain sensitive credential information by reading installation logs.

CVE-2014-6160
Published: 2014-12-28
IBM WebSphere Service Registry and Repository (WSRR) 8.5 before 8.5.0.1, when Chrome and WebSEAL are used, does not properly process ServiceRegistryDashboard logout actions, which allows remote attackers to bypass intended access restrictions by leveraging an unattended workstation.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Join us Wednesday, Dec. 17 at 1 p.m. Eastern Time to hear what employers are really looking for in a chief information security officer -- it may not be what you think.