Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/29/2013
07:53 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Windows 8 Picture Passwords Easily Cracked

Microsoft's picture gesture authentication system isn't that secure, security researchers say.

10 Hidden Benefits of Windows 8.1
10 Hidden Benefits of Windows 8.1
(click image for larger view)
Microsoft Windows 8 offers gesture-based passwords, in addition to traditional text-based passwords, in the hope that tracing a pattern on a familiar photograph is "secure but also a lot of fun to use."

It appears that picture gesture authentication (PGA) achieves only one of the two. Security researchers at Arizona State University and Delaware State University have found that Windows 8 picture passwords can be cracked with relative ease.

In a paper presented at the Usenix Conference earlier this month, "On the Security of Picture Gesture Authentication," Ziming Zhao, Gail-Joon Ahn and Jeong-Jin Seo from Arizona State, and Hongxin Hu from Delaware State, claim that their experimental model and attack framework allowed them to crack 48% of passwords for previously unseen pictures in one dataset and 24% in another.

[ Can you see the cyber warning shots? Read NY Times Caught In Syrian Hacker Attack. ]

This is with 219 guesses in a password space of 230 possibilities. Within the Windows 8 limit of five login attempts, the success rate is less: 216 out of 10,000 gesture passwords in one data set and 94 of 10,000 in the other one. The success rate improved with additional training data. Using a purely automated attack without supporting information, 0.9% of passwords could be cracked within five guesses.

Though that may not seem like a significant vulnerability, the fact remains that gesture-based passwords aren't as secure as Microsoft had hoped. In an email, Ahn said he expected the results could be improved with a larger training set and stronger picture categorization and computer vision techniques.

Setting up a gesture-based password involves choosing a photo from one's Picture Library folder and drawing three points on the image. The system accepts taps, lines and circles. Windows 8 subdivides the image into a 100 x 100 grid and stores the input points as grid coordinates.

Unfortunately, users aren't very good at selecting random points on their images; they tend to pick common points of interest, such as eyes, faces or discrete objects. As a result, passwords derived from this constrained set have much less variability than randomly generated passwords. So they're easier to crack.

Ahn says you only need to look at Microsoft's Windows 8 ads, which show users selecting obvious points of interest to form PGA passwords, to see that Microsoft's approach needs improvement.

The research paper suggests that Microsoft implement a picture-password-strength meter, similar to systems that prevent people from choosing weak text-based passwords. It also suggests that Microsoft integrate the researchers' PGA attack framework to inform users of the potential number of guesses it would take to access their system.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ferrcpb
50%
50%
Ferrcpb,
User Rank: Apprentice
9/26/2016 | 4:44:12 AM
re: Windows 8 Picture Passwords Easily Cracked
I tried several times but it not working properly on my computer. When i created the password reset disk, it even can't boot my computer. It is so weird. Luckily, my friend suggested me a tool called UUkeys Windows Password Recovery. It only took me a few minutes to reset the password.
Zerious
50%
50%
Zerious,
User Rank: Apprentice
9/21/2016 | 3:25:54 AM
re: Windows 8 Picture Passwords Easily Cracked
There is no option to remove password if your system is in domain joined.If your PC are in work group you can disable the password option from control panal-->user accounts then you can have only Picture password option.Please let me know if you are not able to do this.I will help you. You can try iseePassword windows password recoery tool to reset your password.
ganebob
50%
50%
ganebob,
User Rank: Apprentice
4/13/2014 | 9:37:09 PM
re: Windows 8 Picture Passwords Easily Cracked
Picture password is encrypted using the reversible encryption algorithms. With the freeware Mimikatz you can recover Windows 8 Picture password instantly.
justiny99
100%
0%
justiny99,
User Rank: Apprentice
12/13/2013 | 4:32:07 AM
re: Windows 8 Picture Passwords Easily Cracked
To crack Windows 8 picture password, I find out another article about it from a smart key page, I think it is helpful as well, read it in http://www.recoverlostpassword.com/article/crack-windows-8-password.html
asadovnik
50%
50%
asadovnik,
User Rank: Apprentice
10/2/2013 | 3:45:59 PM
re: Windows 8 Picture Passwords Easily Cracked
Here is another article with a similar flavor:

http://chenlab.ece.cornell.edu...
anon9517146816
100%
0%
anon9517146816,
User Rank: Apprentice
9/16/2013 | 9:26:49 AM
re: Windows 8 Picture Passwords Easily Cracked
how to crack Windows 8 picture password if forgot? I got this article to help me: http://t.co/uUXrRqUaFC
Trish MacDonald
50%
50%
Trish MacDonald,
User Rank: Apprentice
9/5/2013 | 5:26:29 PM
re: Windows 8 Picture Passwords Easily Cracked
I always thought it'd be easier to crack a picture password in-person anyway because the screen would show a 'trail' of finger swipes.
dlessard611
50%
50%
dlessard611,
User Rank: Apprentice
9/3/2013 | 1:26:42 PM
re: Windows 8 Picture Passwords Easily Cracked
I love the title "Windows 8 Picture Passwords Easily Cracked" as usual I have to read the entire InformationWeek article to discover that the title again is misleading. Not that I'm defending W8 (I actually like it though) but I find InfoWeek has editorials written by folks at Apple or Google I guess.
Please but some comparative data into your articles, stating some figures is fine but put it up against something that means something to all of us and it will be more useful. And correct your attention getting article names, less informed folks are more impressionable that some.
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
8/30/2013 | 7:13:58 PM
re: Windows 8 Picture Passwords Easily Cracked
Unfortunately, all too often the user is the weak link in the security chain,
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Strategist
8/30/2013 | 3:59:50 PM
re: Windows 8 Picture Passwords Easily Cracked
I like the idea of a password strength meter because let's face it this is probably still stronger than a 1234 or ABCD password alternative. For a lot of use cases it's probably plenty strong and more likely to be used.
COVID-19: Latest Security News & Commentary
Dark Reading Staff 11/19/2020
New Proposed DNS Security Features Released
Kelly Jackson Higgins, Executive Editor at Dark Reading,  11/19/2020
How to Identify Cobalt Strike on Your Network
Zohar Buber, Security Analyst,  11/18/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: A GONG is as good as a cyber attack.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-25660
PUBLISHED: 2020-11-23
A flaw was found in the Cephx authentication protocol in versions before 15.2.6 and before 14.2.14, where it does not verify Ceph clients correctly and is then vulnerable to replay attacks in Nautilus. This flaw allows an attacker with access to the Ceph cluster network to authenticate with the Ceph...
CVE-2020-25688
PUBLISHED: 2020-11-23
A flaw was found in rhacm versions before 2.0.5 and before 2.1.0. Two internal service APIs were incorrectly provisioned using a test certificate from the source repository. This would result in all installations using the same certificates. If an attacker could observe network traffic internal to a...
CVE-2020-25696
PUBLISHED: 2020-11-23
A flaw was found in the psql interactive terminal of PostgreSQL in versions before 13.1, before 12.5, before 11.10, before 10.15, before 9.6.20 and before 9.5.24. If an interactive psql session uses \gset when querying a compromised server, the attacker can execute arbitrary code as the operating sy...
CVE-2020-26229
PUBLISHED: 2020-11-23
TYPO3 is an open source PHP based web content management system. In TYPO3 from version 10.4.0, and before version 10.4.10, RSS widgets are susceptible to XML external entity processing. This vulnerability is reasonable, but is theoretical - it was not possible to actually reproduce the vulnerability...
CVE-2020-28984
PUBLISHED: 2020-11-23
prive/formulaires/configurer_preferences.php in SPIP before 3.2.8 does not properly validate the couleur, display, display_navigation, display_outils, imessage, and spip_ecran parameters.