Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Vulnerabilities / Threats

8/29/2013
07:53 PM
Connect Directly
LinkedIn
Twitter
RSS
E-Mail
50%
50%

Windows 8 Picture Passwords Easily Cracked

Microsoft's picture gesture authentication system isn't that secure, security researchers say.

10 Hidden Benefits of Windows 8.1
10 Hidden Benefits of Windows 8.1
(click image for larger view)
Microsoft Windows 8 offers gesture-based passwords, in addition to traditional text-based passwords, in the hope that tracing a pattern on a familiar photograph is "secure but also a lot of fun to use."

It appears that picture gesture authentication (PGA) achieves only one of the two. Security researchers at Arizona State University and Delaware State University have found that Windows 8 picture passwords can be cracked with relative ease.

In a paper presented at the Usenix Conference earlier this month, "On the Security of Picture Gesture Authentication," Ziming Zhao, Gail-Joon Ahn and Jeong-Jin Seo from Arizona State, and Hongxin Hu from Delaware State, claim that their experimental model and attack framework allowed them to crack 48% of passwords for previously unseen pictures in one dataset and 24% in another.

[ Can you see the cyber warning shots? Read NY Times Caught In Syrian Hacker Attack. ]

This is with 219 guesses in a password space of 230 possibilities. Within the Windows 8 limit of five login attempts, the success rate is less: 216 out of 10,000 gesture passwords in one data set and 94 of 10,000 in the other one. The success rate improved with additional training data. Using a purely automated attack without supporting information, 0.9% of passwords could be cracked within five guesses.

Though that may not seem like a significant vulnerability, the fact remains that gesture-based passwords aren't as secure as Microsoft had hoped. In an email, Ahn said he expected the results could be improved with a larger training set and stronger picture categorization and computer vision techniques.

Setting up a gesture-based password involves choosing a photo from one's Picture Library folder and drawing three points on the image. The system accepts taps, lines and circles. Windows 8 subdivides the image into a 100 x 100 grid and stores the input points as grid coordinates.

Unfortunately, users aren't very good at selecting random points on their images; they tend to pick common points of interest, such as eyes, faces or discrete objects. As a result, passwords derived from this constrained set have much less variability than randomly generated passwords. So they're easier to crack.

Ahn says you only need to look at Microsoft's Windows 8 ads, which show users selecting obvious points of interest to form PGA passwords, to see that Microsoft's approach needs improvement.

The research paper suggests that Microsoft implement a picture-password-strength meter, similar to systems that prevent people from choosing weak text-based passwords. It also suggests that Microsoft integrate the researchers' PGA attack framework to inform users of the potential number of guesses it would take to access their system.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Ferrcpb
50%
50%
Ferrcpb,
User Rank: Apprentice
9/26/2016 | 4:44:12 AM
re: Windows 8 Picture Passwords Easily Cracked
I tried several times but it not working properly on my computer. When i created the password reset disk, it even can't boot my computer. It is so weird. Luckily, my friend suggested me a tool called UUkeys Windows Password Recovery. It only took me a few minutes to reset the password.
Zerious
50%
50%
Zerious,
User Rank: Apprentice
9/21/2016 | 3:25:54 AM
re: Windows 8 Picture Passwords Easily Cracked
There is no option to remove password if your system is in domain joined.If your PC are in work group you can disable the password option from control panal-->user accounts then you can have only Picture password option.Please let me know if you are not able to do this.I will help you. You can try iseePassword windows password recoery tool to reset your password.
ganebob
50%
50%
ganebob,
User Rank: Apprentice
4/13/2014 | 9:37:09 PM
re: Windows 8 Picture Passwords Easily Cracked
Picture password is encrypted using the reversible encryption algorithms. With the freeware Mimikatz you can recover Windows 8 Picture password instantly.
justiny99
100%
0%
justiny99,
User Rank: Apprentice
12/13/2013 | 4:32:07 AM
re: Windows 8 Picture Passwords Easily Cracked
To crack Windows 8 picture password, I find out another article about it from a smart key page, I think it is helpful as well, read it in http://www.recoverlostpassword.com/article/crack-windows-8-password.html
asadovnik
50%
50%
asadovnik,
User Rank: Apprentice
10/2/2013 | 3:45:59 PM
re: Windows 8 Picture Passwords Easily Cracked
Here is another article with a similar flavor:

http://chenlab.ece.cornell.edu...
anon9517146816
100%
0%
anon9517146816,
User Rank: Apprentice
9/16/2013 | 9:26:49 AM
re: Windows 8 Picture Passwords Easily Cracked
how to crack Windows 8 picture password if forgot? I got this article to help me: http://t.co/uUXrRqUaFC
Trish MacDonald
50%
50%
Trish MacDonald,
User Rank: Apprentice
9/5/2013 | 5:26:29 PM
re: Windows 8 Picture Passwords Easily Cracked
I always thought it'd be easier to crack a picture password in-person anyway because the screen would show a 'trail' of finger swipes.
dlessard611
50%
50%
dlessard611,
User Rank: Apprentice
9/3/2013 | 1:26:42 PM
re: Windows 8 Picture Passwords Easily Cracked
I love the title "Windows 8 Picture Passwords Easily Cracked" as usual I have to read the entire InformationWeek article to discover that the title again is misleading. Not that I'm defending W8 (I actually like it though) but I find InfoWeek has editorials written by folks at Apple or Google I guess.
Please but some comparative data into your articles, stating some figures is fine but put it up against something that means something to all of us and it will be more useful. And correct your attention getting article names, less informed folks are more impressionable that some.
Thomas Claburn
50%
50%
Thomas Claburn,
User Rank: Ninja
8/30/2013 | 7:13:58 PM
re: Windows 8 Picture Passwords Easily Cracked
Unfortunately, all too often the user is the weak link in the security chain,
ChrisMurphy
50%
50%
ChrisMurphy,
User Rank: Strategist
8/30/2013 | 3:59:50 PM
re: Windows 8 Picture Passwords Easily Cracked
I like the idea of a password strength meter because let's face it this is probably still stronger than a 1234 or ABCD password alternative. For a lot of use cases it's probably plenty strong and more likely to be used.
Commentary
How SolarWinds Busted Up Our Assumptions About Code Signing
Dr. Jethro Beekman, Technical Director,  3/3/2021
News
'ObliqueRAT' Now Hides Behind Images on Compromised Websites
Jai Vijayan, Contributing Writer,  3/2/2021
News
Attackers Turn Struggling Software Projects Into Trojan Horses
Robert Lemos, Contributing Writer,  2/26/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win an Amazon Gift Card! Click Here
Latest Comment: George has not accepted that the technology age has come to an end.
Current Issue
2021 Top Enterprise IT Trends
We've identified the key trends that are poised to impact the IT landscape in 2021. Find out why they're important and how they will affect you today!
Flash Poll
How Enterprises are Developing Secure Applications
How Enterprises are Developing Secure Applications
Recent breaches of third-party apps are driving many organizations to think harder about the security of their off-the-shelf software as they continue to move left in secure software development practices.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-26814
PUBLISHED: 2021-03-06
Wazuh API in Wazuh from 4.0.0 to 4.0.3 allows authenticated users to execute arbitrary code with administrative privileges via /manager/files URI. An authenticated user to the service may exploit incomplete input validation on the /manager/files API to inject arbitrary code within the API service sc...
CVE-2021-27581
PUBLISHED: 2021-03-05
The Blog module in Kentico CMS 5.5 R2 build 5.5.3996 allows SQL injection via the tagname parameter.
CVE-2021-28042
PUBLISHED: 2021-03-05
Deutsche Post Mailoptimizer 4.3 before 2020-11-09 allows Directory Traversal via a crafted ZIP archive to the Upload feature or the MO Connect component. This can lead to remote code execution.
CVE-2021-28041
PUBLISHED: 2021-03-05
ssh-agent in OpenSSH before 8.5 has a double free that may be relevant in a few less-common scenarios, such as unconstrained agent-socket access on a legacy operating system, or the forwarding of an agent to an attacker-controlled host.
CVE-2021-3377
PUBLISHED: 2021-03-05
The npm package ansi_up converts ANSI escape codes into HTML. In ansi_up v4, ANSI escape codes can be used to create HTML hyperlinks. Due to insufficient URL sanitization, this feature is affected by a cross-site scripting (XSS) vulnerability. This issue is fixed in v5.0.0.