Another idea for an alternative password would be a picture based password. The idea is that the user uploads a bunch of images. Some might have faces and others might be scenes etc. The system would then ask the user to select like 5 of the images from the set of images. The user would then be asked to trace a free form closed region on each of those 5 images. The system records those regions. Accompanying the standard password the user would have to draw that region (within some error bound). This would be useful as a second precaution. Might be a pain to do though…
Month: October 2014
Biometrics and passwords
I’m taking pattern recognition. We had a discussion on biometrics and we came up with the idea of using the gyro info from a smart phone as a password. This would allow users to shake and move their phone in some pattern that would allow them to log into their system.
I found this paper that details how mallicious apps can monitor when users are typing and gather gyro data to predict the keystrokes and thus possible passwords. http://www.cse.psu.edu/~szhu/papers/taplogger.pdf. By using motion based passwords users would not have to fear that their passwords were being stolen. Maybe since websites can detect if you are browsing with a phone they could ask you to input a motion based password if you have previously associated one with your account.
They are doing something similar using Leap Motion http://www.forbes.com/sites/michaelwolf/2013/02/06/could-that-shake-in-your-hand-replace-your-password-leap-motion-thinks-so/. This would be great for medical fraud detection. Can’t use dead people, and you would need the person to be their in order for the system to approve the claim.