more passwords

Another idea for an alternative password would be a picture based password.  The idea is that the user uploads a bunch of images.  Some might have faces and others might be scenes etc.  The system would then ask the user to select like 5 of the images from the set of images.  The user would then be asked to trace a free form closed region on each of those 5 images.  The system records those regions.  Accompanying the standard password the user would have to draw that region (within some error bound).  This would be useful as a second precaution.  Might be a pain to do though…

Biometrics and passwords

I’m taking pattern recognition.  We had a discussion on biometrics and we came up with the idea of using the gyro info from a smart phone as a password.  This would allow users to shake and move their phone in some pattern that would allow them to log into their system.

I found this paper that details how mallicious apps can monitor when users are typing and gather gyro data to predict the keystrokes and thus possible passwords.  http://www.cse.psu.edu/~szhu/papers/taplogger.pdf.  By using motion based passwords users would not have to fear that their passwords were being stolen.  Maybe since websites can detect if you are browsing with a phone they could ask you to input a motion based password if you have previously associated one with your account.

They are doing something similar using Leap Motion http://www.forbes.com/sites/michaelwolf/2013/02/06/could-that-shake-in-your-hand-replace-your-password-leap-motion-thinks-so/.  This would be great for medical fraud detection.  Can’t use dead people, and you would need the person to be their in order for the system to approve the claim.