6 ms·
Show HN: Using a color pattern to let a user 'recognise' their password
This is just a concept I made that allows a user to discern whether they have typed a password correctly before submitting. The user never sees their password, but should be able to recognise it's pattern.
Thoughts?
- charliesome 15y agoLotus Notes has been doing this for years with a series of images instead of colours. It's an interesting idea but I think it's more confusing than helpful.
- skattyadz 15y agoI've seen projects that generate a character or robot from a hash, and that could be interesting here, too. I agree that it's probably more confusing than helpful, though.
- burgerbrain 15y agoIn case anybody is wondering about robot hashing: http://robohash.org/ http://robohash.org/
- djhworld 15y agoReally? I thought those images were just a dumb animation that happened while you typed, I didn't even know the pictures had relevance to your input
- cstuder 15y agoA suggestion: You could reduce leakage of the first one or two characters by only starting the color display on the entry of the third letter.
- gus_massa 15y agoOr at least add a little time delay, so the colors don't give information about each letter, only information of the final password typed.
- mping 15y agoThis has been done before: http://mattt.github.com/Chroma-Hash/ http://mattt.github.com/Chroma-Hash/ Just make sure that the color thing is not reversible.
- skattyadz 15y agoOoh, that's a lot nicer. Thanks :)
- palmr 15y agoArc90 Labs had a similar thing around the same time too: http://lab.arc90.com/2009/07/09/hashmask-another-more-secure-experiment-in-password-masking/ http://lab.arc90.com/2009/07/09/hashmask-another-more-secure...
- kappaknight 15y agoI actually put this on my website a long time ago. I'm still not sure if anyone else is using it for a real, production website. http://www.easyautosales.com/register http://www.easyautosales.com/register
- JoachimSchipper 15y agoNice. Note, though, that accurately capturing the colors will let a bad guy brute-force the password one character at a time, which is trivial. Don't use this if you're worried about shoulder-surfers with cameras, or just plain don't use this with important passwords. (Note that switching to a proper cryptographic hash does not stop the above attack.)
- skattyadz 15y agoAnd importantly, you can't rate limit client site JS like you can server-side with captchas etc.
- icebraining 15y agoNote, though, that accurately capturing the colors will let a bad guy brute-force the password one character at a time How so? Since this is generated from the hash, this attack doesn't reveal more than an hash does, and you certainly can't brute-force one char at a a time from an hash.
- CJefferson 15y agoAssuming I record the colours generated when each character is entered, then I have a hash of just the first character. Cracking that is trivial. Then I can go and crack the second character. There might be a tiny amount of fuzzyness if I can't exactly match the first character hash, but it would be fairly close. I suspect it would be fairly easy to write a computer program which even did this automatically, from a recorded video.
- LaaT 15y agoWhy not do this with hieroglyphs instead of colours? I have deuteranomaly and colours don't work for me. I remember reading %10 of male population has some kind of colour deficiency.
- skattyadz 15y agoThat's a nicer idea. Or to generate some kind of character / robot.
- iaskwhy 15y agoEven with a deficiency you would probably be able to distinguish between different colours, right?
- mrleinad 15y agoDeficiency doesn't mean that he sees colours diminished in hue value, but exactly that he wouldn't be able to distinguish between some colours.
- LaaT 15y agoIts name escapes me, there's a website which you enter a url, it goes and fetches the css, changes the colours such that I can't differentiate it from the original but a normal person would. By my wife'a account there are really huge differences between the two. I'll probably not be able to distinguish some colours where the green component makes the difference.
- ydant 15y agoHere's one I've played around with. http://colorfilter.wickline.org/ http://colorfilter.wickline.org/ I'm not really clear on how it or color blindness in general works. So I don't know if finding the filter which makes the image unchanged for me (color-blind) is a good way of representing how the world looks to "normal" visioned people.
- LaaT 15y ago
- TobiHeidi 15y agoI dont think any user will understand it quickly so it would be helpful. nice idea tough just not mass market useable-
- sambeau 15y agoI don't understand what problem this solves. Can anyone explain?
- jawns 15y agoWhen you enter your password in a password field, the characters are obscured, making it harder to tell when you've made a typo. So, if your password is "Humpty Dumpty sat on a wall" and you accidentally type in "Humpty Dumpty sat on a ball" you would immediately realize your mistake, because the password's color signature would be different than what you're used to seeing.
- jawns 15y agoOf course, my preferred solution to this problem is to allow the user to toggle the password field, so that they can view the unobscured text if they wish.
- ColdAsIce 15y agoAnd anybody behind them as well.
- city41 15y agoThat would require the user to be quite vigilante when they are entering a password on a website. Getting up to go to the bathroom could mean someone steals their password.
- qntm 15y agoGetting up to go to the bathroom between typing in the password and hitting Enter?
- burgerbrain 15y agoWhat if you hit the back button until their browser goes back to the login page, likely with the form still filled out?
- steren 15y agoMozilla worked too on visual hashing: https://wiki.mozilla.org/Identity/Watchdog/Visual_Hashing https://wiki.mozilla.org/Identity/Watchdog/Visual_Hashing Chrome extension: https://chrome.google.com/webstore/detail/lkoelcpcjjehbjcchcbddggjmphfaiie https://chrome.google.com/webstore/detail/lkoelcpcjjehbjcchc...
- kyberias 15y agoWhy not just have one symbol (flag?) that is displayed when the passwords match? What is the added value of displaying three colours?
- eieio 15y agoIf I understand correctly, you're talking about confirming whether a password / confirm password box match. The purpose of the three colors is that they are displayed next to the password box every time the user types their password in, providing a visual clue as to whether they've entered their password correctly.
- klez 15y agoI hope your password is not encoded in the javascript. And if the script tries it via asynchronous requests every time you type a character until you give the right password, think about the network overhead involved. And if you use this solution, how do you distinguish between a sloppy user (that recognizes (s)he hit a wrong key and immediately corrects it) and a bot trying to guess a password?
- Maci 15y agoWith more spark line: http://lab.arc90.com/2009/07/09/hashmask-another-more-secure-experiment-in-password-masking/ http://lab.arc90.com/2009/07/09/hashmask-another-more-secure...
- huhtenberg 15y agoI think a better usage would be to show two patterns - one of the password being entered and another for the password on file. Salt the passwords obviously before generating a pattern. The idea is that I have a dozen of passwords, and some I use only when there are stupid password restrictions in place, e.g. "one uppercase letter, one digit, no special symbols". Since these restrictions are not shown on the Login form, it is frequently hard to remember which password I used with this particular site, so having a hint would help a lot.
- stanmancan 15y agoThe idea is nice but in theory but that would be a _huge_ security risk. You'd be providing anyone you know with your encrypted password, as well as the encryption method.
- huhtenberg 15y agoNo, why? The server will send down a hash function, a salt and its version of a password hash. Use something like bcrypt or PBKF2, reduce their output by folding or by funneling through something like CRC to mitigate the risk of brute-forcing. Alternatively, keep salt/hash on the server side and make the client ajax the current hash from the server.
- astrodust 15y agoWouldn't having a "show password" option be a lot better?
- accountoftheday 15y agoThe hieroglyphs from Lotus Notes are rearing their ugly heads in disguise.
- ebzlo 15y agoThis is cool, but ultimately worthless- even detrimental to security. The only problem this could possibly solve is that user has to wait for a reload before trying their password again. For an attacker, this becomes a lot easier break into. Let's suppose the attacker managed to get the exact values of the RGB (perhaps screen shared). He could run a dictionary attack or brute force on the algorithm and wait until he gets a match. This alleviates an attacker from two previous requirements. 1. A salt if all they had was a hash. 2. Hitting a server to check if the password is valid (thereby passing any potential lockouts).