5 ms·
Yes! I have been wanting this forever. Keys are in too predictable a position
by jslezak 2y ago
Yes! I have been wanting this forever. Keys are in too predictable a position
- all2 2y agoThere were, for awhile, some security systems had on-screen keyboards that would change layout on every key press.
- stoneman24 2y agoI think that this is an attempt to stop the “clean key” problem. Security system keypads (especially outdoor ones) tend not to be cleaned, so as time passes, it is easy to spot the dirty keys. Dirty keys are not being pressed and are therefore not in the passcode. So look for the clean keys and try combinations from there. In a 4 digit (0-9) keypad, knowing the clean numbers drops the possible codes from 9999 to 24 (if my early morning math holds up). Also helps the issue of someone looking over the shoulder of a valid person. Chances are they are just seeing the position and not the character pressed. So the keyboard changes and you actually need to know the character not just the old position.
- m463 2y agoAlso spy robots with thermal imaging eyeballs.
- qrobit 2y agoIt would be 24 if all digits are distinct It actually drops from 10^4=10000 to 4^4=256 combinations
- twnettytwo 2y agoIf they aren't distinct, you wouldn't have 4 clean buttons, but just 3 - in which case we also know the repeating digit repeats exactly once and we get 12x3 (36) possible combinations. With two clean buttons, it's 6 (if both repeat) + 4 (if only one repeats) = 10 and if there's 1 that's just one, and a terrible password.
- penteract 2y agoWith 2 clean buttons, there are 4x2 ways for only 1 to repeat, giving 14 combinations in total.
- karencarits 2y agoI guess you would be able to count the number of clean keys and thus know both the number of distinct digits and the digits (but not the order nor which digit that's repeated)
- bluGill 2y agoThe number that is repeated is likely to be dirtier than the numbers that are not so you get that information too.
- chatmasta 2y agoI encountered a case of this in college, where there were four clean digits - a tough task to be sure! But fortunately the digits happened to be the same set of digits that comprised the room number. It took two guesses, because there was a twist - the combination was the room number, backwards.
- Modified3019 2y agoInteresting. This would also stop keypress extraction via analyzing audio.
- Terr_ 2y agoHmm... It may still be vulnerable if: 1. You have lots of spy-data samples that reveal which physical key is pressed (perhaps they sound different) and the precise timing of those strikes, but you don't know what scrambled numbers were actually being shown. (And it's always the same code.) 2. The trick is that users take longer to press a number when it's displayed far away from its "normal" position, because they had to seek longer to find it. 3. This means you can infer the true numbers based on how quickly or slowly presses happen versus which physical key is struck. For a simple example, assume a two-digit code where there are nine keys. If the fastest first press is always the top left corner, and the fastest second press is always the middle, we can guess the code is either 15 or a 75, depending on if the user is accustomed to phones or keyboard numpads.
- Terr_ 2y agoP.S.: On reflection, I could probably have shortened all that by describing it as a "timing attack" [0] except in meat-space. One mitigation might be to get the user to enter digits at a consistent pace, by forcing a delay between showing the random layout versus accepting a button press. There would need to be some penalty for early presses, to keep lazy users from just tapping the desired button repeatedly until it became active.
- sen 2y agoIt’s still a relatively common thing for pin-coded door/gate security.
- Cthulhu_ 2y agoThis would be an interesting one to integrate into password entry forms... although you'd need to show the randomised keyboard layout on screen. Or have a keyboard with oled or e-ink keys, like the Optimus Maximus [0] promised to deliver. It's kinda weird that nobody else seems to have picked up on this concept since then. Probably just impractical or too expensive. I read that its patents expired in 2016; around 2015 there was a concept for an e-ink button keyboard, but that site is now a plain gambling ad. There's also https://www.nemeio.com/ https://www.nemeio.com/ that still works, but its buttons look like sunken screens under plastic domes. [0] https://en.wikipedia.org/wiki/Optimus_Maximus_keyboard https://en.wikipedia.org/wiki/Optimus_Maximus_keyboard
- hargup 2y agoI have seen this with some of the card swiping machines in India.
- julian_t 2y agoHad this at an ATM recently, and it took a couple of tries at my PIN before I looked at the keypad and realized what was going on. One more wrong PIN and I could have lost my card.
- pandemic_region 2y agoI occasionally still get this in certain petrol stations. Always catches me off guard.
- MrJohz 2y agoA number of countries use this when giving your pin for a credit card or similar (I've noticed it in both Greece and India). I can't help but feel like it's less secure than the default layout - I'm quite good at hiding my PIN and typing quickly, but when the positions of the numbers are randomised, I feel like I practically end up saying my PIN out loud as I try and remember it.
- brokenmachine 2y agoMy bank does this, you can see it at https://www.ing.com.au/securebanking/ https://www.ing.com.au/securebanking/ It also takes ~5s to render the page on my PC, no idea WTF it's doing during that time, probably mining crypto. Hmm actually, it doesn't rearrange on every digit, it's a static but random layout every time you go to that page.
- _yb2s 2y agoExactly, a key should never be in the same place twice in a row- that's just wasted movement that could be better optimized. Letters the computer predicts you probably won't use should automatically disappear, and be replaced with numerous copies of others based on the things it thinks you will type. We should extend this concept of constant automatic optimization to all aspects of everyday life- for example your workplace location should physically relocate each day to an optimal location based on where each person coming in that day lives. An algorithm should tell you where to put away the dishes in your kitchen based on a constantly changing optimization algorithm, so that your dinner plates are in a different cabinet each day. Language itself should be radically redesigned daily to keep it optimal, with changelogs pushed out to be learned and memorized each morning before communicating with anyone.
- inetknght 2y agoA good part is that it will do nothing to improve security and will actively harm peoples' ability to type things correctly, and the best part is when it makes its way into scientific literature and algorithms. Good luck reproducing that which was entered incorrectly!
- _yb2s 2y agoPresumably if something is sufficiently impossible to interact with in any capacity both for the intended audience and nefarious actors, it is also "secure." For example, if your computer keyboard layout is scrambled through a one time pad, where no copies exist except the internal one, inputting non-random data of any kind would be provably impossible. Air gapping is a legitimate security technique. However, in this case the air gap would be between the ears of whoever designed it.
- fuglede_ 2y agoOne way to avoid this element of surprise, for those who do not enjoy surprises, could be to have only a single key whose action upon clicking would simply be the most probable next action.