Registered Member
|
This idea was bring by my low problem with inputting password again. First I input bad password to lock screen (on Plasma) and nothing happens. I must move mouse to re-enable password field. This could be problematic for people without mouse, so my idea was born.
Some hardware may emulate keyboard and try to broke password with brutal-force method. Currently, there is defense method against this attack - add random wait before again write. In some Windows systems, there may be set some requirement to press CTRL+ALT+DEL between password input attempt. Idea is similar. After wrong password typed, user may: a) Move cursor b) Press configured by user (or random) keyboard key combination to re-enable password field. In b) this keyboard key-combination could be displayed on the screen and even could be sound made telling, which key to press. This is must, if you decide to generate random keystrokes. This will protect account, because programmable offense devices could not guess this additional keystroke combination (especially, when it was random; and more important - it can be generated after each failed attempt to provide it).
Lachu, proud to be a member of KDE forums since 2008-Nov.
|
Registered users: bartoloni, Bing [Bot], Google [Bot], Yahoo [Bot]