Thursday, September 18, 2008

virtual keyboard - Is it safe ????

The virtual keyboard of citibank, icici and a whole lot more secure password entries are not to my liking. Well am I a hacker, is not known !! But then this i feel is not secure one bit.
Hey guys do u remember why the password keyd in is shown as "****". Bull shit right. It is simple because an onlooker shouldn't see the password you are typing. All right! accepted tat you are trying to prevent the internet hackers from getting your data through keyboard sniffers. And it absolutely ok for a passby person who peeks - passby peeker* or can make out from the huge fonts in the virtual keyboard, even at miles from your desktop.
Ok Fine we close our monitor while keying in the password, so are you trying to say that if keyboard can be sniffed, can't the mouse be sniffed!!!!!!!

Although not an hacker and a great computer geek, i can clearly see many programs that i have come across that can pin point the cursor location on the screen.

Ok Cool! So you want to say that by swapping the keypad keys everytime we access the login page you are creating some secure stff. You must be kidding right :P

So all that it would probably take an internet hacker ( Not a passby peeker* ) is to take a "print screen" command equivalent when the page gets loaded and save the data onto some file and then capture his mouse click location x,y co-ordinate. And with this data he can even manually find out what location you have clicked the mouse in and what is the key under it!!!!

So whats the logic??? Neither the passby peeker not the great hacker are prevented from password theft. The conventional **** would be better. It is people around you whom you have to be careful of :P

No comments: