gdm

Add mouse based login to avoid keyloggers

Bug #222329 reported by David Hillshafer
4
Affects Status Importance Assigned to Milestone
gdm
New
Undecided
Unassigned
gdm (Ubuntu)
Confirmed
Wishlist
Unassigned

Bug Description

Key loggers (hardware and software) can easily compromise security. I recently saw one way to thwart key loggers on a secure website. Instead of typing in a user name and password, I had to click it in with my mouse using a virtual keyboard. As added security, the placement of letters and numbers were randomized. So even if the location of my clicks was also recorded, it wouldn't be useful because it would never be the same placement twice. I suggest that any time Ubuntu asks for a password, a virtual scrambled keyboard be an input option. Extending this capability to other applications (like a web browser) would be awesome. This way, if I suspect my machine is compromised or I'm using some else's computer, I can guarantee password security.

Unfortunately, I'm not a programmer, but I'd be willing to help anyone interested in this idea.

Revision history for this message
Kees Cook (kees) wrote :

This has been added to the Security Team's "Wishlist" in the Roadmap: https://wiki.ubuntu.com/SecurityTeam/Roadmap#wishlist

Revision history for this message
Pedro Villavicencio (pedro) wrote :

since it was added i'm marking this as confirmed, thanks.

Changed in gdm:
status: New → Confirmed
Revision history for this message
Sebastien Bacher (seb128) wrote :

The issue is an upstream one and it would be nice if somebody having it could send the bug the to the people writting the software (https://wiki.ubuntu.com/Bugs/Upstream/GNOME)

summary: - Thwarting a Key Logger
+ Add mouse based login to avoid keyloggers
To post a comment you must log in.
This report contains Public information  
Everyone can see this information.

Other bug subscribers

Remote bug watches

Bug watches keep track of this bug in other bug trackers.