<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: How to resist keyloggers</title>
	<atom:link href="http://www.securityteacher.com/2007/10/10/security-tip/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.securityteacher.com/2007/10/10/security-tip/</link>
	<description>Internet Security Tips and Advice</description>
	<lastBuildDate>Thu, 22 Jan 2009 18:13:06 -0600</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.6</generator>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
		<item>
		<title>By: Igor Pankov</title>
		<link>http://www.securityteacher.com/2007/10/10/security-tip/comment-page-1/#comment-194</link>
		<dc:creator>Igor Pankov</dc:creator>
		<pubDate>Wed, 18 Jun 2008 13:43:09 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityteacher.com/2007/10/10/security-tip/#comment-194</guid>
		<description>to NSR: Depending on the keylogger app, mouse clicks can also be captured. Web-based virtual keyboards are more isolated from this threat, however, and that was my point in the article – to chose the best option amongst poor alternatives.

Igor Pankov,
Agnitum</description>
		<content:encoded><![CDATA[<p>to NSR: Depending on the keylogger app, mouse clicks can also be captured. Web-based virtual keyboards are more isolated from this threat, however, and that was my point in the article – to chose the best option amongst poor alternatives.</p>
<p>Igor Pankov,<br />
Agnitum</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: NSR</title>
		<link>http://www.securityteacher.com/2007/10/10/security-tip/comment-page-1/#comment-189</link>
		<dc:creator>NSR</dc:creator>
		<pubDate>Tue, 17 Jun 2008 15:15:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.securityteacher.com/2007/10/10/security-tip/#comment-189</guid>
		<description>This method is NOT secure. Software keyloggers can also detect mouse clicks so they would log something like this:

-------------
MYPA *left mouse click* qwertradsffaas837aefud *left mouse click* SSWORD
-------------

And I think software keyloggers are more common than hardware ones since these ones costs money (and some of them can be easily detected just by looking for something strange on the wire from the keyboard to the motherboard) and the first ones can be obtained for free on the internet and installed by some random kid. Just imagine the typical cyber-cafe and you&#039;ll understand what I mean :D

The only methods to securely insert a password in an insecure environment I can think of are these:
-Use the &quot;On-Screen Keyboard&quot; under &quot;Accessibility&quot; (Microsoft Windows) or the web page you say. The first one is more secure since with the second one you have to copy and paste, so that information can be stored by the keylogger if it supports this feature.

-Type random characters anywhere and then copy and paste them one by one with your mouse in the user/password field (not with &quot;shift+direction keys&quot;). You can also paste fake characters and then left click (so they don&#039;t know where that vertical bar that appears when you type is) and delete them. This way, and if you don&#039;t paste the letters/numbers/symbols in order, even if they can see what did you copy or paste it will be really difficult to reconstruct your password if it isn&#039;t something logic (random characters instead of the name of your favorite football player) and it&#039;s long enough.

There&#039;s also the problem that some software keyloggers also can take screenshots every certain ammount of time. Due to resources and hardware capacity limits it is usually set to take one every X minutes though, so that souldn&#039;t be a problem with the methods I say since they will never see every character you copy and where do you paste it, and also remember that the password field usually only shows ***. Also there are ones which can specify the mouse position (x,y) in the moment of the click, but that is just too paranoid and I don&#039;t think the everyday lamer who install a keylogger on your cyber-cafe will use that feature and will spend hours to guess where the mouse was and reconstruct what you did.

And of course all that is meaningless if you don&#039;t log out after using the service and deleting the cookies/browser/windows cache after using it or if you don&#039;t log in using the ssl option.


PS: There are other methods to obtain passwords and usernames such as cameras and that sort of stuff.
PS2: It is also recomended to do that with the username, since it can be bruteforced to obtain the password or used to track your activities on the internet and obtain personal data you post on the internet. Trust me, with only an username you can even obtain a photo of the person and also lots of information in forums and so on...</description>
		<content:encoded><![CDATA[<p>This method is NOT secure. Software keyloggers can also detect mouse clicks so they would log something like this:</p>
<p>&#8212;&#8212;&#8212;&#8212;-<br />
MYPA *left mouse click* qwertradsffaas837aefud *left mouse click* SSWORD<br />
&#8212;&#8212;&#8212;&#8212;-</p>
<p>And I think software keyloggers are more common than hardware ones since these ones costs money (and some of them can be easily detected just by looking for something strange on the wire from the keyboard to the motherboard) and the first ones can be obtained for free on the internet and installed by some random kid. Just imagine the typical cyber-cafe and you&#8217;ll understand what I mean <img src='http://www.securityteacher.com/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>
<p>The only methods to securely insert a password in an insecure environment I can think of are these:<br />
-Use the &#8220;On-Screen Keyboard&#8221; under &#8220;Accessibility&#8221; (Microsoft Windows) or the web page you say. The first one is more secure since with the second one you have to copy and paste, so that information can be stored by the keylogger if it supports this feature.</p>
<p>-Type random characters anywhere and then copy and paste them one by one with your mouse in the user/password field (not with &#8220;shift+direction keys&#8221;). You can also paste fake characters and then left click (so they don&#8217;t know where that vertical bar that appears when you type is) and delete them. This way, and if you don&#8217;t paste the letters/numbers/symbols in order, even if they can see what did you copy or paste it will be really difficult to reconstruct your password if it isn&#8217;t something logic (random characters instead of the name of your favorite football player) and it&#8217;s long enough.</p>
<p>There&#8217;s also the problem that some software keyloggers also can take screenshots every certain ammount of time. Due to resources and hardware capacity limits it is usually set to take one every X minutes though, so that souldn&#8217;t be a problem with the methods I say since they will never see every character you copy and where do you paste it, and also remember that the password field usually only shows ***. Also there are ones which can specify the mouse position (x,y) in the moment of the click, but that is just too paranoid and I don&#8217;t think the everyday lamer who install a keylogger on your cyber-cafe will use that feature and will spend hours to guess where the mouse was and reconstruct what you did.</p>
<p>And of course all that is meaningless if you don&#8217;t log out after using the service and deleting the cookies/browser/windows cache after using it or if you don&#8217;t log in using the ssl option.</p>
<p>PS: There are other methods to obtain passwords and usernames such as cameras and that sort of stuff.<br />
PS2: It is also recomended to do that with the username, since it can be bruteforced to obtain the password or used to track your activities on the internet and obtain personal data you post on the internet. Trust me, with only an username you can even obtain a photo of the person and also lots of information in forums and so on&#8230;</p>
]]></content:encoded>
	</item>
</channel>
</rss>
