Scattered

Main Navigation

  • About
  • Blog
  • Reviews
  • Sprout Venture
  • WordPress
    • WordPress Plugins
    • WordPress Themes
  • Contact Me
url

Stop killing your Apps!

I feel obligated to share this with everyone I know again that has an iPhone, iPad or iPod Touch…again! Please stop using the app switcher to…

Read More
aulani-model-overview

Aulani

Our trip to Aulani in Oahu was spectacular, I can’t saw enough great things about that place, it was honestly everything that I’d hoped…

Read More
apple-iphone-5-and-ios6-maps-updates_100402172_m

(My) Defense of iOS6 Maps

iOS6 Maps is not amazing, which is humerously documented here, nor is it great, neither was Google Maps for iOS 3/4/5/6 and I honestly…

Read More

How To Login From an Internet Cafe Without Worrying About Keyloggers

November 24, 2006

“We tested five shareware or commercial keylogging programs: HomeKeylogger 1.70, GhostKeylogger, KG-BKeylogger, Spytector 1.2.8 and ProBot. None of them captured passwords entered using the trick we describe.”

read more | digg story

Rating

Categories Asides

Tags commercials, internet

Logging In...

Profile cancel

Sign in with Twitter Sign in with Facebook
or

Not published

  • 19 Replies
  • 17 Comments
  • 0 Tweets
  • 0 Facebook
  • 1 Pingback
Last reply was May 13, 2011
  1. nstryker
    View November 24, 2006

    copy-paste also works.

    Reply
  2. JaredB
    View November 24, 2006

    But copy/paste from what? If you aren’t typing in any passwords on that system you would have to have them in an unencrypted file on a portable drive (USB or whatever). Then you have even bigger problems to worry about than keyloggers.

    There are apps out there (similar to keyloggers but even easier to write and distribute) that will copy the contents of any files on such a portable drive and store them (or send them over the network) for later perusal. There are also ones that will dump the contents of the clipboard any time something new is added. That, especially in combination with a keylogger, would (I think) render the copy/paste technique insecure.

    Even the technique described here has its issues. They basically recommend switching the focus to something else and typing random gibberish characters in between typing your password, and going back and forth. I think they need to test this on more keyloggers, though, because I’ve personally seen ones that (in addition to recording raw text) will record any time you switch focus to any other element on the screen, and identify it by name (which every text box, form field, etc. will have, as far as the OS is concerned).

    Basically, the summary is that there is almost no good way to be safe on a system you don’t own. I have to get the kids breakfast right now, but I’ll come back later and write my proposal on a system which I think would work very well for public access like this. I’ll either comment here or post it on my blog and trackback.

    Reply
  3. JaredB
    View November 24, 2006

    But copy/paste from what? If you aren’t typing in any passwords on that system you would have to have them in an unencrypted file on a portable drive (USB or whatever). Then you have even bigger problems to worry about than keyloggers.

    There are apps out there (similar to keyloggers but even easier to write and distribute) that will copy the contents of any files on such a portable drive and store them (or send them over the network) for later perusal. There are also ones that will dump the contents of the clipboard any time something new is added. That, especially in combination with a keylogger, would (I think) render the copy/paste technique insecure.

    Even the technique described here has its issues. They basically recommend switching the focus to something else and typing random gibberish characters in between typing your password, and going back and forth. I think they need to test this on more keyloggers, though, because I’ve personally seen ones that (in addition to recording raw text) will record any time you switch focus to any other element on the screen, and identify it by name (which every text box, form field, etc. will have, as far as the OS is concerned).

    Basically, the summary is that there is almost no good way to be safe on a system you don’t own. I have to get the kids breakfast right now, but I’ll come back later and write my proposal on a system which I think would work very well for public access like this. I’ll either comment here or post it on my blog and trackback.

    Reply
  4. nstryker
    View November 24, 2006

    i copy/paste letters/numbers/symbols from the test on various websites.

    Reply
  5. FreePress Blog
    View November 24, 2006

    Safely Using Untrusted Computers…

    Inspired by this post from Dan that links to a suggestion for keeping your passwords safe when using a computer that isn’t your own, I’ve decided to post on my idea for safe remote access, even though I haven’t actually implemented it…

    Reply
  6. JaredB
    View November 24, 2006

    Good point, I didn’t think about that, but it might be difficult to find some of the more obscure characters, unless I guess you have a page somewhere that just has every character already out there, copy/paste ready.

    Reply
  7. FreePress Blog
    View November 24, 2006

    Safely Using Untrusted Computers…

    Inspired by this post from Dan that links to a suggestion for keeping your passwords safe when using a computer that isn’t your own, I’ve decided to post on my idea for safe remote access, even though I haven’t actually implemented it…

    Reply
  8. The Mike Abundo Effect » Anti-Keylogger Trick
    View November 25, 2006

    [...] (Via Dan Cameron.) Tag: Security Related posts: Filipino Bible-Thumpers Dub Fag Antichrist for Reposting British Photos [...]

    Reply
  9. JC John SESE Cuneta
    View November 26, 2006

    Will not work if the person who installed the keylogger is using a more sophisticated keylogger application.

    I saw a couple of freeware and shareware keylogger apps that can track everything.

    The simplest of these apps, I was able to figure out the password typed in 30 mins after reading the log file. One good way is to simply duplicate the process as is written in the log file.

    Now it is up to the person if s/he will be patient enough to decode the numerous random and not random clicks, tabs, typing, etc.

    Simply, keyloggers will log where and when you clicked and/or tabbed where and when, even if you clicked on another browser window, or tabbed to another browser-tab. If you scroll, typed in notepad, typed in command line, run, etc.

    Oh, basically, there is really no other way to be secured in a public terminal unless you can do a restore of the system from it’s very first state when it was first booted after a fresh reformat and installation.

    That’s why I only trust a very few iCafes in the Metro Manila, and I don’t log in sensitive stuff at terminals that I can easily install and edit the startup system.

    ^_^

    Reply
  10. JC John SESE Cuneta
    View November 26, 2006

    Btw, I forgot to mention. Don’t trust too much on “Copy & Paste”. There are keylogger applications than can log what you copied from what window, what site, when, and the exact order of your copy and pasting, as well as which window, tab, application, mouse move, clicks, etc. etc.

    These apps are out there, these keylogger people just have to be persistent to find these apps we tested. They are few, but once you have it, keylogger galore. Freeware and Shareware.

    Now for a serious person, there are professional grade keyloggers that will do much more than that, and sadly, these pro-keylogger apps can be easily cracked, so well… ;) Be-friend a public terminal owner (iCafe owner that is), like what I do, so you’ll gain access to its restore system (if they use one), or you’ll be allowed to touch and make changes to their whole system (provided you know where to look for and what stuff needs to be checked).

    It’s hard. But so far, I haven’t been victimized by keyloggers.

    Those are what I can share ^_^

    Reply
  11. JC John SESE Cuneta
    View November 27, 2006

    Will not work if the person who installed the keylogger is using a more sophisticated keylogger application.

    I saw a couple of freeware and shareware keylogger apps that can track everything.

    The simplest of these apps, I was able to figure out the password typed in 30 mins after reading the log file. One good way is to simply duplicate the process as is written in the log file.

    Now it is up to the person if s/he will be patient enough to decode the numerous random and not random clicks, tabs, typing, etc.

    Simply, keyloggers will log where and when you clicked and/or tabbed where and when, even if you clicked on another browser window, or tabbed to another browser-tab. If you scroll, typed in notepad, typed in command line, run, etc.

    Oh, basically, there is really no other way to be secured in a public terminal unless you can do a restore of the system from it’s very first state when it was first booted after a fresh reformat and installation.

    That’s why I only trust a very few iCafes in the Metro Manila, and I don’t log in sensitive stuff at terminals that I can easily install and edit the startup system.

    ^_^

    Reply
  12. JC John SESE Cuneta
    View November 27, 2006

    Btw, I forgot to mention. Don’t trust too much on “Copy & Paste”. There are keylogger applications than can log what you copied from what window, what site, when, and the exact order of your copy and pasting, as well as which window, tab, application, mouse move, clicks, etc. etc.

    These apps are out there, these keylogger people just have to be persistent to find these apps we tested. They are few, but once you have it, keylogger galore. Freeware and Shareware.

    Now for a serious person, there are professional grade keyloggers that will do much more than that, and sadly, these pro-keylogger apps can be easily cracked, so well… ;) Be-friend a public terminal owner (iCafe owner that is), like what I do, so you’ll gain access to its restore system (if they use one), or you’ll be allowed to touch and make changes to their whole system (provided you know where to look for and what stuff needs to be checked).

    It’s hard. But so far, I haven’t been victimized by keyloggers.

    Those are what I can share ^_^

    Reply
  13. What is a Keylogger?
    View May 23, 2007

    You could just cut and paste characters from any website, one by one. You actually went and tested 8 apps to come to the conclusion that they only do what they are supposed to do (capture keystrokes)? It should have been obvious.

    Reply
  14. KSINDGA
    View July 18, 2008

    Copy/paste can be catched.
    Go to a website with the alphabet and all chars and numbers.
    Lets say your password is Maple.
    Copy/paste the whole alphabet/nubmers/symbols and WITH YOUR MOUSE, delete all the symbols which aren’t ‘M’.
    Do the same about ‘a’.
    And about all other chars.

    Reply
  15. KSINDGA
    View July 18, 2008

    Copy/paste can be catched.
    Go to a website with the alphabet and all chars and numbers.
    Lets say your password is Maple.
    Copy/paste the whole alphabet/nubmers/symbols and WITH YOUR MOUSE, delete all the symbols which aren’t ‘M’.
    Do the same about ‘a’.
    And about all other chars.

    Reply
  16. hanxiaoniu
    View May 13, 2011

     http://www.coachfactorystoresoutlet.com
    Listen breathing like too long silence.

    Reply
  17. Dricoon_58
    View October 9, 2010

    guys if u type really faster than keylogger will be unable to capture all keystroke technically but possibilities of being safe r less….

    Reply
  18. JB
    View October 9, 2010

    LOL

    Reply
  19. JB
    View October 9, 2010

    LOL

    Reply
NexGen Wars » « Black Friday ‘06
avatarpeirphotoIMG_20596429333409_3c0c250f65_bIMG_1761
prev next

Dan Cameron

I work with awesome people at Sprout Venture, a business that builds web solutions for businesses worldwide. We’ve been focused on WordPress development and design since I started the business.

I have a few open source projects, including some popular WordPress plugins.

If you’re in need of some web development, web design or custom WordPress plugins and/or themes contact me, I’ll be happy to discuss it with you.


Aside from managing my business: I play golf at local courses in Ventura, CA, play softball on the weekends but enjoy the majority of my time with my wild kids and wonderful wife.

  • Sprout Venture
  • Twitter
  • Facebook
  • WordPress
  • Github
  • Stack Overflow
  • LinkedIn
  • Flickr
  • Music

Asides

  • External
  • Google Maps for iOS
  • Skepticism enjoins scientists — in fact all of u…
  • Fix for iOS6 Beta 3 not Sending or Receiving Group Messeges (MMS)
  • Keynote Prototyping Templates
  • No Android for You!

Formats

  • Link
  • Quote

Navigation

  • About
  • Blog
  • Reviews
  • Sprout Venture
  • WordPress
    • WordPress Plugins
    • WordPress Themes
  • Contact Me

Recent Posts

  • Stop killing your Apps!
  • Google Maps for iOS
  • (My) Defense of iOS6 Maps

Recent Comments

  • Todd F on Dotster Not Recomended
  • EmeraldBot on Linux vs. Mac
  • DariusJaruga on Display a loading image until the page completes loading
  • @dancameron on (My) Defense of iOS6 Maps
  • @dancameron on (My) Defense of iOS6 Maps

Copyright © 2012  ·  Scattered