Shocker: Touchscreen smudge may give away your Android password pattern
Fast food connoisseurs should pay special attention here -- according to a recent paper by the University of Pennsylvania, Android users are inadvertently leaving their nine-dot lock patterns in the open, courtesy of their fingers' oily smear on the screen. Specifically, the study on potential "smudge attacks" found that partial or complete patterns could be easily retrieved -- even with added noise on the display or after incidental clothing contact -- by using various lighting and camera orientation settings for the smear analysis. Should we be surprised? No. But should our phones be getting Froyo sooner for the extra PIN and QWERTY password options? Hell yeah.
























@Dafrety You are absolutely right. But if the article mentioned that, it would spoil all the FUD goodness.
where did that man get a white iphone 4?
Most people use their phones, for messaging and other things after they have entered their password, so this is a bit of a stupid story really.
I'm pretty sure the white iPhone 4 is actually a black iPhone 4.
Because.... I remember a while back someone from Engadget (likely the author of this post included) ordered a white iPhone 4 conversion kit from China or something. But, I could be wrong.
if the smudge is that visible and you don't wipe your a slob and a dumb ass
I bet somebody wolfed down a man sized man shank of Osso Bucco before smearing up that Dell Streak. Mmmm, bone marrow.
Well, isn't this kind of mood if you use your phone / device like any normal being on the planet?
I mean, I usually send at least a dozen SMS / texts a day which happens to cover the exact same area with smudges from my fingers as the password (on the iPhone at least).
what idoit uses the most guessable move finger along the edges unlock on my g1 i used a fracking fractal pattern its funny how simple minded the guy with the dell was a 5 yr old could crack it without the smudges
oh dear go whay will they think of next?!
shocker: power buttons turn on phones =="
@FC1032
*what
iPhone's Can have alphaneric pins (letters and numbers for those that don't know) up to 26 digits long... How's That for security
Sent From My iPhone 4 32GB
@Island219 my phone can make calls
and yet my DROID still doesnt have Froyo.....
Am I the only one on here that doesn't pin-lock his phone? I feel that it's more of a hassle to unlock it every time I wish to use it than the tiny risk that someone else will get their hands on it. I mean, how would they? It's in my holster unless I'm home or I'm actively using it, so for whom exactly is the pin set-up for? NO ONE.
Am I missing something here?
@darex I work with special needs kids, and it's nice being able to dump my phone wherever I like without the risk of someone picking it up and looking through my messages, web history and contacts. You may keep your phone with you all of the time, but that's not a luxury everybody can afford.
Ahh its true..
Figured out an old friends lock code while she wasn't looking. And she loves taking "pictures "... :D
That was a good day my friends.
I've done this many times to others and now have to wipe my screen every time I unlock my phone.
anyone remember MacGyver?
Richard did you photoshop the black button on your white Iphone mod out or something?
man, must be a slow news day
Just have a 3 stage pattern. (enter different patterns 3 (or 2) times.
SMH....if you are SERIOUSLY worried about this...take your phone, shove it up your butt and jump off a bridge.This was brought up when I got my first droid and i purposely attempted to recreate with a friend. we swapped phones and neither of us were able to use the smudges and we're both I.T Analyst so we know a few tricks. NON ISSUE!!!! I
Maybe just make a smaller grid and make every code require hitting every button. That way, just knowing where the fingerprints are is meaningless, since they will always be on every button.
I blame it on McDonalds.
Good thing I wipe my screen multiple times every day
Clean your screen with your shirt. Problem solved. Durrrr
I still want an unlocked Streak.
Easy enough to solve, buy a screen protector and whipe it clean every once in a while. If that's too pricey for ya use some hard see-through tape and stick it on there...i've done it with my Nokia cell and it simply works!
I use a phone with a physical keyboard so I might not know what I'm talking about, but what if you make the very last 'point' of the pattern the same as the very first point? If the pattern is a giant loop then it might be hard to decipher any sort of order from the numbers.
Sure there's a finite number of orderings, but still... almost as good as using pin? I dunno.
Uh wait for froyo? Is my Droid X the only one that has PIN options now?
I circumvent this problem by not using a pattern. I did one, got it to work a few times, and then suddenly my phone tells me the pattern I'm doing isn't right. It was a Z - impossible to screw up. Had to log in with my gmail information and give up on the pattern lock.
Android has passwords that you type with letters, the pattern, and a number password. Time for you to learn more about android.
@blacksilva Only on 2.2+.
@Richard Lai Third party apps.
Would have trouble with mine, I often make mistakes on my pattern :P
HEY!!!! where did you get the WHITE ONE????
I see this comes from the University of Duh! (A sister college to D'OH U.) Um... anyone ever heard of wiping the smudges from the screen? I do that all the freaking time.
Meh. I use swype for my keyboard... good luck trying to figure mine out.
AHH! That's how everyone knows my password! Wish it didn't smudge.
Why not just randomize the placement of the digits on the screen each time?
Kind of a pain - but - hey ... liberty ain't free and all.
You know you could just clean the screen. Or do what I do. Put it in wrong the first few times before entering the correct sequence.
Wait a paper just got released on this topic... are you kidding me, someone did a study on this. The first time i ever saw an android phone that my friend had i noticed the smudge and unlocked it. That was months ago. If i had have known it was worth writting a paper about i would have.
My Android handset has way more smudges on it than that.
I don't even lock my phone with a password, I always have it on me in public and I trust my roommates not to use it. If I lose it, I'd be more mad about losing the phone and would just change my passwords, as I don't have any critically sensitive material on the phone. I always secretly laughed at my roommate unlocking his phone all the time... to think of all the time wasted IMO.
If you lose your phone you are just careless, most of the time...
Wait, most android devices just have a random lockout of dots?
What idiot thought that was a good idea?
Isn't this totally EXACTLY the same as on iPhone ?
(but since it is a slightly negative article and we never are too carefull you decided not to associate the name iPhone with "oily smear on the screen")
You really are @Fox News level of biased engadget it's scary you do it on EVERY level.
how bout a shake to unlock? remember your intensity.. like a morse code type of encryption... like a secret knock on a door? easy fix i think.