Re: [Full-disclosure] Most common keystroke loggers?



Kyle Lutze wrote:
say somebody's password is foobar, on screen there would be a page that shows the new alignment of characters,such as saying a=c, d=3, b=z, etc. so instead of typing foobar the password they would type in for that session would be hnnzck.

The next time the screen came up, it would be a=n, b=l, etc. and the password they would enter would be something else. Then, if the computer had a keylogger, not too much anybody could do with that info.

If the only threat in the world were keyloggers, there are many schemes you could use. My main point is that if your computer is fully compromised and the attacker can adapt, there's no scheme you can up by adding just software to the existing client computers that will help.


Second, the scheme you just proposed is a monoalphabetic substitution cipher. The are considered somewhat weak, i.e. they print them in the newspaper to be solved with a pencil during your communte.

						BB
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



Relevant Pages

  • Re: FOOL OR FASCIST? Andy Burnham, Under Secretary of State, Home Office, London SW1
    ... while private organisations will be able to conduct verification checks ... I am reminded of a new scheme adopted at the local primary ... As I had with the previous child been persuaded against my ... teacher kept asking, kept saying she couldn't complete the forms, was ...
    (uk.politics.misc)
  • Re: who needs scheme when you have happs?
    ... I am saying that your application is likely to be well ... within the constraints required for HAppS to make sense for it. ... Well, PHP, Ruby, Python, and Perl have all gotten their fame from web ... I just find it odd to make the barb in a Scheme forum, ...
    (comp.lang.scheme)
  • Re: OT: Happy Plumber
    ... I remember Veggie Dave ... saying something like: ... I've seen some dreadful cowboy work, ... If such a scheme goes ahead, I can see a direct parallel to Pt P ...
    (uk.rec.motorcycles)
  • Re: Can we obtain securer data encryption if we encrypt the data once more?
    ... >> Or there is mileage in this adversary's scheme. ... >> I'm not saying it isn't a daft idea. ... and $E'$ for the second; the composed scheme is then ... same key as the second cipher. ...
    (sci.crypt)