Let A Picture Be Your Password With ObPwd

We all know how difficult it can be to keep your online accounts safe and how hackers are always trying to break into accounts with dictionary attacks. This is why you should never use short simple passwords that you can find in a dictionary such as your name, the name of your partner, child, dog, whatever. You might think that having PASSWORD as your password is hilarious but it isn’t hilarious when you’re locked out of your online banking account.

But some people still persist in doing it nevertheless. One of my former bosses from years back used to have a password which was “123″ – and he was in charge of the payroll! I could have logged in under his name anytime and given myself a payraise!

But now two university researchers have proposed a different approach to the way we make passwords – by using a picture, song or video clip instead of a text password as a “digital identifier”. The software is called “ObPwd”.

Here’s how it works. First, I need to warn you that this is still all very experimental so if you want to try it out, don’t entrust any sensitive web accounts to this. OK with that disclaimer out of the way, go to their website and install the Firefox extension or the Windows application.

Now from what I can gather, it works like this – you can either choose:

  • a selection of text
  • a photo / other image
  • a song
  • a video clip

I chose an image to try it out. I tried the video clip by going to YouTube but I couldn’t get it to work because right-clicking on the video clip didn’t bring up the ObPwd option. Likewise, if you want to use a song, the song needs to be online and if you upload a MP3, isn’t that illegal file sharing ?! So I just tried an image.

So I went to one of my favourite art websites, the Rijksmuseum in Amsterdam and I decided to try out ObPwd on one of the paintings. Now just say for a moment that I wanted to change my Gmail password. Instead of using password generator tools like PassPub, Password Chart etc. to generate another text password which will written down and stowed away in my encrypted folder, how about getting ObPwd to take that painting in the Rijksmuseum and generate an unique password off of that?

So just take your photo, painting, image, whatever, right-click, choose the “Get ObPwd from Image” option and this comes up :

use image as password

What is in the box is your password. Now everytime you click on the image, you will get the same password so in theory you don’t have to write your password down – you can just keep coming back to the image, right-click, copy-paste your password and log into your web account. Or if you do write it down, you can come back to the image and right-click to get a reminder if you forget the password.

Now how is this more secure from a security point of view? Well for a start, assuming you don’t use an obvious photo (and you don’t publicise what image you are using), there’s no way for a hacker to know what photo / image you are using for your password. Plus “Ja4VIWSIiLKe” is not exactly a common dictionary entry is it? So just choose an online favourite image, one that no-one else knows you like, right-click on it, generate your password and hackers suddenly have a hard time working out what your password is.

I’m going to try this out with a song and a video clip because I am intrigued to know how this works but as I said, how I can do this without illegally uploading music to the net I don’t know (I’m a very law-abiding citizen, oh yes). Plus most video clips have Macromedia installed in them which makes it impossible to get the ObPwd right-click option to come up.

If anyone installs ObPwd and gets the video clip one to work, let me know in the comments how you managed it.

[Rating=4]

By) Mark O’Neill is a blogger, professional freelance writer and the editor of Make Use Of. Check out his personal blog at BetterThanTherapy.net

Tagged:

Mark O'Neill

Mark O'Neill is the managing editor of MakeUseOf.com

Similar Stuff

The comments were closed because the article is more than 90 days old.

If you have any questions related to stuff mentioned in the article or need help with any computer issue, just ask it on MakeUseOf Answers.

  • Rehan

    The URL for the image (and therefore your password) will be in your browsing history. It’s not right upfront and obvious but easy to find if you know that your victim is using this program.

  • http://www.murphyzville.com/blog/ murphyz

    Knowing my luck I’ll choose my favourite image, use if for a few years on all of the websites I sign up to – and then the image will disappear from the website I was taking the image from – along with my password.

    • http://makeuseof.com Aibek

      LOL :-)

      Yeah, it might be a good idea to doanload and save the image on your PC as well.

  • Clancolin

    I like this idea and I’m going to give it a go. As for images disappearing after a couple of years, who keeps passwords static for that length of time? That is asking for you secret stuff to be nabbed.

    In extremis, you could use a logo image perhaps, because even if the logo is updates suddenly, then the one you used should still be in the Wayback Machine, shouldn’t it?

    • http://makeuseof.com Aibek

      Funny, I thought the same thing. As long as not many people know about this program one way to use it would be to use the logo of the service/site to generate the password for it.

  • http://www.geekishblog.com Saad Ibrahim

    How does this works? I Guess it creates a random string out of the md5 hash or something of that image/video/mp3

  • Tolli

    I have a few concerns with this. First, it displays your password in plaintext on the screen. However, the password is long enough that it would be very difficult for a bystander to memorize the password in the short time it is on the screen. My second concern is that you copy the password to the clipboard. If someone saw what website you were at and your username they could simply paste the password in to the website. (these are mostly an issue when using a public computer).

  • http://n-70.info ShoukaT

    oh very cool man….

    things getting more and more secure…