Windows Vista Forums
Vista Forums Home Join Vista Forums Donate Vista Tutorials Tags

Welcome to Vista Forums we are your forum to discuss Windows Vista x64 and x86 systems. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

a dumb question: on-screen keyboard...

Closed Thread
 
Thread Tools Display Modes
Old 09-13-2007   #1 (permalink)
David
Guest


 

a dumb question: on-screen keyboard...

would using an onscreen keyboard to type in passwords when on a wifi
hotspot avoid capture by keylogging programs? reason i ask, i was just
reading a Norton email about password security and they mentioned that
one shouldn't log in to a bank site when on those hotspots due to
possible key loggers.

Dave
Old 09-13-2007   #2 (permalink)
David
Guest


 

Re: a dumb question: on-screen keyboard...

oh, and my ING account sign in page has an onscreen keypad for entering
log in info, ostensibly to avoid keyloggers, I believe...

Dave
Old 09-13-2007   #3 (permalink)
Steve Riley [MSFT]
Guest


 

Re: a dumb question: on-screen keyboard...

Keyloggers run on individual machines, not on entire hotspots. The session
between a workstation and the bank's web server is protected with SSL. So if
someone were sniffing traffic from the hotspot, your password would be
protected. However, if you were using some kiosk computer (rather than your
own), then it is possible that keylogging software on that machine could
intercept your password before it gets passed to the SSL encryption. I never
worry about hotspots, because I always use only my own laptop. I do, though,
worry a bit about kiosks.

Onscreen keyboards really don't help here. Sure, they can thwart keyloggers,
but what about screen recorders? What about rootkits or trojans (again,
installed on a kiosk) that can hijack a session after login happens? Public
machines simply present too many risks.

--
Steve Riley
steve.riley@xxxxxx
http://blogs.technet.com/steriley
http://www.protectyourwindowsnetwork.com


"David" <david@xxxxxx> wrote in message
news:57WdnX9LFOxh3HTbnZ2dnUVZ_hKdnZ2d@xxxxxx
Quote:

> would using an onscreen keyboard to type in passwords when on a wifi
> hotspot avoid capture by keylogging programs? reason i ask, i was just
> reading a Norton email about password security and they mentioned that one
> shouldn't log in to a bank site when on those hotspots due to possible key
> loggers.
>
> Dave
Old 09-13-2007   #4 (permalink)
David
Guest


 

Re: a dumb question: on-screen keyboard...

Steve Riley [MSFT] wrote:
Quote:

> Keyloggers run on individual machines, not on entire hotspots. The
> session between a workstation and the bank's web server is protected
> with SSL. So if someone were sniffing traffic from the hotspot, your
> password would be protected. However, if you were using some kiosk
> computer (rather than your own), then it is possible that keylogging
> software on that machine could intercept your password before it gets
> passed to the SSL encryption. I never worry about hotspots, because I
> always use only my own laptop. I do, though, worry a bit about kiosks.
>
> Onscreen keyboards really don't help here. Sure, they can thwart
> keyloggers, but what about screen recorders? What about rootkits or
> trojans (again, installed on a kiosk) that can hijack a session after
> login happens? Public machines simply present too many risks.
>
thanks for the info, Steve! very helpful!

Dave
Closed Thread

Thread Tools
Display Modes


Similar Threads
Thread Thread Starter Forum Replies Last Post
WPF - Possible Dumb Question Chuck B .NET General 1 05-20-2008 03:23 PM
Probably a dumb question but... reaverto .NET General 1 04-09-2008 03:52 AM
Dumb Question 3 Julian Vista General 2 11-27-2007 03:54 AM
Is this a dumb question? Julian Vista General 5 11-27-2007 02:47 AM
Dumb question...RC2 John C. Iliff Vista installation & setup 3 10-07-2006 07:53 PM








Vistax64.com is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50