{"id":307002,"date":"2021-07-23T17:41:33","date_gmt":"2021-07-23T14:41:33","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/how-android-unlocking-patterns-could-be-made-more-secure\/"},"modified":"2021-07-23T17:41:33","modified_gmt":"2021-07-23T14:41:33","slug":"how-android-unlocking-patterns-could-be-made-more-secure","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/how-android-unlocking-patterns-could-be-made-more-secure\/","title":{"rendered":"#How Android unlocking patterns could be made more secure"},"content":{"rendered":"<p>&#8220;<strong>#How Android unlocking patterns could be made more secure<\/strong>&#8221;<\/p>\n<div>\n<div class=\"article-gallery lightGallery\">\n<div data-thumb=\"https:\/\/scx1.b-cdn.net\/csz\/news\/tmb\/2018\/1-android.jpg\" data-src=\"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2018\/1-android.jpg\" data-sub-html=\"Credit: CC0 Public Domain\">\n<figure class=\"article-img\"><img loading=\"lazy\" decoding=\"async\" src=\"https:\/\/scx1.b-cdn.net\/csz\/news\/800a\/2018\/1-android.jpg\" alt=\"android\" title=\"Credit: CC0 Public Domain\" width=\"800\" height=\"518\"\/><figcaption class=\"text-darken text-low-up text-truncate-js text-truncate mt-3\">\n                Credit: CC0 Public Domain<br \/>\n            <\/figcaption><\/figure>\n<\/div>\n<\/div>\n<p>Users of Android devices can unlock the display by entering a pattern. This function is convenient and thus popular\u2014however, less secure than locking with a PIN. An international research team thus recommends implementing a blocklist on Android devices that prohibits the 100 most popular patterns, which are thus the easiest to guess. Precisely how this needs to be created has been investigated by Philipp Markert from the Horst G\u00f6rtz Institute for IT Security at Ruhr-Universit\u00e4t Bochum together with colleagues from The George Washington University and the United States Navy.<\/p>\n<p>                                                                                The team led by Professor Adam Aviv from The George Washington University will be presenting the results at the USENIX Symposium on Usable Privacy and Security, which takes place from 8 to 10 August as a virtual conference. The data is available in advance as a freely accessible preprint.<\/p>\n<p><b>What the most popular Android patterns look like<\/b><\/p>\n<p>&#8220;While the four-digit PIN allows users 10,000 different combinations, there can theoretically be 389,112 versions of the Android patterns that are drawn on a three-by-three grid,&#8221; explains Collins Munyendo, first author of the publication from The George Washington University. &#8220;However, users are not making the most of these options.&#8221; In parts of the world where people read from the top left to the bottom right, patterns in the form of letters\u2014such as a Z, L or W\u2014are particularly popular. Around 49 percent of all patterns start in the top left; 32.5 percent end in the bottom right\u2014this makes it easier for attackers to guess a pattern.<\/p>\n<p><b>Various blocklists put to the test<\/b><\/p>\n<p>In the current online study, the research team tested how blocklists of different lengths affect security and usability. They had 1,006 people select a new unlocking pattern. Some of the participants were able to select from all theoretically conceivable possibilities (control group); certain patterns were excluded for the other five groups, whereby five blocklists of different lengths were used. If a user selected a blocklisted pattern, they were shown a warning and had to enter a new pattern.<\/p>\n<p>The researchers had identified in an earlier study which were the most popular Android patterns. The shortest of the five tested blocklists contained the twelve most popular patterns from the previous study, the longest blocklist contained the 581 most popular patterns.<\/p>\n<p><b>Blocklist with 100 patterns recommended<\/b><\/p>\n<p>&#8220;The medium-length list with 100 blocklisted patterns is the best compromise between security and usability,&#8221; summarizes Miles Grant from The George Washington University. With this blocklist, users took an average of 19 seconds to select a non-blocklisted pattern. As a comparison: a pattern was selected in 13 seconds in the control group. Once a pattern had been chosen, the users were able to remember it well: 99.54 percent correctly remembered the pattern they had set, while the figure was 100 percent in the control group.<\/p>\n<p><b>Security increases, even with the shortest blocklist<\/b><\/p>\n<p>The researchers also verified to what extent the blocklists affected the security of the patterns. They simulated how easily an attacker could guess the pattern of a stolen mobile phone. Without a blocklist, the chance of success was 23.7 percent after 30 attempted guesses. With the longest blocklist, it was 2.3 percent. The recommended list with 100 blocklisted patterns reduced the chances of success to around 7.5 percent.<\/p>\n<p>&#8220;A blocklist with 100 entries would thus already significantly increase security, but require little extra effort from users during setup,&#8221; summarizes Philipp Markert. &#8220;The layout with three-by-three grids, which users know and like, would remain unchanged.&#8221; In contrast to this, other ideas for improving the security of Android patterns included a four-by-four grid or a random arrangement of the grid dots on the display.\n                                                                                                                        <\/p>\n<hr\/>\n<div class=\"article-main__explore my-4 d-print-none\">\n<p>                                            Double patterns could advance Android device security\n                                        <\/p><\/div>\n<hr class=\"mb-4\"\/>\n<div class=\"article-main__more p-4\">\n                                                                                                <strong>More information:<\/strong><br \/>\n                                                Using a Blocklist to Improve the Security of User Selection of Android Patterns. <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.usenix.org\/conference\/soups2021\/presentation\/munyendo\">www.usenix.org\/conference\/soup \u2026 resentation\/munyendo<\/a><\/p><\/div>\n<div class=\"d-inline-block text-medium my-4\">\n                                                Provided by<br \/>\n                                                                                                    Ruhr-Universitaet-Bochum<br \/>\n                                                                                                        <a rel=\"nofollow noopener\" target=\"_blank\" class=\"icon_open\" href=\"http:\/\/www.ruhr-uni-bochum.de\/index_en.htm\"><br \/>\n                                                        <svg><use href=\"https:\/\/techx.b-cdn.net\/tmpl\/v2\/img\/svg\/sprite.svg#icon_open\" x=\"0\" y=\"0\"\/><\/svg><\/a><\/p><\/div>\n<p>                                        <!-- print only --><\/p>\n<div class=\"d-none d-print-block\">\n<p>                                                 <strong>Citation<\/strong>:<br \/>\n                                                 How Android unlocking patterns could be made more secure (2021, July 23)<br \/>\n                                                 retrieved 23 July 2021<br \/>\n                                                 from https:\/\/techxplore.com\/<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/news\/\" data-internallinksmanager029f6b8e52c=\"2\" title=\"News\" target=\"_blank\" rel=\"noopener\">news<\/a>\/2021-07-android-patterns.html<\/p>\n<p>                                            This document is subject to copyright. Apart from any fair dealing for the purpose of private study or research, no<br \/>\n                                            part may be reproduced without the written permission. The content is provided for information purposes only.<\/p><\/div>\n<\/p><\/div>\n<p><script id=\"facebook-jssdk\" async=\"\" src=\"https:\/\/connect.facebook.net\/en_US\/sdk.js\"><\/script><\/p>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong>\n<\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more Like this articles, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/science\/\" target=\"_blank\" rel=\"noopener\">Science category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/techxplore.com\/news\/2021-07-android-patterns.html\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#How Android unlocking patterns could be made more secure&#8221; Credit: CC0 Public Domain Users of Android devices can unlock the display by entering a pattern. This function is convenient and thus popular\u2014however, less secure than locking with a PIN. An international research team thus recommends implementing a blocklist on Android devices that prohibits the 100&#8230;<\/p>\n","protected":false},"author":1,"featured_media":307003,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/scx2.b-cdn.net\/gfx\/news\/hires\/2018\/1-android.jpg","fifu_image_alt":"","footnotes":""},"categories":[16],"tags":[],"class_list":["post-307002","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-sciencee"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/307002","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=307002"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/307002\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/307003"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=307002"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=307002"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=307002"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}