<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:georss="http://www.georss.org/georss" xmlns:geo="http://www.w3.org/2003/01/geo/wgs84_pos#" xmlns:media="http://search.yahoo.com/mrss/"
		>
<channel>
	<title>Comments on: Startup Vidoop Has A Plan To Monetize User Logins</title>
	<atom:link href="http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/feed/" rel="self" type="application/rss+xml" />
	<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/</link>
	<description></description>
	<lastBuildDate>Wed, 22 May 2013 21:24:48 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.com/</generator>
	<item>
		<title>By: Raymond Seetook Jr.</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181859</link>
		<dc:creator><![CDATA[Raymond Seetook Jr.]]></dc:creator>
		<pubDate>Fri, 22 Aug 2008 21:49:18 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181859</guid>
		<description><![CDATA[Are they going to be installed here in the villages around Alaska?just wondering.I heard they were going to be installed everywhere in oct.]]></description>
		<content:encoded><![CDATA[<p>Are they going to be installed here in the villages around Alaska?just wondering.I heard they were going to be installed everywhere in oct.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: OpenID Has Big New Friends - GigaOM</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181858</link>
		<dc:creator><![CDATA[OpenID Has Big New Friends - GigaOM]]></dc:creator>
		<pubDate>Fri, 08 Feb 2008 02:00:51 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181858</guid>
		<description><![CDATA[&lt;p&gt;[...] OpenID is proving to be a huge windfall for at least one startup: Tulsa, Okla.-based Vidoop, which we introduced here in October. Vidoop&#8217;s consumer play, called MyVidoop, uses images rather than letters or numbers to [...]&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>[...] OpenID is proving to be a huge windfall for at least one startup: Tulsa, Okla.-based Vidoop, which we introduced here in October. Vidoop&#8217;s consumer play, called MyVidoop, uses images rather than letters or numbers to [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Blomquist &#187; Blog Archive &#187; The hard FAQs about Vidoop</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181857</link>
		<dc:creator><![CDATA[Scott Blomquist &#187; Blog Archive &#187; The hard FAQs about Vidoop]]></dc:creator>
		<pubDate>Wed, 10 Oct 2007 16:22:27 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181857</guid>
		<description><![CDATA[&lt;p&gt;[...] myVidoop.com and Vidoop Secure (over at Judi Sohn&#8217;s Web Worker Daily review of myVidoop, or Carleen Hawn&#8217;s write-up over at GigaOM for [...]&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>[...] myVidoop.com and Vidoop Secure (over at Judi Sohn&#8217;s Web Worker Daily review of myVidoop, or Carleen Hawn&#8217;s write-up over at GigaOM for [...]</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Blomquist</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181856</link>
		<dc:creator><![CDATA[Scott Blomquist]]></dc:creator>
		<pubDate>Wed, 10 Oct 2007 15:56:01 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181856</guid>
		<description><![CDATA[&lt;p&gt;I collected the common questions that have been raised here an in other places into one big FAQ and posted answers to them at http://scott.blomqui.st/2007/10/09/the-hard-faqs-about-vidoop/&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>I collected the common questions that have been raised here an in other places into one big FAQ and posted answers to them at <a href="http://scott.blomqui.st/2007/10/09/the-hard-faqs-about-vidoop/" rel="nofollow">http://scott.blomqui.st/2007/10/09/the-hard-faqs-about-vidoop/</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: WhatIsXing</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181855</link>
		<dc:creator><![CDATA[WhatIsXing]]></dc:creator>
		<pubDate>Wed, 10 Oct 2007 04:32:11 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181855</guid>
		<description><![CDATA[&lt;p&gt;S.W.&lt;/p&gt;

&lt;p&gt;it took you three attempts to break your own password?  that&#039;s pretty sad.  you should try remembering your own password better.  it normally takes me one try to break my own password, since i already know what it is.&lt;/p&gt;

&lt;p&gt;maybe you should try hacking my myvidoop account; it is easier to break into than the good ol password authentication, according to you.&lt;/p&gt;

&lt;p&gt;but for real, three attempts?&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>S.W.</p>
<p>it took you three attempts to break your own password?  that&#8217;s pretty sad.  you should try remembering your own password better.  it normally takes me one try to break my own password, since i already know what it is.</p>
<p>maybe you should try hacking my myvidoop account; it is easier to break into than the good ol password authentication, according to you.</p>
<p>but for real, three attempts?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: George Louthan</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181854</link>
		<dc:creator><![CDATA[George Louthan]]></dc:creator>
		<pubDate>Tue, 09 Oct 2007 23:40:27 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181854</guid>
		<description><![CDATA[&lt;p&gt;I&#039;m not going to provide any arguments of my own; I&#039;m just going to summarize the arguments I&#039;m already seeing, in the hope of adding clarity.&lt;/p&gt;

&lt;p&gt;The first is that the following two attacks are of approximately equivalent sophistication:&lt;/p&gt;

&lt;p&gt;Attack against Vidoop:
1. Exhaustively scrape from a constantly-changing (We aim to turn over the entire image library on a regular basis), randomly-presented library of images
2. Have a human attach a guess (albeit probably a good guess) of the category or categories represented by each of those images
3. Steal a user&#039;s soft token
4. Capture that user&#039;s screen and keystrokes simultaneously during login
5. Presumably with some kind of computer vision library, exhaustively match all of those scraped images to the images in the grid during sign-in
6. Use OCR software to match a character to each of the images in the user&#039;s grid
7. Compare the OCR&#039;d characters to the characters recorded when the user signed in
8. Sign in by repeating the process of exhaustively matching grid images, OCRing the characters on it, and then entering the appropriate characters&lt;/p&gt;

&lt;p&gt;Attack against passwords:
1. Capture a user&#039;s keystrokes with keylogging software.
2. Sign in as the user, using the password captured by the keylogger.&lt;/p&gt;

&lt;p&gt;The other argument I see here is this:
&quot;If an attacker is assumed to have the ability to execute arbitrary code on a user&#039;s computer, that user screwed.&quot;&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>I&#8217;m not going to provide any arguments of my own; I&#8217;m just going to summarize the arguments I&#8217;m already seeing, in the hope of adding clarity.</p>
<p>The first is that the following two attacks are of approximately equivalent sophistication:</p>
<p>Attack against Vidoop:<br />
1. Exhaustively scrape from a constantly-changing (We aim to turn over the entire image library on a regular basis), randomly-presented library of images<br />
2. Have a human attach a guess (albeit probably a good guess) of the category or categories represented by each of those images<br />
3. Steal a user&#8217;s soft token<br />
4. Capture that user&#8217;s screen and keystrokes simultaneously during login<br />
5. Presumably with some kind of computer vision library, exhaustively match all of those scraped images to the images in the grid during sign-in<br />
6. Use OCR software to match a character to each of the images in the user&#8217;s grid<br />
7. Compare the OCR&#8217;d characters to the characters recorded when the user signed in<br />
8. Sign in by repeating the process of exhaustively matching grid images, OCRing the characters on it, and then entering the appropriate characters</p>
<p>Attack against passwords:<br />
1. Capture a user&#8217;s keystrokes with keylogging software.<br />
2. Sign in as the user, using the password captured by the keylogger.</p>
<p>The other argument I see here is this:<br />
&#8220;If an attacker is assumed to have the ability to execute arbitrary code on a user&#8217;s computer, that user screwed.&#8221;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Wondering</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181853</link>
		<dc:creator><![CDATA[Wondering]]></dc:creator>
		<pubDate>Tue, 09 Oct 2007 23:07:02 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181853</guid>
		<description><![CDATA[&lt;p&gt;S.W. (now I&#039;m over here wondering the same thing)&lt;/p&gt;

&lt;p&gt;You need to go back to school. How exactly does a password (no matter how complex) combat simple keystroke logging? automation? guessing? etc...&lt;/p&gt;

&lt;p&gt;-WONDERING what kind of security related authority you have especially since you sound like you are just hating.&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>S.W. (now I&#8217;m over here wondering the same thing)</p>
<p>You need to go back to school. How exactly does a password (no matter how complex) combat simple keystroke logging? automation? guessing? etc&#8230;</p>
<p>-WONDERING what kind of security related authority you have especially since you sound like you are just hating.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: S.W.</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181852</link>
		<dc:creator><![CDATA[S.W.]]></dc:creator>
		<pubDate>Tue, 09 Oct 2007 22:51:52 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181852</guid>
		<description><![CDATA[&lt;p&gt;Four-digit ATM PINs are a very low bar and used in a very different security setting. You cannot brute force a physical ATM machine remotely like you could with malware-infected PCs.&lt;/p&gt;

&lt;p&gt;I still contend that the image-based login system doesn&#039;t buy you anything. It doesn&#039;t thwart keylogging since you can scrape and categorize the library of images, plus you can steal the software token.&lt;/p&gt;

&lt;p&gt;The image login system is less secure, harder to use, won&#039;t work on small devices, and can&#039;t be used by anyone who is blind. In almost every respect, it&#039;s weaker than a plain old alphanumeric password.&lt;/p&gt;

&lt;p&gt;The only idea of merit is using SMS as a trusted, out-of-band channel. The image-based login will not be successful because of its usability and security issues.&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>Four-digit ATM PINs are a very low bar and used in a very different security setting. You cannot brute force a physical ATM machine remotely like you could with malware-infected PCs.</p>
<p>I still contend that the image-based login system doesn&#8217;t buy you anything. It doesn&#8217;t thwart keylogging since you can scrape and categorize the library of images, plus you can steal the software token.</p>
<p>The image login system is less secure, harder to use, won&#8217;t work on small devices, and can&#8217;t be used by anyone who is blind. In almost every respect, it&#8217;s weaker than a plain old alphanumeric password.</p>
<p>The only idea of merit is using SMS as a trusted, out-of-band channel. The image-based login will not be successful because of its usability and security issues.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Scott Blomquist</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181851</link>
		<dc:creator><![CDATA[Scott Blomquist]]></dc:creator>
		<pubDate>Tue, 09 Oct 2007 21:37:18 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181851</guid>
		<description><![CDATA[&lt;p&gt;S.W., the difficulty that you saw in categorizing images only serves to impede a hacker, not a legitimate user.&lt;/p&gt;

&lt;p&gt;A hacker has to answer &quot;what category does this yellowish-sphere-with-a-ring-around-it represent?&quot; We don&#039;t spend any effort to make our images work well in this direction.&lt;/p&gt;

&lt;p&gt;Legitimate Vidoop Secure users, on the other hand, have to answer &quot;which image is an example of an object in space?&quot; (It&#039;s that yellowish sphere from before, only now it&#039;s more clear because I know more about what I&#039;m looking for.) We extensively test our images to make sure they work in this direction.&lt;/p&gt;

&lt;p&gt;We&#039;re working to make the hacker version of the question even harder than when you had difficulty with it before. By using images that represent more than one category, a hacker has a bigger identification problem to solve (and one that doesn&#039;t have a unique solution). As you noticed from your experiment, some of our images do this already.&lt;/p&gt;

&lt;p&gt;On the subject of strength-of-secret, it&#039;s true that a Vidoop Secure user&#039;s secret is only 11-17 bits. Remember: an ATM PIN is around 13.3 bits, and is also weakened by end user bias.&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>S.W., the difficulty that you saw in categorizing images only serves to impede a hacker, not a legitimate user.</p>
<p>A hacker has to answer &#8220;what category does this yellowish-sphere-with-a-ring-around-it represent?&#8221; We don&#8217;t spend any effort to make our images work well in this direction.</p>
<p>Legitimate Vidoop Secure users, on the other hand, have to answer &#8220;which image is an example of an object in space?&#8221; (It&#8217;s that yellowish sphere from before, only now it&#8217;s more clear because I know more about what I&#8217;m looking for.) We extensively test our images to make sure they work in this direction.</p>
<p>We&#8217;re working to make the hacker version of the question even harder than when you had difficulty with it before. By using images that represent more than one category, a hacker has a bigger identification problem to solve (and one that doesn&#8217;t have a unique solution). As you noticed from your experiment, some of our images do this already.</p>
<p>On the subject of strength-of-secret, it&#8217;s true that a Vidoop Secure user&#8217;s secret is only 11-17 bits. Remember: an ATM PIN is around 13.3 bits, and is also weakened by end user bias.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: S.W.</title>
		<link>http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181850</link>
		<dc:creator><![CDATA[S.W.]]></dc:creator>
		<pubDate>Tue, 09 Oct 2007 19:03:53 +0000</pubDate>
		<guid isPermaLink="false">http://gigaom.com/2007/10/04/startup-vidoop-has-a-plan-to-monetize-user-logins/#comment-181850</guid>
		<description><![CDATA[&lt;p&gt;If you say so, but I took three screen shots and it appears that the categories change on each reload. If they are the same, then it&#039;s a usability problem, since the categories are not clearly distinguishable.&lt;/p&gt;

&lt;p&gt;Regardless, you can still scrape the images and build your own corpus by categorizing them. That would allow you to log keystrokes just like a password.&lt;/p&gt;

&lt;p&gt;Vidoop&#039;s user secrets only have about 11-17 bits of information, depending if you choose 3 or 5 categories. That&#039;s assuming users have no bias for certain categories, which they obviously will.&lt;/p&gt;

&lt;p&gt;If a computer is activated, Vidoop&#039;s security is based on essentially a cookie and a tiny shared secret. Both can be stolen by malware. Or, since the secret is so small, a non-trivial portion of activated computers can be brute forced.&lt;/p&gt;

&lt;p&gt;Using the cell phone as a second factor is a better solution and has merit on its own. However, I think the image-based login is weak and would not recommend it to anyone.&lt;/p&gt;]]></description>
		<content:encoded><![CDATA[<p>If you say so, but I took three screen shots and it appears that the categories change on each reload. If they are the same, then it&#8217;s a usability problem, since the categories are not clearly distinguishable.</p>
<p>Regardless, you can still scrape the images and build your own corpus by categorizing them. That would allow you to log keystrokes just like a password.</p>
<p>Vidoop&#8217;s user secrets only have about 11-17 bits of information, depending if you choose 3 or 5 categories. That&#8217;s assuming users have no bias for certain categories, which they obviously will.</p>
<p>If a computer is activated, Vidoop&#8217;s security is based on essentially a cookie and a tiny shared secret. Both can be stolen by malware. Or, since the secret is so small, a non-trivial portion of activated computers can be brute forced.</p>
<p>Using the cell phone as a second factor is a better solution and has merit on its own. However, I think the image-based login is weak and would not recommend it to anyone.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
