Question:
Is using the on-screen keyboard a measure of security for online purchases?
Tim Tam
2010-08-12 07:36:04 UTC
I had this virus once called some lsaskeylogger or something. Someone told me it tracked credit card details by "knowing" what you typed into the credit-card number field, whenever you make a purchase. (The way hackers do this need not be known, only that they do do it).

So therefore, after that, and after getting a paypal account, i try to NEVER use the keyboard for typing in passwords of my ebay and paypal account. Instead i use the on-screen keyboard.

Does this even help in the least?

Something which supports my belief that it helps has been westpac online banking. I recently registered for an online-banking service with them. I realised they used a on-screen keyboard, for which i must type my password into, as a security measure... Hrmm..

Thanks in advance :)

If I get a lot of 'no's' i will know the on-screen keyboard has been a waste of time? I know nothing much about these computer fraud crimes, so I wouldn't have a clue how to protect myself.
Five answers:
Michael
2010-08-12 08:48:54 UTC
Well first of all the keylogger you thought you had was infact just a Fake ...see this in the link...



Lsas.Blaster.Keylogger is a fake Trojan infection that is usually downloaded to the PC by a rogue anti-spyware application called System Security 2009. Once installed, fake security alert appears and warns the user about the worm Lsas.Blaster.Keylogger.



http://social.answers.microsoft.com/Forums/en-US/xpsecurity/thread/0b916b73-6c50-4cdf-8351-62c74663bdbf



In this link you will see the following....under On-screen keyboards.

http://en.wikipedia.org/wiki/Keystroke_logging#On-screen_keyboards



Most on screen keyboards (such as the onscreen keyboard that comes with Microsoft Windows XP) send normal keyboard event messages to the external target program to type text. Every software keylogger can log these typed characters sent from one program to another.[14] Additionally, keylogging software can take screenshots of what is displayed on the screen (periodically, and/or upon each mouse click).



So an alternative is Trusteerrapport which i'm told is very good and recommended by some banks

but can slow you down a shade ....but better to be slowed down than robbed.



http://download.cnet.com/Rapport/3000-18510_4-10972537.html



Another alternative which i use is the Virtual Keyboard in Kaspersky 2010 but the link below is from KIS 2011 which is the latest version....but still doing critical fixes for it i believe



Protection for your digital identity at all times Improved!

Smart anti-phishing protection and Virtual Keyboard keep your digital identity absolutely secure when you are shopping, banking or social networking online..



Anyway if considering changing your security anytime the Virtual Keyboard is what you want

and certainly makes you feel safer.
mugfuy
2010-08-12 14:44:40 UTC
A third-party on-screen keyboard (for example from a Banking site) would certainly assist in stopping specific keyloggers especially as they will be driven by it's own (likely encrypted) engine. Using the OSes own On Screen Keyboard for other sites is not a viable security resolution however and keyloggers would pick this up just as they would if you use the physical keyboard (Windows own on-screen keyboard will still fill the keyobard buffer).



In short, No. :-)
Guru_Lite
2010-08-12 14:43:05 UTC
Yes - the on-screen keyboard does help security.

The Malware you mention keeps a log of EVERYTHING you type o the keyboard. Including passwords. There is no way to log the mouse clicks on your screen. But if you are using a touchscreen someone with physical access to your touchscreen could use your fingerprints/oils to discover the letters you typed.
anonymous
2010-08-12 18:26:52 UTC
The single, most effective method to avoid keylogging (and almost all other rubbish that plagues Windows users) is to use a solo partitioned or bootable Linux distro, dedicated for monetary transactions.

Ubuntu is handy: comes with Firefox; installs in about 20 minutes...ready to go.
?
2010-08-12 14:43:56 UTC
online keyboard is better. do you know why?



it capture the pixel location rather then the actual password. so even if someone tries to copy it digitally, it wont be able to find the words easily since its in pixel XY axis value.



Keylogger or any kind of password trojans wont work since you are using your mouse and not typing anything.


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Continue reading on narkive:
Loading...