Entering Login details thru Keyboard has been found to pose security risks. I just got an idea which i will explain with an example. This is much safer as it uses mouse clicks and no ASCII characters encrypted or otherwise move on the SSL Page in TCP/IP, No keystrokes are generated since only a Mouse is used.

When the Secure Login page is visited by the User, He will see an image (png) with randomly generated Numbers (or Alphabets).

 This is done using a Captcha like process.

Now the user in order to Login to his Account will click the Numbers (image map - js onclick). The numbers can be scrolled, inc/dec (area on number top/bot). He will set the User ID and Password with a series of clicks (just like Combination lock.

When he is done he will Press Login. The safest Login that can ever be achieved, no trace of number anywhere. The only risk is posed by an Onlooker or a Webcamera, Hence this can be used in closed Opaque kiosks only.

Alternative -

A Random Captcha AlphaNumeric KeyBoard Layout Imagemap. The User and Password field will be textboxes as usual. The User will click into textbox, a key-layout appears on right (ajax). The user clicks the alphabets and numbers on keyboard image and then he presses Login.

Here the password will appear as ****. And the keyboard imagemap layout is random size usable AlphaNumeric Single png Image.

Idea date :17:47 19-Dec-07, Type : Open Source

