kingpotnoodle
From the article:
"Microsoft says that this secondary log-in offers many more permutations than a standard password and will therefore make systems more secure, though it has acknowledged that smudges on the screen could give away passwords and suggests that users clean their screens regularly."
That is a bull**** claim. A good password has trillions of combinations (at worst say 26^8), there are not trillions of distinct points on a picture, the screen only as a few million pixels at most and it will be less discerning than individual pixel accuracy.
Maths fail ;)
For starters, no-one is saying a password has to have 8 characters in it, and I'm certain many log-on passwords don't.
Anyway, take your typical (today) mobile screen @ 480x800. Say you can only select to the nearest 5x5, so 15360 possible points on the screen. Let's suppose we have three points in the password.. that gives roughly 3.6x10^12 permutations. Going back to your 8 character password example, that gives roughly 2.1x10^11 permutations.
Granted, you might argue that a typing-based password would include digit and symbol character spaces, and possibly more than 8 characters. But equally, there is no way I'm having some long complicated password like that on my phone, and probably 90% of those who have a password on their phone (rather than a swipe/pattern thing) have four digits - just 1x10^4 permutations.
From the other point of view, if this is used on laptops, you have far more screen estate to play with. On your typical 1366x768 laptop, those three points give you roughly 7.3x10^13 permutations.. contrast that with roughly 7.5x10^13 permutations for a 7 character password from upper and lower case text, numbers, and symbols*.
Given how much easier it is to increase the permutations for the pattern password (~3.1x10^23 permutations for a five point password vs ~6.1x10^23 permutations for a 12 character password encompassing upper case, lower case, digits and symbols), their argument makes some sense.
Personally I think it's less secure for the grease mark reason, I'm just playing devil's advocate.
*96 characters total, calculated from all the characters on my keyboard