Categories
Security

Locking The Front Door But Leaving The Back Open

Here is an amusing yet failing attempt at security available in the App Store called Spaghetti Pad. Here’s the description from the app developer:

Is somebody always looking over your shoulder, snooping on your iPhone? Sure, we know. That’s why we built Spaghetti Pad. It’s a semi-private notepad which obfuscates your notes so they’re more difficult for others to read — without login screens to slow you down.

How does it work?
Spaghetti Pad takes advantage of the amazing power of the mind to read words with mixed up letters. As long as the first and last letters are in the correct place you can still read the word. Just type in your note normally and Spaghetti Pad will mix the letters up for you. When you view the note later it’s all spaghetti text, slow for others to read but easy for you.

The Technique Is Real

The technique used is actually true, research is showing that we read at least partially the shape of the word rather than the individual letters. Take the following example:

Aoccdrnig to a rscheearch at Cmabrigde Uinervtisy, it deosn’t mttaer in waht oredr the ltteers in a wrod are, the olny iprmoetnt tihng is taht the frist and lsat ltteer be at the rghit pclae. The rset can be a toatl mses and you can sitll raed it wouthit porbelm. Tihs is bcuseae the huamn mnid deos not raed ervey lteter by istlef, but the wrod as a wlohe.

This may be slightly more difficult for people whom English isn’t their native language, but most will read it nearly as quick as if it were all spelled out correctly. More research can be found here. I should note this was an Internet meme sometime around 2003.

The Use Case Fails

Now ask yourself: what allows me to read the text, but prevents someone next to me from doing the same? Does your brain hurt yet? Virtually all of us can read it because we all read the same way. It doesn’t even slow down reading very much. As a result it appears like security through obscurity, but in reality it’s less effective than Pig Latin or Ubbi dubbi. With Pig Latin, there is at least a little bit of knowledge required before decrypting it becomes natural (though you can sometimes guess). Igpay Atinlay isway otnay ecuritysay.

Your better off getting one of these privacy screens.

Leave a Reply

Your email address will not be published. Required fields are marked *