Everykey – The Master Key to Your Phone, Laptop, Website Accounts, and More
everykey.com
everykey.com
It was an Ident-i-Eeze, and was a very naughty and silly thing for Harl to have lying around in his wallet, though it was perfectly understandable. There were so many different ways in which you were required to provide absolute proof of your identity these days that life could easily become extremely tiresome just from that factor alone, never mind the deeper existential problems of trying to function as a coherent consciousness in an epistemologically ambiguous physical universe. Just look at cash point machines, for instance. Queues of people standing around waiting to have their fingerprints read, their retinas scanned, bits of skin scraped from the nape of the neck and undergoing instant (or nearly instant --- a good six or seven seconds in tedious reality) genetic analysis, then having to answer trick questions about members of their family they didn't even remember they had, and about their recorded preferences for tablecloth colours. And that was just to get a bit of spare cash for the weekend. If you were trying to raise a loan for a jetcar, sign a missile treaty or pay an entire restaurant bill things could get really trying.
Hence the Ident-i-Eeze. This encoded every single piece of information about you, your body and your life into one all- purpose machine-readable card that you could then carry around in your wallet, and therefore represented technology's greatest triumph to date over both itself and plain common sense.
And thanks for reminding me to read the Hitchhikers Guide again!
Don't forget that today's iris scan, using Daugman's algorithm are the gold standard in biometric technology.
Since a few weeks I'm using the Windows Hello system on my new Surface Pro 4. Its using facial recognition, and it's pretty awesome: turn on the PC, sit still for a second, it greets you, logs in and you can work. For two factor logins I use the Microsoft Account app on Android, which also works very well (no typing a code, just approve the request on the phone).
Now only if Microsoft would fix the power/sleep issues with Surface 4, it would be perfect.
Of course, it makes the assumption that "<user>'s face in front of the computer means <user> wants to log in", which may not always be the case.
That being said, I'm eagerly looking forward to reading about its pitfalls once people crack it.
I've read it is very accurate: even twins who look very much alike won't fool it.
But it still has some funny characteristics: if you train it for two people/faces (you can scan multiple times), it will happily let both people log into the account.
Another gotcha: if I go for a coffee I usually lock my PC (Windows-L). If I then go too slowly, it will recognize me again and log me back in, leaving the pc unlocked.
It's like the technological version of "Go the fuck to sleep" I suppose.
Load the newly updated Intel display driver.
(Not to mention hardware attacks, since even if the device has a secure element, it has to send key material back to the device with the keychain.)
[1]: https://www.kickstarter.com/projects/everykey/everykey-the-w...
[2]: https://www.indiegogo.com/projects/everykey-your-only-key
I really don't understand why that is. I've always thought it was partly a pricing problem (which would be very bad for this $128 gadget), but when you're company is providing it to you for free, that can't be the reason you don't use it.
I already made a prototype for Mac & generic smartwatches [1], but if you have a Pebble you'll have to disconnect the watch from the phone. Questions, criticism & suggestions are welcome.
I think you should have some initial prompt on the watch that asks the user if it is OK to unlock the device. It's more friction, but otherwise it's trivially bypassable.
Very true. But I am using Bluetooth and it has much better security protocols than the plain simple radio-frequency signals for car remote controls. At the very least, the user needs to first pair the watch with the computer. Besides, all communication between the 2 is encrypted. And, to avoid Bluetooth spoofing, there is also an exchange of time-based encrypted tokens, all transparent for the user. There are a few more security details about it (e.g.: the authentication password is not stored in the watch, is AES-encrypted in the computer, etc). I intend to write a detailed risk-assessment about it later.
In truth, my intention is someday to make it FIDO-UAF [1] compatible, if I have get the money to do it.
It is very cool to understand what concerns people have about it. Thank you.
But I am concerned that you cannot measure proximity accurately because an attacker could just replay messages between the two devices and boost the signal without being able to decipher the contents, and none of your comments about crypto or time-based tokens convince me otherwise.
As a simplified version of a MITM attack? That is clever, I admit I didn't think of it.
However, even in case the attacker is able to do so, the watch would still inform the user when the PC is unlocked. And the user can manually force a lock, from the watch, overriding the proximity/signal strength. To intercept this the attacker would need to decipher the messages. That is for the Android Wear-Windows PC version, though. I admit the Mac version is not that sophisticated, yet.
It's better than nothing, but the user is likely to think of it as a malfunction if they are far away (e.g. at a coffee shop), and the watch may not actually be physically on them at the time either.
And a second is really enough to plant malware on a computer; you can already buy a USB stick which types in commands much faster than a human: http://hakshop.myshopify.com/products/usb-rubber-ducky-delux...
Though that might be more of an argument about why this attack vector is unrealistic since most people don't even have full disk crypto on their phones/computers.
Also, not sure if you've seen this, but surprisingly these guys are still around: http://www.knocktounlock.com/
Not if the attacker stops the relay right after the PC is unlocked.
No, if it happens the program falls back into the "user is away->lock the computer" mode.
Not exactly the guy I want safeguarding my entire identity.