Goodbye, Passwords. You Aren’t a Good Defense
nytimes.com
nytimes.com
Thank God someone finally sees that OpenID is a waste of time and resources. I really don't understand why so many tech kids are jumping on this openid bandwagen when it is:
1. Difficult to use 2. Confusing 3. Has no obvious advantages for most end users 4. Insecure by design
Anything that requires physical access to a card or usb stick or a specific computer to do things on the web is a non-starter.
Given this constraint, passwords work fine. The problem boils down to the completely unavoidable security vs. ease of use trade-off. I say just get rid of the complexity requirements. If someone wants to enter a blank password for all their needs, let them. I personally will keep track of my varied and complex passwords.
Sure, keep using your passwords, my grandpa also loves using his walkie talkie.
That's OpenID. I assume you're going to use a password for your StickKey host provider.
In my mind, ideally, secure auth. should test:
1. "something you know" (password)
2. "something you are" (biometric)
3. "something you have" (cryptokey, dongle, etc)
I'd heard this idea probably 5 years back, and it's stuck with me
All current 'something you are' systems can be fooled - and they can be copied without you even knowing it (fingerprint is very insecure for example, since you leave them everywhere, same for dna. Iris systems can be copied with a telescope.)
'Something you have' system are flawed because it's too easy to loose the item, or have it stolen. Or the item can be duplicated (often very easily, sometimes not so easy).
Only 'something you know' is secure because it can never be taken from you or copied without your knowledge.
Hence we have passwords.
What might lead anyone to believe there is a technical solution to this?
Even if the most fearful involved here manage to mass-deploy what they're told is uncrackable personal remote identification -- and undoubtedly at great financial cost to all parties involved, and quite probably at great social cost, too -- it'll (still) get cracked.
Security need be "good enough", "affordable" and "useable." Security that is unaffordable or unusable will be bypassed.
This stuff needs to be built into the browser, and it needs to be on your keychain. Hence my USB stick idea.