When passwords attack: the problem with aggressive password policies
arstechnica.com
arstechnica.com
That does reduce the USB key to a single point of failure though. That risk could be mitigated with a proprietary key copier.
A standard way to generate key pairs for authentication would be a lot better though. (Really, there's no reason we couldn't use SSH private keys with some simple client and server plugins.)
There's an implied 'because' between these two sentences, which I think is problematic, since the first sentence does not necessarily follow from the second.
I couldn't care less about the second part, but the first is a great idea. When I visit the website in your profile, though, I don't see any mention of hardware, just software.
Is there more information available somewhere?
The hardware key is in private beta and will be publicly available soon. We have evaluated half a dozen smartcard technology vendors and are partnering with a couple of them, so we can deliver a key with or without FIPS certification depending on your cost consciousness and security requirements. Please e-mail me for additional info.
I'm honestly not trying to spam HN with links to my product but since it's on topic I'll just mention that I developed an iPhone app called KEYBOX ( http://www.jayfuerstenberg.com/keybox/ ). It securely manages passwords and other secrets without dongles or other devices.
USB keys are a good idea from a convenience perspective but what makes it convenient for you makes it equally so for a hacker (the nefarious kind) to break into whatever system you're trying to make secure.
So take my below answer with a grain of salt...
I'm surprised by all the attempts to replace the password with non-secret keys be they facial recognition (face prints?), fingerprints, or other...
I can login to your facial recognition screen just by holding up your photo. Fingerprints are little more difficult but the technology exists.
But if I am not in possession of your password I'm going to be spending a lifetime cracking it.
Conclusion: Keys are not secrets and can be easily copied. Passwords ARE secrets.
Yes, passwords can be difficult to remember but that's a different problem.
If you want to see secret/password management done right check my website ( http://www.jayfuerstenberg.com )
I agree with your assessment on facial recognition and fingerprints, though the biggest problems with the fingerprint authentication are the lack of ubiquitous sensors and privacy issues.
But password manager software is better than nothing ;)
Is there something that makes a smartcard based USB key work differently when held by a person other than its rightful owner?
My impression of them, perhaps incorrect, is that they are akin to Hanko ( http://en.wikipedia.org/wiki/Hanko_(stamp)#Japanese_usage ). Basically a system of using possession combined with a fairly unique set of data as a means of distinguishing and authenticating its owner. But in practice its far less than perfect.
Nothing is perfect of course. The risk/threat is very similar to someone stealing your phone and has somehow gotten to know your master password to your password management software. However, password management does not really solve neither the usability or the security problems of usernames and passwords ... although a good piece of software can certainly help.
* Someone can watch you type in the password
* Someone can receive/sniff/keylog you typing in the password
* Someone can find the password database and crack it
* You might tell the wrong person the password
* If you wrote the password down, someone might find it
* More i'm not thinking of (probably)
There is some kind of attack that will work to get your password, I guarantee it. So stop obsessing over it. Just make one difficult password, keep it for a long time (as suggested in the article) and make use of a second authentication factor.Use a keyfob from PayPal or Verisign combined with OpenID ($5-$40; there are other cheap keyfobs out there too). Soft keyfobs are free and (while not impenetrable) present a new mandatory additional attack vector that increases complexity. It's less secure, but you can also use an SMS-based system for another free and cross-platform alternative.