Traveling Light in a Time of Digital Thievery
nytimes.com
nytimes.com
Cut and paste instead of typing -- really? We all know the clipboard is equally insecure. This is logic that seems to come from a child-like understanding of how computers work.
Why don't more organizations have their own secure token system? Then add a layer of secondary authentication over access to any sensitive data? Security is more about creating reasonable inefficiencies that ensure the right people are accessing information than it is about protecting your passwords from key loggers.
But he says software keyloggers, so that's pretty moot.
Apparently he didn't realize that it's also trivial for snooping software to monitor the clipboard content.
Use a token or smartcard in addition to your password.
If they're capable of installing keyloggers at customs inspection, I suspect they're also capable of imaging my phone at the same time.
While I'm _reasonably_ confident the crypto in the app is probably done right, the truth is I've got barely 13bits of entropy in my unlock code for Authenticator - and I could easily work out how to brute-force it given a realistic "government security agency" sized IT infrastructure. (Hell - even spinning up 10,000 EC2 instances for long enough to crank up the android simulator and try all possible 4 digit "PINs" one at a time would probably only cost "nice dinner out" kind of money…)
It seems strange to consider the devices to be contaminated if privately inspected by Chinese officials, when there were plenty of previous opportunities to root them at the factory.
Isn't cheaper stuff better for consumers in the long run? Besides, how do companies know that their foreign competitors didn't legitimately reverse engineer and/or independently reinvent the product in question, especially if the product comes out years later?