NoPassword
nopassword.alexsmolen.com
nopassword.alexsmolen.com
Just a few off the top of my head:
1. Easier for email hackers to detect sites where you have logins. (Controlling someone's email usually means controlling most/all logins, but it takes some digging to get a good list of vaulable logins. With this solution, most of the list is on the first page or two of the inbox.)
2. Harder to detect being hacked. (Previously, a hacker with email access would have to reset your passwords, and you will notice that at least some passwords have changed. Now the hacker just has to delete any incoming authentication emails after reading them.)
3. Losing a job becomes potentially more catastrophic. (Hope you didn't associate too many passwords with your work email, because IT wiped your account while security was escorting you out the door. And before you say only dumb people use work email for personal accounts, consider that part of the idea of this nopassword system is to help "dumb people" who fail to (for example) use password managers.)
4. Your email provider now has a nice easily mined record of what sites you log into most often. But, hey, I'm sure we can all trust Google not to use that information in a terribly creepy manner, right?
This of course only solves problem (1) that you mentioned and possibly(?) (2) partially.
It occurs to me that this is kind of an interesting evolution of systems like 1Password, where the user experience is very similar: you have one password that gives you access to other passwords. Similarly here, your "one password" is your email password, and that gives you access to what is conceptually a new password on every login (vs a pre-generated one).
I wonder if we couldn't solve 3 and 1 together by creating a "login email provider". For example, pretend dropbox wanted to offer this service. Dropbox gives you an @dropbox.com email specifically for logging into places. When a login email was sent to you, you would go to dropbox and navigate to the logins tab, which would have a very non-emaily interface showing you the last login links that were sent to you (again, auto deleted after 5 minutes -- and since this is not meant to be used as normal email there is no expectation for them to last longer). If websites only supported "known" services like @dropbox.com for this kind of login, then the (3) could be solved. Maybe to make things even clearer, the .login TLD could be used or something.
1 & 2. If your email is hacked, the least of your concerns is what else is being accessed. No matter what, if someone controls your email then you are screwed. We've seen enough examples of that being true.
3. Well, if you don't remember your password and you no longer have access to the email you're in trouble as well. Password managers are great, but there is still some use cases where they don't work very well and I've had keepass go corrupt on me once before.
4. They already know all the sites you visit (if you're really worried about it). You still get password resets, user account confirmations, and weekly notifications from most sites.
And yes it's possible to figure out which sites I visit from my Gmail, and yes it's possible to lose your job AND forget your password all at once, but these issues are made exponentially worse by the "email a login token every time" scheme outlined in the article.
Proposals for browser plugins and special protocols that use email for authentication have been around for a while too. It's just a matter of mainstreaming them. Which I hope never happens until we make sure email is as secure as a password manager.
I personally would like to disable the ability to reset my password via email on every one of my accounts (and disable resetting by "security questions" too.). I have all those passwords in my password manager, backed up on all my computers, an external disk, and the cloud. I won't need to reset my password. (Except when the service provider forces me too, like Dropbox recently did.)
I already use my primary email for this purpose. Most passwords I memorize, but some, for services with requirements so arcane that memorization isn't possible, I just email to myself with a unique key I remember. To get the password, I just search my email for the key.
Yes, this makes me vulnerable if my email is ever compromised. But my primary email is already a single point of failure and pretending otherwise doesn't do me any favors.
I could use a password manager, which would have the advantage of encryption. But it's also limited to those places I have access to it. I can store the database in my dropbox, but that limits the platforms I can access it from (at least, without some serious headaches) and makes the whole process that much more painful.
To do this, of course, you'd have to get an email sent to that machine. Then, you must login to your email on that same machine to get the PW, and thus the problem: now you have a much greater chance of leaving your email logged in on the 3rd-party machine. Whether it's a friend's laptop or a public terminal (library, airport, etc.) this is not a good thing whatsoever; all you needed to do was to login to a site to post a comment on some silly discussion board, and now you've left the keys to your kingdom in the open.
Further, if there are actual security issues with that box, say it's actively being MitM'd, keylogged, etc. well instead of simply gaining access to your silly forum account, now they will have access to your email.
I think I would flat-out refuse to use any service for these flaws.
Normally this would be more work, but if you're away from your email it might be a good alternative..
Email/SMS would be an obvious security hole for people who just click "OK" without reading, though. I guess a QR code would be secure anyway.
6. Your "password" being stored in the clear via cookies on your machine.
(not sure if that's how it works or not)
Realistically, I expect most people/services will converge on Single Sign On via one of Twitter, Google, Facebook, and maybe a couple others. Hopefully all offering 2-factor authentication. So you'll only need a handful of passwords anyway.
Also, if you've been waiting for Persona to hit "beta" before trying it out, well, check back Thursday morning. :)
For example, you could define a special URLs for login and logout actions. (E.g. persona:action=login&onsuccess=encoded_url1&onfailure=encodedurl2 ). I don't know about others, but it would make me much more willing to give a try.
"We are sorry, this is taking a longer than it should. If this doesn't resolve itself within a few seconds, please close the window and try again."
In one case the attacker needs full control during the password reset and in the other they can simply scour email for all passwords and get out - perhaps even without controlling the account - ie, transparent proxy + poisoned DNS would do the 2nd easily.
It seems like you could easily handle this by making the link invalid after a certain time period, requiring you to request a new one. Which, is actually what a lot of password reset emails do currently.
This doesn't avoid any number of different scenarios.
Too bad we don't all use PGP for email...
My SMS are encrypted with A5, and my email (gmail's inbound smtpd) is (usually) encrypted with TLS.
Of course, I always check with TLS as well.
It's not quite as bad as you seem to make it out.
There is no such thing as secure transport-level e-mail because eventually it may [read: will] hop through a relay which does not use transport-level security.
It's not secure, period.
Edit: looks like I missed the point here
Sent from mobile
So, a user could implement this workflow themselves already.
Basically, create a password for the site that you don't even know yourself when you sign up. Make sure you select the appropriate "keep me logged in" option.
Now, if you ever get logged out, go to a different computer or otherwise clear your cookie, you just "reset" your password... which generally involves sending you an email that lets you login to the site based on the link or code provided.
This approach is simply making that the norm and doing away with the (probably insecure anyway) password for the site.
If email and SMS aren't secure for password recovery, what alternatives do we have that scale and provide for a quick and user-friendly experience?
If you create a ridiculously difficult to crack password once, you don't have to keep doing it. If it takes 50,000 years to crack, creating a new one 3 days later will not make you more secure.
If you're going to the level of PGP to send yourself a new password every time you log in, just use client certs!!!
Let me put this in more plain terms, because I want you to understand exactly why what you're doing is wrong.
Now that I know you always reset your password, i'm going to find a way to intercept your e-mail. (There are many.) Then i'm going to automatically reset your password as soon as the mail is delivered, faster than you ever possibly could by hand.
If you had just remembered or saved your password in the browser this would have been impossible. Now your account is compromised because you thought it was easier to go through 4 steps every time you log in versus just logging in with a saved password.
What's REALLY weird: my browser is showing a different cert than OpenSSL is. My browser shows it's signed by PositiveSSL, but when I connect with 'openssl s_client' I get this:
depth=0 C = --, ST = SomeState, L = SomeCity, O = SomeOrganization, OU = SomeOrganizationalUnit, CN = ip-10-119-98-53, emailAddress = root@ip-10-119-98-53
verify error:num=18:self signed certificate
verify return:1
depth=0 C = --, ST = SomeState, L = SomeCity, O = SomeOrganization, OU = SomeOrganizationalUnit, CN = ip-10-119-98-53, emailAddress = root@ip-10-119-98-53
verify error:num=10:certificate has expired
notAfter=Feb 24 01:08:21 2012 GMT
verify return:1
depth=0 C = --, ST = SomeState, L = SomeCity, O = SomeOrganization, OU = SomeOrganizationalUnit, CN = ip-10-119-98-53, emailAddress = root@ip-10-119-98-53
notAfter=Feb 24 01:08:21 2012 GMT
Not only is it self-signed, it's expired. I actually don't know what the fuck is going on here.Otherwise, you are correct.
While this may be mostly true, the fact is that many still use POP email, and so what, you're to setup a POP account on whatever machine just so that you can access a website? Just let me remember my simple PW, thanks.
Any recommendations? I won't use PHP or MySQL on grounds of taste and decency.
Good for you.
For previous discussion: http://news.ycombinator.com/item?id=4308190
There's a lot of peace of mind in knowing that my users' passwords won't ever end up on pastebin but overall I regret the decision.
I get a couple of emails a week from users who don't understand how it works. If I had to do over I'd choose openID.
Of course to really make it secure, you would want all smtp connections between you and the user to use SSL, which you cannot guarantee. One test I always use for new authentication schemes is would the NSA be able to compromise your account if they wanted? In this case I would definitely say yes.
Still, this would be excellent for sites that only have you login to set preferences, etc.
An even more secure way to implement one-time passwords is through an HTOP[1] smartphone app. The crypto is seeded once and then never has to communicate over the network to generate an OTP. Only the person with physical access to your phone can generate a password. I know when I was with USAA, they allowed you to generate one-time passwords using this method.
[1] http://en.wikipedia.org/wiki/Time-based_One-time_Password_Al...
"The concern is that in the 2 seconds it takes me to type the password in someone will intercept it and beat me to it?"
The concern is that someone will snoop the password before it even gets to your phone. SMS snooping/MiTM has been demonstrated before [1]. Time-Based One-time Password algorithms are safer because they are not vulnerable to the aforementioned probems -- they never touch the network.
"This is way safer than email."
I never said it wasn't?
If you believe it's unlikely anyone will ever either A. work for a telecom company, or B. build an OpenBTS base station, while also C. try to get into your bank account, then you shouldn't worry.
If you believe it's unlikely anyone will ever A. work for an ISP or other mail relay, or B. sniff traffic on a network segment that an unencrypted mail relay runs on, while also C. try to get into your bank account, then you shouldn't worry.
Now then. If you think both of those are likely to happen, you can simply use a one-time pin program on a phone (or a keyfob -- much more secure than on a phone) and neither of the two attacks will be possible, thus your bank account will be more secure.
It's only a matter of how much you care about your bank account. If you care enough you won't use e-mail or SMS. If you don't care, then whatever happens, happens.
The one area where I think it would fall down is logging into web apps that have multiple points-of-entry. Such as chartbeat(phone app and website). I don't see how you would be sent a link to log into an iPhone app. Or could you be sent and email with multiple links: one that goes to the site, another that flings you into an app?
The best implementation would be if web apps offered this in the preferences area with a check-box saying: "Enable NoPassword" (so you don't offend any traditional password lovers or confuse people that just might not understand it).
In such system, The weakest link is the mail system, but this is not worst than what is done today. Replace mail by an sms code or whatever equivalent.
Also, as a user, you can accomplish this same thing by just using a common username across all your 1-off sites, along with a gibberish password that you reset every time you want to log in.
I still see this cluttering up my inbox, they would need to be deleted right away...for me it's just easier to type in a password.
Can you be specific as to why? If you use Dropbox for personal information, I'd assume it would be similar.
It's pretty much the ideal scheme for all those sites you don't visit regularly (and many of us, despite knowing better, use the same password for...).
(I know its not exactly that)
IMHO everyone should be using two-factor authentication for their email.
1) You don't have/won't access your email account on that computer (ex: Internet Cafe)
2) Spam filters that may delay the mail and so will delay the ability to log in. (ex: Grey Listing)
3) Changing your email account (ex: Work Email to personal email)
2 and 3 and really valid though.
Seriously? Intenet cafes are the least secure computers to give your email and password to. Sure for junk and spam-email accounts, that you dont care about anyway. But logging in to your personal email account on an internet caffe!? Thats madness.
That's what they are proposing. Every time you log in they send you a one-time secret token URL by email.
If you want to log in again, repeat the process.
Now, here's why this is a bad idea: e-mails are not secure. They are sent willy-nilly around the internet in plain text through multiple mail relays. All one would need is to sniff traffic on a network segment that the mail travels over and you'd have a hell of an easy time collecting login info. This is why the passwords sent over e-mail are supposed to be temporary, and why most good password reset forms ask for additional confirmation details before they let you reset the password.
You might think the above process would be secure if the link they send you is de-activated the first time you click it, but anyone could just keep sending more e-mail login requests and collecting the e-mails. The whole thing is pretty not-secure.
Thanks!
+ What if you lose your email account password?
If you lose you email account password, you'd need to follow the email service provider recovery process. Gmail, Hotmail, etc. have significant resources dedicated to helping people with this.
"Yes, logging in by waiting for an email and clicking a link does take longer than entering a password. But you should only have to do this once per device. Unless you’re constantly letting other people use your computers (and logging out of your email client each time), you’re golden."
or password managers