Kill the Password: Why a String of Characters Can't Protect Us Anymore
wired.com
wired.com
I simply don't believe this. Absent a keylogger or some massive security breach with Google themselves, I can't think of any way an attacker could get into my gmail account short of rubber-hosing.
The author hand-waves all of this by saying "let's say you're on AOL". Well, let's say I'm not. Let's say I have an account at Gmail with a > 20 character password and a > 20 character answer to the password reset question. If someone can break into that within a few minutes, they are severely undercharging at $4.
"The hackers persuaded Apple to reset my password by calling with details about my address and the last four digits of my credit card. Because I had designated my Apple mailbox as a backup address for my Gmail account, the hackers could reset that too, deleting my entire account—eight years’ worth of email and documents—in the process."
For anyone who had an email account prior to Gmail's launch in 2005, I'd wager there's an excellent chance that they initially linked their prior account to their Gmail account while signing up. In fact, reading this article has made me realize that I'm in the exact same boat; I still have my Gmail address linked to an ancient, dormant email account on a relatively-insecure service (I trust them more than AOL, but not nearly as much as Google).
If you're the target of a directed attack, you have even more to worry about.
[0]: http://support.google.com/accounts/bin/answer.py?hl=en&a...
For the record, I've had viruses and have been hacked in the past, but it never did any significant damage. Accounts are separated (unlike the writer of this article's), different services on my server are isolated as much as possible, I use a number of password levels, etc. The hacks were due to carelessness, something that can always happen accidentally. What should not occur is that you're completely fried when one account or one technology fails, like the writer of this article was (his twitter got hacked, all Apple devices were wiped).
What I think should happen is an improvement in terms of how we store password (for starters, don't write them down and put them next to your pc), how we enter passwords (keylogger vs. password manager hacked problem), how passwords are transferred, how passwords are handled on the server, and how we can do password-equivalent actions. By password-equivalent actions I mean anything that bypasses the need for the password, such as password resets.
When these things are improved, passwords are still perfectly fine in 2012. For high-risk systems such as banks you surely might want to use two-factor authentication, but generally a password should be fine - or at least an option for those who think they can keep it safe.
That's not stupid, that's just how folks who have other stuff to worry about in their lives, do with a technology they hardly understand. Security frameworks even for banking systems primarily depend on passwords and little else. It's similar to "getting past the gatekeeper to the fort, and then having access to the Armory, Queens Chamber and the Royal Safe". Access should not be granted because you could recite 10 characters in the right order. It should be granted after having fully understood the context of your attempt, the history of the account and the account holder, and doing KBA (knowledge based auth) commensurate with the damage that could happen if the wrong person accessed that account.
Passwords should die a horrible death. They are a mere fallacy. An illusion of security.
If that is so relevant, we should also kill online (and offline) banking, selling used cars and insurances etc. ... Because clueless people will get owned and scammed everywhere.
What the article neglects is pointing out the total failure of Amazon, AT&T and Apple to protect their customers. It's complete nonsense to allow identity theft on the basis of information that is easily obtainable (credit card and social security numbers - they've been exposed hundreds of times and are no secrets). Class action suits might fix that in the long run, but at least don't blame passwords when they weren't the weakest link.
No, because although some people may get scammed, there is still massive overall benefit to those services.
We are using the same method of authorization that was going on 1,000 years ago. "Sentries would challenge those wishing to enter an area or approaching it to supply a password or watchword, and would only allow a person or group to pass if they knew the password."[2]
This method has no context in a world bursting at the seams with sharing, connection and relevance. Who are you, where did you come from, who is with you, what is your purpose and how did you get here?
It should be contextual like: What is the speed of a swallow? (African or European?)[3]
[1] http://www.cl.cam.ac.uk/~jcb82/doc/B12-IEEESP-analyzing_70M_... [2] http://en.wikipedia.org/wiki/Password#Alternatives_to_passwo... [3] http://www.youtube.com/watch?v=pWS8Mg-JWSg
Wrong. Passwords have worked well for decades. They are, by far, the best balance between convenience and security. Service providers need to do a better job of taking into account other factors (IP addresses, cookies, recovery techniques) to mitigate breaches.
Passwords are here to stay. They provide reasonable security.
Words.
Since the premise of the article (and the person to which you've replied) is that your statement is false, you're going to need to provide more than the above to refute it.
I did not make the irony clear, my fault.
I'd bet that only a small fraction of a percent of accounts are hacked in a given year (by password or otherwise).
Though there's room for improvement, lets not pretend that currently popular security measures do nothing.
But one thing that a lot of this glosses over is that different accounts need different levels of protection. I really want things like my bank account to offer stronger protection than a password. On the other hand for things like my hackernews account and my dragongoserver account they are probably plenty and its not worth additional inconvenience to have more.
It would be like saying your average bike chains are dead because they can be defeated by bolt cutters. Bike chains are plenty of protection for an average bicycle, but I want something more protecting a safe deposit box.
If they have 'other stuff' why they spend so much time posting about memes, or TV shows or other meaningless stuff?
When I was in high school only nerds would know what's a hard drive, or what's an email address. Now everyone seems to know something about computers, everyone has emails and twitters and other things (even if they don't know what a MFM encoding is).
The same can be true for password security.
Honestly, computer security is important, and therefore should NEVER be dismissed with the 'other stuff to worry' hand-wave. If someone doesn't know about it, they should learn.
If passwords are to be changed for a better technology, nothing changes about my point: people should learn to use it correctly, whatever that is.
It's a great idea in theory, but the execution is the trick.
Actually, given today's attack vectors, this would be an improvement. Remote attackers have greater and greater ability to compromise an account, but if the "key" is physically hidden away then it becomes an unreachable needle in a the massive haystack that is our physical world.
(I'm speaking theoretically, of course, this does nothing to protect the user from the kind of attacks that are most common: phishing and social engineering)
When the password is a stickie next to your computer, then the most imminent risk is that the janitor or a coworker will filch from you. Then have your password be something you put on a sticky save for a memorable number that you prepend to it (but not something too guessable, like your birthday). The chances that this acquaintance who goes snooping around your physical cubicle is going to also run a brute force crack is pretty slim...because such a person will likely have an easier way to violate your privacy/thieve from you.
# Tired of hearing you cry about getting hacked dude. Get over it. #
#This guy is the laughing stock of our organization, he's almost achieved meme status. This guy is a "technical" writer at Wired for god sakes. A magazine I've been reading since almost Issue 1.
He's comes off as if he's been traumatized by the experience, like he's survived some sort of violent crime. It's an insult and he just keeps milking this experience over and over again.
I've been working in IT Security for almost a decade, his experience is trivial compared to some of the incidents I've worked and seen.
Maybe he's just milking his tale as link bait, who knows, but I'm tired of hearing him whine.
Grow a pair and move on.#
#"Tech writers" that don't backup or protect their data obviously chose the wrong career. Honan is a bigger joke than Wired has become.#
Clicked through to the article expecting something interesting, left almost immediately upon realizing it was just Mat Honan milking his hacking once again.
No, you had one 'robust' password, one good password, and one godawful password that you should feel bad about not securing better.
And then you linked all of the account together, basically putting all the keys in the kingdom in the weakest safe you had.
It was a poor decision, and has nothing to do with the strength of passwords as a data protection mechanism.
Fantastic.
Some comments here seem to imply that having a strong Gmail password and having a weak Twitter (or whatever) password will somehow make it easier for a hacker to get into your other accounts. It all hangs around that word "linked" that I don't quite understand. But I see from other comments that the story is that the offenders went through Amazon to get someone's Apple password. That makes sense after reading the full story.
related: mythbusters hacking (a probably not that advanced) fingerprint protection http://www.youtube.com/watch?v=3Hji3kp_i9k
Today I've read one of Polish banks is going to test out fingerprint ATMs. Not that I have ammounts worth cutting my thumb off, but I wouldn't opt-in for that.
http://spectrum.ieee.org/biomedical/imaging/the-biometric-wa...
Neither do I, but attackers don't know that.
On the other hand, cutting off someone's thumb is probably more effort than leading them up to an ATM at gun-point. I'd be more worried about spoofing the scanner itself.
Things like BrowserID/Persona are what web sites should be moving towards - verify my email address is real, don't ask me to manage a set of data to log in with.
Edit: Here's the kind of thing you can do without ever needing to go near passwords: https://github.com/wrr/wwwhisper#readme
The point being that no new password comes into being, and I don't have to worry about yet another site having a password I have to manage.
On the other hand your smartphone can get more secure with updates and your token provider will surely be much harder if at all possible to upgrade.
Anyway the point is moot, if such a scheme is ever viable (as in most people will have one and you can implement it in many websites without having to be a bank) it will be through smartphones.
Not a solution for everybody, but it would be nice if it were at least a possibility.
The password requirements of my current company have got so insane now an average human cant remember them and therefore have to write them down
Defeating the point of having a secure password in the first place.
Delegated authentication designed from the beginning to be secure is the solution. And we've had technical implementations of that going back at least 10 years (Microsoft Password, client-side SSL, OpenID). The reason they haven't succeeded is a combination of product design and political problems.
Mozilla's BrowserID / Persona project is looking promising. Tim Bray at Google has also been talking about identity a lot lately, maybe Google will offer a solution too.
If having an Apple account gives that much control over your data, then that's your own fault for having one in the first place.
He lost me at seven.
My AppleID password is pretty secure (~25 characters, upper/lower case, alphanumeric, bunch of symbols, etc.) and having to type it in on an iPhone/iPad every time I want to download an app (even a free app, or updating an app I've already purchased) makes me want to cry.
I think I'd rather stop reading FUD articles on Wired written by noobs, than give up passwords.
I've quizzed most of the people I've encountered who claim to use this technique. They all use four words that "pop into their head". That's quite a big different from using random words, and almost certainly much weaker.
Obligatory: http://xkcd.com/936/
* Trusting the 'cloud' (by whatever name) to the extent that you don't keep a local backup of your important data.
* Linking all your online accounts together for the convenience of anyone who wants to hack them. (I like to think of this a the 'gift-shop-attack"; The castle seems strong and easy to defend, but there's always a gift shop with just a little old lady watching over it!)
* etc. etc. etc.
And this is exactly why I have an offline copy of all important documents. It's just a humble 1 TB USB drive that gets synced once in a while. I keep it at the office, just in case the house gets burglarized.
Actually, two offline copies would be better. Gotta think about that.
His accounts were all linked together - gaining access to one made it easy to gain access to others. Social hacking was used to either gain access to accounts and/or change the passwords.
Do we as an industry need to improve how we store passwords and manage interactions that could allow unauthorized people to take over or otherwise gain access to accounts? Yes. Does that mean doing away with passwords? No.
Emphasis mine. Enough said. Passwords are still pretty secure; two-factor authentication makes it even more so.
My gmail password is the safest (longest) one. Nothing else uses that password.
Then it comes the second layer. I use a safe (16 chars) password for other services that are not gmail.
Then third and fourth layers, for diminishing levels of importance, each layer has a password.
And finally a somewhat insecure (14 chars) for the standard fire and forget services.
I definitely reuse the insecure password a lot. And I don't care.
Give me a break...
Something to make it more visual would be cool. If I could go to a site and draw a little picture in a box (obviously this is better suited for touch devices), I think that would be pretty hard to crack. Right (I'm the furthest thing from a security expert)?
The problem with passwords is not their strength. It's not the passwords themselves. It's the way people use the web. For example in the article the author mentioned that because he had all the accounts linked, breaking one meant ability to break the others. Well duh! Perhaps try NOT linking accounts together like that next time?! Oh? It's hard? It's not. It's inconveinient. We're lazy and we want our stuff to be in one place, "cloud", because "it just works". And when shit just hits the fan, you're screwed. Not because of passwords, but because of the way you manage your "digital life".
The whole "digital life" concept is utterly retarded from security point of view. Not the passwords.
Think about every massive online success, past and present. MySpace, for example, was not fundamentally different than how you could upload an HTML page to a server...though designing and maintaining links is obviously work beyond the average dedicated developer. And Facebook was not fundamentally different than MySpace, but its news feed eliminated the work of visiting every friend's profile to figure what happened today, which made it much more likely that you'd be "rewarded" (in the psychological sense) for visiting facebook.com rather than myspace.com...
And so forth. The password encryption schemes used as an industry standard are quite secure against a brute-force, random intruder. So social-engineering is a much more viable way to break-in...and why does Bob read his password over the phone to someone claiming to be from IT rather than take the time to verify the integrity of the transaction?...Laziness.
What's the answer? Have all sites use OAuth and delegate to sites like FB / Twitter and hope they get more secure?
I've seen sites like http://www.loginprompt.com that try to provide authentication as a service, but they're all still fairly rudimentary or expensive.
But my whole strategy is defeated behind my back because of this idiotic OAuth/whatever technology. Now only one of my accounts needs to be hacked on a high profile site and suddenly every site that gives an OAuth option is compromised for me, even though I've never used OAuth one time.
80 000 ATMs in Japan use vein scanners.
Biometrics are used as part of a three-factor system.
http://spectrum.ieee.org/biomedical/imaging/the-biometric-wa...
it supports a number of OTP flavours (OATH-HOTP, OATH-TOTP, mOTP etc.). GOOG and others also provide OATH apps, ie:
http://f-droid.org/repository/browse/?fdfilter=OTP
all FLOSS and work with standard services. If you prefer a hardware token, inexpensive Yubikey tools come with every Linux distribution.
- Carry one OTP device and authenticate to a federated identity service
- Carry an OTP device which can embedded several OTP seeds such as a smart card
I'm sure there are quite a bit of downsides to this method and it will resort to even logging in with some sort of "password."
Memorable passwords are in your brain for the long-term, and can't be lost or stolen. (Well, aside from improbables like torture.)