Google Wants to Replace All Your Passwords with a Ring
technologyreview.com
technologyreview.com
It also means you dont have to worry about drivers, and can use it on whatever OS you want (OK, any OS that supports USB keyboards).
Ahh - just seen it's got NFC build in.
And you can get lastpass to remember certain devices, so you don't have to keep authenticating on your home laptop, for example (and you can always go to the site and revoke access to that machine if it ever gets lost).
It's pretty awesome.
Currently sold out. We expect new orders to ship in 7 weeks.
Who knows, watches may return, only with the bands as the holder for your key storage devices.
> One device should be sufficient with a reasonable number of websites for which users have accounts. But, for privacy preservation, the websites mustn’t be able to correlate users based on the device.
Since people have been kidnapped and forced to enter their ATM PIN to withdraw the maximum (often kidnapped near midnight so the gang can make two maximum withdrawals) this violent scenario isn't particularly farfetched. It depends what the ring gives access to.
Do you wear a ring? I ask because I used to think similarly, but now that I've worn a ring for a couple of years, I find them incredibly easy to remove.
Admittedly, some might wear smaller and tighter rings, but I think the good ol' twist & pull works in a lot of cases.
Having it work by proximity makes me a bit more uneasy, though -- I imagine someone brushing by your hand in the subway and authenticating with your bank then & there.
Maybe, maybe not, but there are all kinds of professions and occupations where rings must be removed for safety and/or security reasons. It would seem easy for a thief to be able to take advantage of those situations to get the "key" to someones online persona.
There are alternatives: 1. Point gun and say give me the ring with your entire identity on it. 2. Chop finger off and take the ring.
Becoming the bearer bond of my identity seems like a very bad idea.
Here's a copy of the most important parts:
---
(One ring to rule them all, anyone? ;) )
Anyway.
"using personal hardware to log in would remove the dangers of people reusing passwords or writing them down"
Shit yes, writing passwords down and putting it in a drawer at home is so much more vulnerable than stealing the one thing with which you secure all of your accounts and take with you. And how is one-factor authentication that someone has to force out of you (password) worse than one-factor authentication that someone has to rip from your finger and run away with? People apparently can steal watches without the bearer noticing, what the hell am I supposed to think of a ring?
"Everyone is familiar with an ATM. What if you could use the same experience with a computer?"
An ATM requires a PIN-code. Your second factor (a 4-digit password) that is validated by the IC on your card and provides some sort of secure authentication.
People should be doing a risk analysis of their online services, so they can decide what kind of password security is useful to them.
I'm a big fan of writing passwords down and keeping that list in a secure place. But some people (eg, in offices) don't have a suitably secure place to keep those passwords. This device would be handy for them.
http://www.computer.org/cms/Computer.org/ComputingNow/pdfs/A...
Ach. Such a missed opportunity.
"ONE RING TO RULE THEM ALL"
It looks like the Workspace versions support Windows To Go for a managed portable OS scenario. I wonder at how robust that can be against a malicious host.
Having a keyfob to log in is pretty standard security practice. The only thing that makes a ring different or interesting is that it's an easier form factor, and I presume it would have wireless capabilities so you don't have to actually plug it in for it to work.
http://appadvice.com/appnn/2013/03/report-the-iphone-5s-will...
A hardware key, on the other hand, can be almost arbitrarily big, is upgradable and totally random.
A real key is 100% reliable if you have it and 100% secure if you don't.
Having recently married and struggling a lot with the ring issue (basically lots of money for a useless piece of metal), the idea of a wedding ring with some badass electronic capabilities has crossed my mind, though.
Unlike LastPass and many other password managers, they are fully offline.
Also, Keepass has full mobile support as well as many plugins, including auto-login on browsers.
2. There's no universal method for connecting a mobile phone to another device.
3. Besides, what if you require authentication without a password, on a mobile?
4. The closest to a universal method for interdevice connection is USB. Most importantly, a browsing-capable device almost certainly has a USB interface.
Hence, efforts like Yubikey.
I guess, in a sense, I wear the keys to my car basically everywhere I go.
You'd need to have those passwords backed-up anyway, either somewhere locally or in the cloud, so you can retrieve them later. You could also make it so you have to "reconnect" with your PC account or whatever every 24 hours, every week, etc.
I'm sure there are other ways to keep this safe, too.
The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost interest in hacking something neat.
Uh... actually, since it's just radio waves, I don't think there's any manufacturing involved. If you can transmit an identical signal at the proper time, regardless of the source, you can spoof an object.
An RFID chip is just a transponder. A tiny antenna, wired to a circuit that reacts to radio waves in a specific manner, with a specific transmission. It's not a prerequisite that the antenna and circuit must be tiny and/or embedded in a chip. Any radio equipment that can send and receive radio transmissions will do.
Also, they tend to be mostly passive, so it's just a big string that you present to the computer, rather than a decent challenge / response.
The C/R is what makes the article interesting, and it's what's holding me back from buying a Yubikey. (Which does a convoluted form of C/R, but on Windows.)
That's why I lost interest. The smart cards that do active (async) encryption for a proper challenge/response are all contact, rather than contact-less.