Show HN: Slick Login - Seamless Login which users will love it
slicklogin.com
slicklogin.com
Security is a hard problem and one that benefits from having a lot of people try to tear it apart.
what? don't.
I've already got something similar to act as a second factor to allow me to login to my work and home desktop machines...ya. I [and alot of other people] would need to do everything we can to make sure your patent is invalidated to prevent you from trying to sue us for something we've been doing since before you existed.
I'm not a lawyer and this is not legal advice. ;)
That is horrifying.
I'm curious as to what form that "local" connection would take. I don't think it's a problem to require an installed app on the personal device, but what are they doing on the web client? Does this require a browser extension to broadcast to/receive from the personal device? Maybe even a driver of some sort? That could make this less convenient than it seems. Sure you can always use the browser on your phone, but then this becomes a lot of rigmarole that reproduces the capabilities of client-side certificates. (Not saying THOSE are easy to use, but that technology already exists.)
I assume the "seamless" part you mention here means that no extra window etc etc... except that after i click login, it's now going to wait for me to pull out my cellphone? What if it isn't around? What if i lose it or I am out of battery?
I mean from a geek's point of view, sure it's pretty darn cool (ps: I am a geek too!) But from a general user perspective, is it really that much more useful?
Ok. How do I get out of this site?
Seamless Login which users will love.
or:
Seamless Login: which users will love it?
Any MOD here who can edit the grammar of the title ?
Also, every new login method requires user training. What does the user education process look like if you had to train and support them on (up to) seven different authentication methods? If a user gets used to one of them (say, proximity), how smoothly can you keep them educated that if they are in the subway, GPS won't work, so they need to try /method X/, then /method Y/, etc. That may be worth the effort to some services where security is absolutely paramount; hopefully anyone using this service builds in some heavy analytics to find out!
[1] http://blog.mailchimp.com/social-login-buttons-arent-worth-i...
I'd bet the proprietary technology is that the phone constantly emits some tone outside the normal range of human hearing (probably with some time varying value encoded in the frequency of the tone) which the mic on the computer listens for. Once the computer picks up the tone, it decodes the time varying value from the tone and from there proceeds like any other TFA login system.
There's also a question of what happens in a busy setting like say an office environment when multiple people are using this system and say two people attempt to login to a site secured with this at the same time.
The military uses two factor authentication (you need to insert your ID and know your username/password) as well as some corporate consultants. This bypasses the need to create coded ID cards and purchase card readers.
There is potential but still a few issues.
Maybe this is meant for corporate intranets more than end-users?
The problem is that I can take my gf / friend's phone during dinner put it next to my tablet and check their bank account. What are your thoughts on that?
As many comment, this is a pretty vague proposal.