HNHacker News
TopNewBestAskShowJobs

markkum

65 karma · joined March 17, 2011

Founder & CEO of Mepin / Meontrust Inc. Serial entrepreneur, serial father, cereal lover ... password hater.

www.mepin.com

submissionscomments
markkum··on When passwords attack: the problem with aggressive password policies
You are right. The sentences were hastily written.

The hardware key is in private beta and will be publicly available soon. We have evaluated half a dozen smartcard technology vendors and are partnering with a couple of them, so we can deliver a key with or without FIPS certification depending on your cost consciousness and security requirements. Please e-mail me for additional info.

markkum··on When passwords attack: the problem with aggressive password policies
Good smartcard in general cannot be copied and it will not work without the user's pin code. It can also lock itself if the pin code is entered wrong too many times. But most importantly, the keys/certificates inside the smartcard can be revoked remotely if the smartcard is lost. So even if the wrongful holder of the key has somehow got hold of the pin code, he cannot use the key for long.

Nothing is perfect of course. The risk/threat is very similar to someone stealing your phone and has somehow gotten to know your master password to your password management software. However, password management does not really solve neither the usability or the security problems of usernames and passwords ... although a good piece of software can certainly help.

markkum··on When passwords attack: the problem with aggressive password policies
Umm ... your conclusion is kind of funny and wrong. You might not be familiar with cryptography, modern smartcard technologies, and how those can actually keep a secret.

I agree with your assessment on facial recognition and fingerprints, though the biggest problems with the fingerprint authentication are the lack of ubiquitous sensors and privacy issues.

But password manager software is better than nothing ;)

markkum··on When passwords attack: the problem with aggressive password policies
Phishing is the biggest risk/threat. An average user is typing in his username and password if presented with a decently familiar login form no matter what the browser address bar or the rest of the web page says. Unfortunately the PayPal and Verisign keyfob security codes can also be phished.
markkum··on When passwords attack: the problem with aggressive password policies
We currently support OpenID, so any site/service supporting OpenID works with the Mepin keys. Sadly there are a lot of shaky OpenID implementations out there, so yes the implementation is a challenge. And I do also agree that we will never get rid of all the passwords.
markkum··on When passwords attack: the problem with aggressive password policies
Our USB key cannot be easily, if at all, copied. It's based on smartcard technology used by banks and governments around the world. It's not a memory stick.
markkum··on When passwords attack: the problem with aggressive password policies
Good article, though the whole premise of people being forced to manage passwords is screwed. We are working hard at Mepin - www.mepin.com - to get rid of passwords one by one. Our premise is that people are much more capable of managing a key - a physical key like a phone or a USB key. Care to agree?
markkum··on Steve Blank - What's wrong with business development?
I did work very closely with the product development, however actually my question was why the title Business Development seems to give negative vibes for people? And is this the case all over the world?

The job I was denied btw was a sales job and the feedback was that my Business Development experience was not sales enough.

markkum··on Steve Blank - What's wrong with business development?
I fully understand and agree with Steve's point against hiring sales people before finding the product/market fit.

However, at least in my mind, in a bit larger organization it is the Business Development people who continues to do the customer development work while Sales is focused on 'exploiting' the first found fit (which might or might not be a big one).

markkum··on How I got a burnout
I had my worst burnout symptoms at a 9-to-5 job after I sold my first startup. That's how I realized I'm an entrepreneur. I left the job and the lockup shares, and have since been happy, sometimes rich/stressless sometimes poor/stressed, 24/7 startup kind of guy.
markkum··on The Definitive Guide To Website Authentication
You should look at two-factor authentication solutions to solve many of these issues. For example https://www.mepin.com is a two-factor authentication service free to integrate and use for the websites. It supports standard OpenID interfaces, so no proprietary integrations needed.
markkum··on Proof-of-concept public key authentication for web users
This is exactly what we are building here; https://www.mepin.com The private key is generated and stored in a smarphone or separate USB smartcard, so that normal users don't have to manage their private keys.
← PreviousPage 2 of 2