4 ms·
The best security that an individual can get from passwords is clearly achieved by using a password manager and generating a unique random password for each sit
by warrenpj 10y ago
The best security that an individual can get from passwords is clearly achieved by using a password manager and generating a unique random password for each site, and changing high-value passwords periodically. (It's arguably already impossible for a human to generate or remember enough good passwords, and either way it gets harder as computers get better at guessing human-generated passwords.)
However, from the point of view of someone implementing an authentication system, passwords on their own are broken. There will be a significant fraction of users who re-use their password at a site with minimal-effort security. If you subscribe to the idea that computer professionals have a moral duty to safeguard people's private information entrusted to them, then password-only authentication is just broken.
The solution is to either: spend the money to implement a multiple factor authentication system (with a secure password database and fraud detection) or use a federated identity service. (Even just sending a one-time login code via email is fine). The latter is simple and takes even less effort than implementing a password system from scratch.
There should be fines (at the very least) for having an unsalted password database with more than X number of users.
- nyir 10y agoOr for an unhashed password database, c.f. http://plaintextoffenders.com/ http://plaintextoffenders.com/.
- unlinker 10y agoThe fact that your password is mailed in plain text to you when you register does not prove the password is not hashed when it's stored. In a "lost password" mail, of course, that's another thing.
- crottypeter 10y agoBut the mail is stored!
- ptaipale 10y agoFortunately, the mail is not typically stored in the user database, so acquiring it would take at least a separate leak.
- unlinker 10y agoBy you, right? Or is it common practice to store outgoing mails?
- jonathankoren 10y agoYou could always not store password reset emails.
- Bartweiss 10y agoArguably, sending a one-time password over email in plaintext isn't a disaster. It's stored, fine, but it's no less secure than the user's email account (that you were going to reset to anyway). If internal storage on the site is still responsible, it's not a huge concern. Of course, a truly healthy system also wouldn't allow email-only resets, but that's life.
- noja 10y agoA moot point. If they are sending your password across anything in plaintext, you just immediately lost a lot of the advantage you got from storing the password hashed.
- unlinker 10y agoIf they can hack into your mail they can reset your password anyway. (I'm not being technically correct here, but I'm being practical, and my argument here applies to 99.9999% of all cases)
- daenney 10y agoIt's not about hacking your email even. A significant amount of SMTP traffic still goes around unencrypted so just seeing that traffic fly by is enough to get the password.
- warrenpj 10y agoA one-time password system should also have a second token that was sent to the browser as a cookie over SSL. When the link is clicked the browser sends both tokens (the cookie and the OTP) together. The password is only valid for one browser. Also the OTP should expire after a short time. [1] It has the same security properties as a federated identity service like OpenID (except that it is less vulnerable to phishing.) Of course if you're talking about just a normal plain text static password, then it's obviously wrong to see it in an email. [1] "Simple Authentication for the Web" (2007) https://isrl.byu.edu/pubs/saw_TechReport%20%28revised%20March%202007%29.pdf https://isrl.byu.edu/pubs/saw_TechReport%20%28revised%20Marc...