5 ms·
The golden rule about storing a password is to not store a password... I can't wait till SQRL takes off
by mistat 10y ago
The golden rule about storing a password is to not store a password...
I can't wait till SQRL takes off
- pryelluw 10y agoFor reference: https://www.grc.com/sqrl/sqrl.htm https://www.grc.com/sqrl/sqrl.htm
- mataug 10y agoIt won't. See http://security.blogoverflow.com/2013/10/debunking-sqrl/ http://security.blogoverflow.com/2013/10/debunking-sqrl/ for a myriad of reasons. I've also come to realize that one should take everything that SG says with a large table spoon of salt.
- mtgx 10y ago> The proposed SQRL scheme derives all application specific keys from a single master key. This essentially provides a single juicy target for attackers to go after. That sounds like the same problem password managers have. And yet they are still recommended over (re-)using your own passwords for each website.
- teraflop 10y agoThe crucial difference is that with a password manager, passwords are protected by a master key, but not derived from it. So you can rotate passwords whenever you want, either proactively or reactively, mitigating the effects of a password database compromise.
- danieljscott 10y agoWhy is that? I've heard lots of people saying that, but not had any concrete reasons why. As far as I know, he's generally correct about the things he discusses. And pretty good at making technical discussions interesting.
- pkd 10y agohttp://attrition.org/errata/charlatan/steve_gibson/ http://attrition.org/errata/charlatan/steve_gibson/
- danieljscott 10y agoYeah, I've seen that site - 1 item in the last 10 years. Not a lot considering that he broadcasts 2 hrs a week. Maybe he's improved since the early 2000s? Anything else? I don't really understand the extreme reaction he seems to get.
- borplk 9y agoNonsense. Steve has been on public record for at least the past 12 years weekly on Security Now explaining things clearly and carefully. I've learned a lot from him and am very thankful. If he even makes a tiny mistake on a podcast episode about something he comes back with a correction the next week. He's been sharing his knowledge and expertise generously and a lot of people like me enjoy listening to him for 2 hours every week. If you have a criticism write it out properly.
- BoppreH 10y agoNote the protocol has been improved since then, for example by adding revocation features.
- tlrobinson 10y agoIs that at all likely? Looks like SQRL was published in 2013... and this is the first I've heard of it.
- tptacek 10y agoNo, it is not at all likely.
- yeukhon 10y agoI argue that one-time password with a secure MFA implementation is essentially the best viable solution.