4 ms·
The reason it's not used more often is only because it's incrementally better than salted and memory-hard hashed passwords. It has obvious and important benefit
by dev_dull 8y ago
The reason it's not used more often is only because it's incrementally better than salted and memory-hard hashed passwords. It has obvious and important benefits, but still only incrementally better.
It's more important that bad implementations are removed immediately. Personally I'd rather get rid of all of my passwords and use FIDO2 or perhaps even something through touch-id on my iOS/Mac. At this point every password I have is unique thanks to great password managers.
- DINKDINK 8y ago>Personally I'd rather get rid of all of my passwords and use FIDO2 FIDO2 should be implemented in many more areas but it shouldn't be exclusively relied on for authentication. Authentication should require proof of person/entity (something you have, a FIDO2 key) and proof of volition (using a password stored in their brain that their will decides to produce/disclose)
- floatboth 8y ago> their will decides to produce/disclose Or someone else's will decides to shoulder-surf / keylog the password :)
- floatboth 8y agoUSB/NFC tokens and phones/computers are all "loseable". There are cool ideas about backup tokens https://dmitryfrank.com/articles/backup_u2f_token https://dmitryfrank.com/articles/backup_u2f_token but IMO they can't be the only way to sign in, there should be some way to restore access from nothing (I guess my specific paranoia is about being locked out :D) There are many specific auth "factors": - valid signature from an extrernal hardware token (U2F/WebAuthn via e.g. YubiKey) - valid signature from a device's embedded token/TPM (something like Touch ID / Windows Hello / Android keystore thing) - … as a WebAuthn implementation - … in response to a push notification on another device (Twitter, if they still have that) - … in response to a QR code (SQRL, Yandex.Key) - one-time code via push notification to another device (Apple) - one-time code generated from a shared secret key (TOTP) - one-time sign-in link via email (Tumblr) - passwords - secret questions (like extra passwords but worse) - behavior pattern analysis (IIRC Google showed an Android demo that looked at keyboard typing patterns and whatnot) A good auth system should combine multiple factors in a correct way to minimize both impersonation and lockout chances, and maximize usability. How? That's the challenge…