5 ms·
Passwords will continue to exist. But it has a lot of flaws, so it's nice have alternatives.
by rodorgas 8y ago
Passwords will continue to exist. But it has a lot of flaws, so it's nice have alternatives.
- ehsankia 8y agoIs there a solution for the fact that all of your accounts will be secured by the same "source"? Isn't this almost close to using the same password on every site? I realize a physical secret is better than a password, but if someone gets their hand on your little FIDO device, do they instantly get access to all your accounts?
- AgentME 8y agoThe big problem with using the same password on multiple sites is that if any of the sites record your password (because of maliciousness or incompetence), they can re-use your password to log in as you on any other site. Using a security token is more like a password manager with random passwords everywhere than that (the attacker needs to get access to your password manager to get access to your accounts; it's not enough for someone to hack a single site you use), but more secure because it's generally not copyable and the attacker needs physical access to use it. (A virus on your computer can't clone your security token, even if it's plugged in.)
- ehsankia 8y agoThat's fair. Although, for my password manager, you need both password and 2FA to access it, whereas a FIDO key would just require stealing the physical key. Does there exist FIDO key (other than phones) that require a password to "enable"? For example, when it's plugged into a new device, the key locks until you input some master password?
- jontro 8y agoThe Ledger Nano S requires you to enter a pin code at least
- rkeene2 8y agoMost smartcards require you to authenticate to them before they will perform operations using their private cryptographic keys. I'm adding WebAuthn support to my smartcard middleware [0]. [0] https://cackey.rkeene.org/ https://cackey.rkeene.org/
- forgotmypw7 8y agoWho said anything about using the same password on different sites?
- MaulingMonkey 8y ago"Isn't this almost close to using the same password on every site?" is in the post AgentME is replying to.
- MaulingMonkey 8y ago> Is there a solution for the fact that all of your accounts will be secured by the same "source"? 2FA is still an option (e.g. 1 thing that you have + 1 thing that you know), with the hardware token representing a more secure alternative to phone SMS messages. > Isn't this almost close to using the same password on every site? To get the a shared password, you have to hack one of hundreds of different services that password is used on, or phish the user, and penetration often goes undetected for years. To get the physical secret, you have to rob the user, who will notice they've been robbed the next time they attempt to login. Additionally, trying to login to a phishing website won't automatically auth them with the real website - I can't do secure key exchange algorithms in my head, but a hardware device can.