24 ms·
Microsoft ruined passwords, now aims for a passwordless future
- rastafang 5y agoembrace... "extinguish", etc
- triska 5y agoIt is really interesting how long we have collectively tolerated, and continue to tolerate, many counterproductive password policies and password-related software problems and limitations that are explained in the linked talk and that affect many different software products, such as not being able to enter very long passwords in many applications, or having to change the password periodically. The xkcd quote mentioned in the talk sums it up nicely: Through 20 years of effort, we've successfully trained everyone to use passwords that are hard for humans to remember, but easy for computers to guess. Relatedly, YouTube - where the talk is hosted - informs me that it will require 2-factor authentication starting on Nov. 1st for accessing YouTube Studio: Action required: Turn on 2-Step Verification by November 1, 2021 or you will lose access to YouTube Studio I wonder whether this would be necessary if better password practices were established, so that more secure passwords can be more readily used. The linked NIST guidelines are interesting, and include pertaining recommendations such as "Do not require that memorized secrets be changed arbitrarily (e.g., periodically) unless there is a user request or evidence of authenticator compromise.": https://pages.nist.gov/800-63-3/sp800-63b.html https://pages.nist.gov/800-63-3/sp800-63b.html
- dheera 5y agoAnd sometimes their 2FA is SMS based. I don't use SMS. I don't use hardware phones in my workflow. For Microsoft Teams I have no choice but to direct the call to a Twilio number and use a script to answer it and automatically hit #. If you want 2FA, have support for hardware keys. Period.
- brendoelfrendo 5y agoI recently bought a second Yubikey and wanted to go through my accounts to add it as a backup; you know, have one locked up so that if I ever break my primary, I'm not SOL. Not only do only about half a dozen services I use actively support hardware security keys, even fewer support enrolling more than one. Worse, many only support SMS 2FA as the backup option, which I just can't abide.
- dheera 5y agoRight, AWS is the biggest offender of this. Also, Coinbase, Kraken, and several others. Seriously, deprecate SMS already. I deprecated it 10 years ago.
- Closi 5y agoSounds like your organisation has just limited the 2FA options in the auth settings. Hardware keys are supported on Teams, along with software phones (that have a static number / extension) and a linked desktop/mobile app. In fact FIDO2 hardware keys like Yubikey are part of what Microsoft refers to as ‘passwordless’ - see https://docs.microsoft.com/en-us/azure/active-directory/authentication/concept-authentication-passwordless https://docs.microsoft.com/en-us/azure/active-directory/auth... I assume you aren’t an admin on the account just because otherwise you could just disable 2FA properly rather than disabling it with a weird twillio workaround, although I have to give you credit, this is the most effort I have seen someone put in to subvert a security policy.
- dheera 5y agoYeah I'm not an admin on the account and have no control over it. An app doesn't work for me either, When I have a big rack-mounted immobile desktop that should if anything BE the 2FA device, if anything, not a 6-inch easily-stealable device.
- hirsin 5y agoWhich gets you back to the problem OP has - trusting that device enough to make it a secure root of trust. Windows lets you do it, so do Android and iOS. But your admin, maybe not (or you're not on windows, which is more likely I guess).
- rkeene2 5y agoNot everyone has tolerated passwords. US President George W. Bush signed a Presidential Directive directing all parts of the US Government to make and implement plans for getting rid of passwords in August of 2004.
- meowtimemania 5y agoI’m looking on google for more information but struggling to formulate a query that yields good results. What were the results of this directive? Does the government no longer use passwords?
- hunter-gatherer 5y agoI left the IC just over a year ago and we were still using passwords. Although, the RSA tokens had just been rolled out. Most likely everyone on JWICS (if someone still in the space can correct me, please do) has now moved to a PIN+RSA token. The government moves ever so slowly on some issues. I wouldn't be surprised if a directive on password policy signed in 2004 took 15 years to implement.
- nonameiguess 5y agoIC users on JWICS use IC ITE PKI. You get issued a client cert and key when you get an account, and that is used to authenticate you to all web-based services. Additionally, it links directly to your clearance, so it automatically redacts content based on the portion label, meaning you can do something like load Intellipedia and it will not show you parts of pages containing information you have inadequate clearance to see, but still show you everything else. 2FA is implemented by requiring you to unlock your private key with a 8-digit pin. It is light years ahead of the public world wide web. But, of course, the problem is a lot easier to solve when you have a single source of identity for every user and every user only has a single identity. Something like this is impossible if you want any level of anonymity, but users of government systems have no expectation of anonymity.
- Jtsummers 5y agoMy experience was with DOD. They made major strides by 2010 to use smart cards (CAC) for access control to all the major systems. Some systems still had passwords, but everything new was supposed to use CAC and everything old was being migrated to support CAC in addition to passwords, ideally dropping passwords (not always possible due to how some things were accessed).
- ncphil 5y agoThis is a major change from the original NIST guidance that MS & dog previously followed. It turns out the author of that guidance admitted not so long ago that it was basically rubbish: just like the half dozen or more boxes that security managers have been mindlessly checking since 2004 (to be sure many of those misguided policies had become canon long before being enshrined in NIST's standards). It was the snakeoil press that made millions (billions?) for the producers and actors engaged in over a decade of security theater. The independent genius and intellectual courage of XKCD's author can only be fully appreciated against that background. https://www.engadget.com/2017-08-08-nist-new-password-guidelines.html https://www.engadget.com/2017-08-08-nist-new-password-guidel...
- varenc 5y ago2FA is necessary because users still consistently fall for phishing attacks. Password policies wouldn’t effect that. There’s also the password reuse problem, though better policies might discourage reuse, it’ll still happen.
- deleted 5y ago[deleted]
- echelon 5y agoWho needs passwords when your identity is owned by a corporation? Use your^W the newest rented iDevice in your vicinity to confirm your identity. Make sure to replace the device regularly and have an active subscription to our movies, music, spying, and more services so that we can fulfill your banking login request today. It's important that you eat so that you may work and consume more. We'll charge the customary 55% fee to everyone you interact with that isn't in our device platform bubble. Make sure not to log in with their account system or you may find your identity reputation score lowered and your chat bubbles rendered in poop brown to your peer group. How disgraceful. Remember to buy our official chargers. Here are some ads from third party sponsors. Thank you.
- userbinator 5y agoExactly. The authoritarian "security" industry is largely to blame for helping to build this dystopia of corporate control.
- rrobukef 5y agoMore than three decades of bugs, crashes, worms, virused, trojans, hackers, scammers, social engineering, ransomware, idiot users and the occasional battery fire. I'd secure my device as well.
- hammyhavoc 5y agoA forbidden thought.
- citrusynapse 5y ago"Remember to buy our official chargers. Here are some ads from third party sponsors." Holy hell this hit hard.
- dane-pgp 5y ago"It's as simple and painless as letting us record the unique biometric markers in your right hand or forehead, and then you're on your way to enjoying the global economic system that you're required to use. Just make sure you agree to the 13,000 word self-updating terms of service, and don't use our devices to express any opinions that go against the set of socially acceptable beliefs that our company expects all its employees and users to hold."
- mastrsushi 5y agoOn Windows being a nursing home. I found desktop Linux to be more like nursery school. Windows is when it’s time to put the toys away.
- hammyhavoc 5y agoI found Linux to be a workshop of tools for work and science. Nothing "nursery school" about that.
- autoliteInline 5y agoIt isn't like Windows is a toy I admit. My view is that it's the result of decades worth of customer demands (scarcely any of which I need) and a tendency to feature creep to do major releases. The cruft in a thing like that is remarkable.
- Spooky23 5y agoThis was a really weird article that reminded me of circa 1999 Slashdot. It’s easy to throw heat at Microsoft. But… 2021 crypto and security is different than 1991. The standards this stuff was built around were for an era where local dictionary attacks were common and a serious threat. They still are in many scenarios. If you’re going to throw shit at Microsoft, attack their head in the sand approach to NTLM, their implicit deprecation and failure to develop AD further and prioritization of monetization over baseline product needs.
- mc32 5y agoIf my understanding is right to this day on prem AD does not salt its passwords and MS is not doing anything to address that weakness. That should make everyone tear out their on prem AD.
- Spooky23 5y agoAD exists as it does today because they were able to meet the USGs definition of a distinct crypto module in the 90s, and it’s too popular to break by policy.
- lukeh 5y agoAES keys are salted. Moreover, if you use public key authentication (e.g. smartcard, FIDO) it's not a requirement that any keys are provisioned on the user. I'm not sure if you can disable the generation of the NTLM key when using passwords, though (and it's true, that is unsalted).
- initplus 5y agoActive directory is on the back-burner because it just doesn't have the same growth potential as other products. Everyone who wants to use AD is already using it, and the market size is limited by the number of employees at businesses. If a business grows their customer base by 100x, they don't grow headcount at the same rate. But their resource consumption of cloud managed services will increase more proportionally to the customer base.
- 5y ago
- webmobdev 5y agoExcellent article - "passwordless" is Microsoft's (and BigTech's) attempts to take away more control from us, similar to Apple's "delayed" attempt to violate our rights by scanning our device for "illegal" content (begining with CSAM).
- hughrr 5y agoI want my passwords back. Windows hello doesn’t know who the hell I am until after lunch.
- hammyhavoc 5y agoIt knew who you were before lunch?
- bdamm 5y agoThe author's conclusions are naive on a couple of fronts: o Passwords ARE fundamentally broken and they do not put you in control. Passwords must be shared to work, therefore they can never truly be secret. Only a private/public key pair can even hope to authenticate an entity. o Surveillance is present in all neighborhoods. The realm of free software is home to surveillance by the network, and attacks on the software ranging from distribution to zero days to common misconfigurations. To top it off, the author perpetuates an anti-pattern, which is to place faith in the idea of password policies at all. NIST has recognized the pointlessness of password policies and now simply recommend that passwords are compared against databases of known passwords. Fortunately we don't need to wonder what to do. WebAuthN is here now and has been ready for a couple years now.
- NieDzejkob 5y ago> Passwords must be shared to work, therefore they can never truly be secret. That's not entirely true, as demonstrated by constructions like PAKE. It is a shame, though, that the adoption is almost nonexistent.
- acdha 5y agoThat's probably an interesting lesson in its own right: PAKE originated in the early 90s and if it's still facing adoption barriers that suggests that the model is fundamentally untenable.
- thaumasiotes 5y agoNot really. Compare https://www.johndcook.com/blog/2008/03/25/innovation-ii/ https://www.johndcook.com/blog/2008/03/25/innovation-ii/ An English captain ran a private experiment in 1601 to see what happened when sailors were fed lemon juice. The group receiving lemon juice had zero cases of scurvy. The group not receiving lemon juice experienced 40% mortality from scurvy. (Imagine running an experiment today with 40% mortality in the control group!) The results were reported, but nothing was done with them. The navy had to rediscover the same fact a few hundred years later. But there was nothing wrong with the model.
- Ajedi32 5y ago> This baseline 12-character minimum means folks won’t be tempted to reuse their insecure (but technically complex!) 8-character password mullets from other sites. Instead they'll re-use their insecure (but technically complex!) 12-character passwords from other sites. So much better. /s Face it: passwords suck. They're far too easy to misuse (re-using compromised[1] passwords from other services) and far too difficult to use correctly (long, random, unique passwords for every service). At this point I'm inclined to support just about any alternative that isn't even more horribly flawed. Ideally yeah, an open source solution would be preferred. WebAuthn nearly has this solved for the web; we just need a cross-platform authenticator for it. For local device logins (such as to Windows PCs) neither WebAuthn nor password managers work particularly well, so I'm glad Microsoft is exploring alternatives there. [1]: https://haveibeenpwned.com/Passwords https://haveibeenpwned.com/Passwords
- UncleMeat 5y ago> Instead they'll re-use their insecure (but technically complex!) 12-character passwords from other sites. So much better. /s Yeah. In fact, I'd wager that longer password lengths make reuse even more common if people aren't using password managers.
- alerighi 5y ago> long, random, unique passwords for every service Using a password manager is not that difficult. Then you really have to worry about one password, the one to unlock the password manager, and don't even have to think about the others. There are plenty of open source password manager to choose from.
- mjg59 5y ago> "Knowing that all Windows 11 computers will have a TPM allows them to enforce that all Windows 11 hardware only runs software Microsoft has signed" This seems… wrong? Or, at least, one does not directly follow from the other. You don't need a strong hardware root of trust to enforce signing requirements - if Microsoft wanted that, they could do so without requiring a TPM at all.
- chihuahua 5y agoThere's a certain kind of tinfoil-hat people who predict that Microsoft is about to restrict what software they can run on their computers. There were similar conspiracy theories when Windows 8 launched - some kind of secure boot scheme. Never mind that nothing of the sort happened and you can still run whatever you want on your PC, both with and without Windows. Meanwhile Apple has all kinds of anti-competitive restrictions but this is fine.
- mjg59 5y ago> Never mind that nothing of the sort happened and you can still run whatever you want on your PC To be fair, that was largely because of significant public pushback on early versions of the Microsoft requirements (which didn't require that it be possible to disable secure boot) and a lot of negotiation with Microsoft to ensure that third party operating systems would be able to get signatures. (Source: one of the people who designed and implemented Shim and ensured that Microsoft would be willing to sign it)
- dane-pgp 5y agoEven if you trust Microsoft not to abuse its "secure (against the user) boot" scheme, despite the evidence[0], you should realise how eager governments are to remove apps from app stores and how quickly they would take advantage of a technology that allows them to limit desktops and laptops to running only "approved" applications too. People rightly foresaw the potential for scope-creep in Apple's latest device-side file scanning "feature", and we should be similarly cautious for any similar feature that makes it hard for Microsoft to oppose enforcing a government-maintained blacklist or whitelist of installable software. [0] https://www.computerworld.com/article/2542952/aussies-rage-against-the-microsoft-machine-over-vista-security-feature.html https://www.computerworld.com/article/2542952/aussies-rage-a...
- lom 5y agoThis article doesn’t do a great job of explaining what the supposed password-less future is. Based on Microsoft’s article[1] it seems like it will fully be reliant on your mobile phone and the authenticator app that you will have to install on it. What happens when someone gets access to your phone? What happens when you lose it? Does the app on the phone have the same protections under the law as passwords[2]. Is this just 2fa without any passwords at all involved? Just a few questions and doubts I could come up with in a small timespan. [1] http://microsoft.com/security/blog/2021/09/15/the-passwordless-future-is-here-for-your-microsoft-account/ http://microsoft.com/security/blog/2021/09/15/the-passwordle... [2] https://time.com/3558936/fingerprint-password-fifth-amendment/ https://time.com/3558936/fingerprint-password-fifth-amendmen...
- megaman821 5y agoThe app can be configured to require a PIN/fingerprint to authenticate you. The 2 factors become control of the phone and your fingerprint.
- brendoelfrendo 5y agoFingerprint is fine, maybe, sort of, for situations where your threat model doesn't involve someone compelling you to put your finger on the device. But PINs are just a step backward and I'm not sure why we should get on-board with replacing one form of knowledge auth with a weaker form of knowledge auth.
- llampx 5y agoIf you have a fingerprint or can hack it, it basically will let you into the phone and into the auth app.
- mattashii 5y agoYep. But no-one ever leaves their fingerprints on their phone, so this is 100% safe. /s
- marcodiego 5y ago
- WorldMaker 5y ago> The best passwords are truly random strings that are unmemorable Let's not fool ourselves: those are no longer passwords. A password in the "things that you know" sense of Two Factor must be memorable for it to meet that definition. Which is not that this is bad advice, as it remains great advice: if you must use "passwords" at least use random garbage passwords that you cannot possibly remember and store them somewhere safe such as a Password Manager. What it does point out is that passwords are broken and have been for some time now. Those of us with the wherewithal to use random garbage backed by password managers have already been living in the "passwordless future". Certainly it is a different "passwordless" than what Microsoft has done, but it is in base principle the exact same thing: using a "something you have" factor (password manager). Certainly a number of specifics differ and in theory if you've bothered to setup your own you are more likely to be using a (unique) strong "pass phrase" as a master key and at least keeping it "something you know by-proxy". I appreciate the stance that Microsoft's "passwordless" requires you to give Microsoft more control than other options, but I think we need to be very clear that "passwordless" is the goal whether it is "passwordless" via tools such as password manager or "passwordless" via device hardware keys and biometrics engines. Passwords in the traditional sense of "secret you have memorized" have never really worked well and we should get rid of them. (And they were broken long before the bad password policies that Microsoft helped enable that required constant password rotation.)
- jareklupinski 5y agoThis was the realization that made me backburner my physical password manager project https://github.com/jareklupinski/zamek https://github.com/jareklupinski/zamek I'm more interested in exploring ways to ease the burden of "thing you know" for a lossy human mind, than racing to the bottom of "thing you have" with a bunch of other hardware vendors. So far I really like those spinning wheel codexes you can keep on a keychain :) Looks random to everyone else but only I know the exact pattern to turn jumble into password.
- forty 5y agoYou would still login to your password manager using a (human memorable) password, so that would still count as something that you know ;) (it's true though that many password managers will allow you to use some second factor to login)
- advael 5y agoThe more general model of "local password that unlocks a key" seems like better security at every turn, and something that's feasible to implement on any system. This leaves attackers with the same options they'd have with 2FA: Gain access to the device that produces/stores the key, or crack the crypto. There's no technical feasibility concern for implementing good security, there's just endless incentives for these big players to pretend it's hard without you handing over control
- autoliteInline 5y agoIn terms of passwords, I just have them written down in a file that I print out in a desk drawer and keep a copy of in my email.
- dredmorbius 5y agoFor anyone tempted to do likewise, this is extraordinarily bad advice. A hardcopy of your passwords is fine. Preferably one you've written out by hand. An unencrypted online file is an extraordiarily bad idea. This puts your secrets where they're readily accessed and exfiltrated. My own preference runs toward passphrases (based on random word selection) for secrets I've got to remember, and very long random strings for anything else, managed in a password manager or encrypted file.
- Waterluvian 5y agoIs anyone else out there technically literate but still very resistant to using password managers? I just don’t trust that it’s not going to burn me badly when I get locked out of a single point of failure, which locks me out of my entire financial and online life.
- alphabettsy 5y agoI think this is why is important to choose wisely. As someone who’s been using the same one for over 10 years this is not my biggest concern.
- smallerfish 5y agoAgreed. For example: https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=lastpass https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=lastpass or https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=1password https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=1password. I do let chrome remember my passwords (and sync them), as that has high utility (and I'm already significantly trusting that google have their shit together when it comes to security.) But that said I have two categories of passwords; sites that are relatively trivial (e.g. spotify, hackernews), and sites that are tied to my identity or finances (e.g. email, banking). There really aren't that many in the latter category, and it's manageable (with a bit of practice) to use a memory palace type technique to associate sites with a strong visual that turns into a phrase. For the former category, I have a fairly junky heuristic that gives each site a unique non-dictionary based password that's usually 15+ characters. If my chrome profile ever disappears (or isn't obtainable), I could recreate passwords that way.
- aeternum 5y agoYes, they also significantly increase your potential attack surface. To get into your e-mail, an attacker now has the option to find a vulnerability in your e-mail server or your password manager. They're great for random websites but they should probably not be used for your most critical secrets.
- tobiasSoftware 5y agoI am. I use a system where I have a complex master password that is memorized that I mix with a unique password that I write down. It's not a perfect system, but it protects me from the three main attack vectors: an online attacker using a dictionary attack, an online attacker who knows one password and is checking for repeated passwords, and an offline attacker looking for a written password. The main disadvantage is that it doesn't protect against is if someone is focused on me specifically and has compromised multiple passwords and figures out the pattern. However, I've always been wary of password managers as a single point of failure. At the very least, I have concerns about how a password manager would function when I want to use a password at work that was created on my home computer. Currently, I can easily write down my unique password on a slip of paper, and even if someone finds it they wouldn't be able to successfully use it.
- Terretta 5y agoI'd argue the worst thing in Microsoft's password policy engine was "complexity" rules instead of any way for allowing entropy rules. A combo of "is this high enough entropy" and "is this in a rainbow table already" would let people have personal and memorable pass phrases. - Microsoft's own experience[1] realized length beats the "one of each kind of symbol" nonsense some time ago: https://docs.microsoft.com/en-us/archive/blogs/msftcam/password-complexity-versus-password-entropy https://docs.microsoft.com/en-us/archive/blogs/msftcam/passw... - Simple entropy checker: https://www.bee-man.us/computer/password_strength.html https://www.bee-man.us/computer/password_strength.html - Keepass tries a few other angles as well: https://keepass.info/help/kb/pw_quality_est.html https://keepass.info/help/kb/pw_quality_est.html - Overview of Diceware for hand generating pass 'phrases': https://theintercept.com/2015/03/26/passphrases-can-memorize-attackers-cant-guess/ https://theintercept.com/2015/03/26/passphrases-can-memorize... --- 1. TL;DR quote from TechNet: - Password lengths are significantly more important than password complexity requirements - Password complexity only prevents users from creating easy-to-guess passwords - Password complexity actually reduces the total number of possible passwords in a key-space - In theory, the most secure password policy would define a longer-length password with no other complexity requirements with a very large dictionary that consists of all easily-guessable passwords
- slaymaker1907 5y agoThe problem is how do you computer entropy? In my opinion, the only truly effective way is to generate passwords using a fixed procedure like diceware or by throwing password cracking software at a potential password and seeing how long it takes to discovery.
- dathinab 5y agoIMHO passwords always had been broken from the get to go for general purpose usage. This doesn't mean bad password rules haven't made it worse. Neither doesn't it mean there are special purpose use-case where passwords can make sense, like for a a way to unlock whatever you use to eliminate passwords. But even then there are always better alternatives, like word pins. In my opinion there are a few services which should have a high level of security, like e.g. email. In which case I would argue a password is not enough and should be complemented with a hardware token or similar which prevents certain kinds of fishing attacks passwords (or word pins) are prone too. Some have a security level where a password, word pin or HST+PIN would be ok. But many more are partially irrelevant logins which are best of with a password manager, HST without PIN, SSO, or similar which all can (but often/mostly isn't) done in a reasonable privacy aware way. > Passwords Put You In Control How, do you have more control? Any data sharing can be done and promoted even without SSO or similar. You still login with email or worse phone number, which (in general) gives much more information away then any HSK. And let's be honest I try to avoid making accounts if possible/reasonable but still accumulated ~70 logins. How am I supposed to remember more then a small number (let's say 10) secure passwords which must not have any pattern or there is a risk if a site is corrupted. That wasn't ever a option, never feasible and always broken. It doesn't put you into control, it forces you to use "something" to give control to (a notepad, password manager etc.). So IMHO if we want an improvement we need some form of privacy preserving, open anti-decentralizing "SSO"-like protocol/system which can be feed by HST, Secure Modules or simple Apps. Does it exists? Probably, somewhat? But making it widely used seems as unlikely as people (in general) choosing passwords if they have the choice to not have passwords.
- gerdesj 5y agoOP opines with retrospect. I'm a dyed in the wool Linux bod but I can't accuse MS of destroying passwords via AD. AD is simply a hierarchical database of data that is DNS federated. It has a heavy lean to windward in the guise of Kerberos and LDAP. The thing about Kerb is DNS ... lol! Our internets needed RFC1918 to squeeze a few extra decades out of a 32 bit IPv4 address. We have NAT and that means that DNS becomes difficult for identity purposes. That means that Kerberos doesn't work quite as well as originally envisaged, without some bodges. That means that you use a lot of NTLM ... Unixs and Apples have also always relied on passwords as a first authentication method. OK, I hate the term "best practice". There is no such thing, and MS deploys that term with complete and utter gay abandon. That is what is wrong for me. I think there is good and bad practice but never "best". There is no discussion outside of their own little minds in much of the MS documentation. I suspect this is changing right now but I have read an awful lot of MS docs over around four decades. Authentication is hard. Trust is harder. Twatting around with phrases like "passwords are wrong" is irresponsible. You need to look at the whole chain of trust and how to authenticate it sensibly.
- swiley 5y ago> Unixs and Apples have also always relied on passwords as a first authentication method. Nowhere have I seen anyone primarily relying on passwords (unless they didn’t have a clue.) Everyone is using PKI.
- nixpulvis 5y agoHeadlines like this give me a knot in my stomach and make me really anxious. How long until my working solution no longer works thanks to the masses of tech-illiterate animals without password managers? Or should I be more upset that I, a free man, should be forced to manage passwords? There are two issues here: 1. Unified and standardized password management must become a thing 2. Fewer sites should require a permanent account to make a transaction
- slvrspoon 5y agopasswords ain't broken but the thinking here is at HN :( passwords are going to be around for a good long time as i suspect WebAuthn and others will discover. the author is correct that hackers are smarter than companies and developers about human psychology, which, like, matters. databases want identity data and a simple 2FA on top of passwords is winning because marketing can get your phone # too. and on and on...
- sytelus 5y agoIf I was Apple, I would spin off FaceID as a separate business. It is proven at scale, can be packed into tiny device and no worse than passwords. It is beyond me that I still have to carry rectangular cards to buy something or have little book to get through Airport or type password to login anywhere.
- varenc 5y agoApple is working on getting state ID cards in your phone and supposedly even the airport TSA will accept them. https://www.apple.com/newsroom/2021/09/apple-announces-first-states-to-adopt-drivers-licenses-and-state-ids-in-wallet/ https://www.apple.com/newsroom/2021/09/apple-announces-first...
- moogly 5y agoI don't understand the mental leap here to blame password rotation on Microsoft specifically. Shouldn't that blame be aimed at (older) NIST and (current) PCI DSS compliance? Blaming Microsoft for making it easy for sysadmins to centrally control a password policy through Active Directory seems, to me, just... very misguided.
- technion 5y agoMicrosoft has made a big deal out of this being their way forward, but the only way to logon to a Windows Server is to use a password (unless you count a Smartcard) and their answer for how this all fits together is pretty much "let's just talk about our cloud services". I don't think this aim is going to reach the majority of organisations any time soon.
- easton 5y agoI wish they’d come out and say that Windows Server is just going to be tracking kernel/plumbing changes from the mainstream release and no new features are planned. The biggest “feature” in Server 2022 is that you can now address more cores and RAM (2048 cores and 48TB) because apparently SQL Server needed that. I see every day someone coming onto r/sysadmin saying “oh I have this SBS 2011 server that really needs an update” and all these graybeard Windows admins come out of the woodwork screaming about how they need to set up a old school AD domain controller and print server and all this crap. It’s dead guys. New apps should not be adopting Windows Server.
- technion 5y agoYes it's been an interesting one to read through Microsoft's "what's new" for Windows 2022, there's multiple references to TPM support and Credential Guard and the MS Edge Browser (features we have already). We then have Azure Only features, and "Azure Hybrid" features. Microsoft have effectively done what you describe with Exchange. Current literature is pretty open about the fact they are barely working on the on-premises version. Which would be fine if they sorted out the hybrid management situation.
- slaymaker1907 5y agoYou can also store the certificate on a Yubikey instead of a smart card. We do that at my work in combination with an associated pin so that you have two factors.
- NoPicklez 5y agoIt erks me how the author has described that Microsoft RUINED passwords. Sorry, but AD has been around for decades and implemented passwords way before we had the technology or foresight of today to know and do better. You can't say a company ruined something when that was arguably the best implementation of that at the time. It's like saying Ford ruined cars because they produced the first combustion engine and now that we all use electric cars they ruined the automobile and enabled decades of emissions in hindsight. I've reviewed the AD password policies for around 80+ companies now and I can safely say that many of those companies were not even implementing the full extent of what the policy would allow. I'm not disagreeing with the premise of passwords, just that it's easy to stand on a pedestal decades later in hindsight and say "they did it badly" knowing what we know now.
- toss1 5y ago>>In the name of security and convenience your computer will be less and less your own. In whatever they name it, the obvious attitude of these tech giants has nearly always been that it is not MY/OUR computer, but THEIR COMPUTER. Just the attitude that they could reboot anytime to force an update, nevermind what was happening at the time, whether we were in a critical presentation or other situation. It seems it took a Windows computer literally rebooting in the midst of a surgery and endangering the patient's life to start "allowing" us plebs to partially postpone and schedule updates. (And yes, I get it that there are millions of DEUs out there who will fail to update in a timely fashion and endanger us all by being ignorant botnet hosts. That does NOT mean that the first response should be to stomp on everyone) Toxic attitude.
- soundnote 5y agoWindows Update was practically malware at the start of Windows 10's life. I don't miss those days.
- dredmorbius 5y agoAs much as I'm a fan of gratuitous Microsoft bashing, this would be a far better essay without the distracting and counterfactual swipes. Yes, AD does implement a number of previously recommended password management practices, and site administrators can choose to impose these. No, Microsoft did not come up with those policies. As I replied to Kyle on Mastodon, my copy of the late Evi Nemeth's UNIX System Administration Handbook 2nd ed, (1995) has a discussion of password aging (automated timed-out passwords) on pages 95 & 544. She's not a fan, but the capabilitiy exists and is noted on Solaris, Irix, and BSDI. She does recommend rotating the root password regularly. https://toot.cat/@dredmorbius/106965632066772456 https://toot.cat/@dredmorbius/106965632066772456 (thread) Note that at the time, Microsoft produced largely only single-user operating systems, without any user password at all. (Yes, Windows NT 3.1 was released in 1993. It saw very little use. Active Directory wasn't released until 1999.) What AD ended up impelemnting was in fact considered best practices at the time. And implementing best practices as standard (and default) configurations is a powerful tool for compliance. As has been demonstrated many times, and curren global events show again, leaving choice to end-users tends to result in very poor safety pratices with severe consequences for all. Unforunatly, knowledge evolves, whilst encoded practices often don't. Kyle's principle gripe is that Microsoft (and Apple, Amazon, and Google, at the very least) are all racing down the same road as fast as they can of ensuring that their devices form the core of digital identity management. Yes, I'd argue that that is a significant concern. But better advocacy without needless distractions would help.
- Pelam 5y agoObligatory XKCD Horse Battery Stapler reference. https://xkcd.com/936/ https://xkcd.com/936/ MS AD and many others certainly did a lot to prevent this sane password future. - arbitrary and low max password lengths - weak unsalted hashes - mandatory short rotation (never mind your passphrase has 50 bits of entropy and cracking it from hash with state of the art would still take years) - banning whitespace - requiring symbols and numbers and capital letters - instead of estimating entropy
- xmly 5y agoTwo-factor for the password manager, then everything else are randomly generated and rotated periodically. I do not want to lose my phone and lose access to my computer as well...
- darzu 5y agoI just wish any big company offered a password manager.
- jpalomaki 5y agoThis claim from the article is not really true: "This passwordless future requires that Microsoft follow in Apple’s and Google’s footsteps in deciding which software you are allowed to run on your computer." For example on Windows the "passwordless future" simply means that you don't need to type in your password during the authentication (for example when you login). You can still continue run all the same apps you have been running before.
- darzu 5y agoOne thing that is really holding back a “passwordless” future is that no large companies are offering a password manager. No one does, or really should, trust the tiny companies that do password managers today. If say LastPass had a major breach, they could just fold the company and it wouldn’t be an enormous loss, compare to a Google that can’t fold. In fact, it might be more profitable for LastPass to sell all the passwords and credit cards it has access to then continue to earn $2 a year from a handful of people. People intuit this and are very hesitant to trust all their passwords to LastPass or OnePass or whatever. The browser password managers aren’t full featured enough. They don’t remember history well, it’s hard to add and edit entries, and it’s especially hard to use them outside that browser or on sites where the prompts don’t trigger right (still very common.)
- stalfosknight 5y agoApple offers Keychain and I think it could be argued that Apple is one of the biggest corporations to ever exist.
- aorth 5y agoThis strikes me as being part of the larger war on general purpose computing. Microsoft is saying that, in order to use your expensive device, you need another expensive device, and you need to involve a third party as an arbiter. See Cory Doctorow's excellent 2011 keynote to the 28th Chaos Computer Club conference entitled "The Coming War on General Purpose Computing": https://boingboing.net/2011/12/27/the-coming-war-on-general-purp.html https://boingboing.net/2011/12/27/the-coming-war-on-general-... What do we do about this? I can (and do) run open-source software on my laptop, but what about my parents, kids, friends, et al? Some of them care, but can't be bothered. Others are oblivious.
- fsflover 5y ago> What do we do about this? Have a look at the website where the OP is published.
- qPM9l3XJrF 5y agoCan anyone speak to merits/demerits of purism products? A security focused linux laptop is honestly quite appealing to me, although I think preinstalled openbsd would be even better. Would ideally like some sort of secure boot as well.
- OneTimePetes 5y agoSo, what this all boils down too, is centralization of weakness? As in, all people, store all there "passwords" in one centralized hierarchical structure, easily accessible by a weak traditional "password" or at least 2factor and that is supposed to be saver? Let me guess, the next step is a AI that predicts likelihood of you being you, by access and usage behaviour patterns? Locking you out, if your late for work? etc. Let Co-Workers vouch for a transaction being in character? Sure, he would buy three cars.. Last step, is location data being necessary to login- the device has to be in the sphere of trust around your cellphone. At that point the full fledged rebellion will have reached the developer offices, ending this nightmare in fire, as the mob sides with mob for protection against the security insanity.
- indigodaddy 5y agoGood article. I used to love reading Kyle Rankin’s rantings in Linux Journal… good times.
- zw123456 5y agoI built my own hardware password manager years ago and it works great for me. It is based on a small microprocessor (PIC) that emulates a keyboard via USB and has a small LCD display and 3 buttons. You simply scroll through the menu that lists the name of the thing you are logging into, it does not display the password, you press the button and it enters the password via keyboard USB HID. Works on any OS any device that uses USB keyboard which is basically everything. Pretty simple, tough to hack, no way to get into it except me (no remote access to it, you have to know how to program it). Bad thing is if I ever lose it I am screwed and would have to change every password, because I don't have any authorization on it, whoever possesses it can plug it in and hit a button and it will dutifully output the passwords. I originally made it because for work I probably type in the same password 50 times a day, with this I just plug it in scroll to the work password and then its just 1 button push each time. Someday I may think of a way of securing it somehow, but for now I just have to make sure I don't lose it!
- mattowen_uk 5y agoI have a teensy sitting in a box somewhere waiting for me to build exactly something like this! Care to share your build process? Regarding initial security - have you though about a button sequence with the 3 buttons after it's plugged in, which 'unlocks' the password list?
- zw123456 5y agohehe ya, i should put it up on my github, you are getting me interested again. For authentication ya, button sequence, or another thing i was thinking might be cool would be NFC. I have a little NFC chip, could make a new version. That would be cool then you could activate it with your phone using an NFC app.
- ho_schi 5y agoThis is sadly all true. Password policies like "you must/must not use this characters" are bad and the worst are "you must change this password every six weeks". The first is a restriction which prevents well memorable passwords, the seconds enforce throwing away a good password for another on. So users do what? The look for a pattern to pass this test, a acceptable solution is a famous german football club "Schalke04" or use the month "June_06". The enforced changing passwords was never a good thing. At least the german language differs between a password (Passwort) which is assigned to one person and parole (Kennwort) which is common for all allowed persons. And yes, Windows still ask for a parole like Win98. The last known users of parole where the soldiers of the ancient roman empire. It was required to change it rapidly, because some Gaul oder Germanic could have beaten it out of a soldier. The IT applies security measures from the ancient Romans! A password instead must match 'you' and only you can use it, the guard must know you (e.g. passport) and you need to know the personal password and it doesn't allow for bringing others into the camp. Well. A nowadays some people recommend passwords with the length of an SSH-Key because "Computer getting faster". Seriously - NO! It the computers job to lock your account for some time and making a computer based attack useless. Linux is doing that on your TTY with a few seconds and GNOME is temporarily banning you for 10 minutes. Even an iPhone does this. And yes, one long and well memorable password which is not easily guessable is fine. By the way, SSH-Keys are a fine and good thing for automatic authentication. And Microsoft has a shameful history, so called "Security Questions" which are often enforced. What is the family name of your mom? Your favorite meal? The name of your pet? What is wrong with Microsoft. It not a security question, it is a wide open backdoor. And now TPM? The correction description of TPM is "We don't trust you, you must trust us". Well, trust is a mutual thing?
- _wldu 5y agoTo add to that, MS Active Directory hashes are very weak. One round of MD4. Very easy to crack.