4 ms·
Good article, though the whole premise of people being forced to manage passwords is screwed. We are working hard at Mepin - www.mepin.com - to get rid of passw
by markkum 15y ago
Good article, though the whole premise of people being forced to manage passwords is screwed. We are working hard at Mepin - www.mepin.com - to get rid of passwords one by one. Our premise is that people are much more capable of managing a key - a physical key like a phone or a USB key. Care to agree?
- jimmar 15y agoYes, people are good at managing physical things. The issue I'm guessing you'll run up against is the implementation. You have to convince every developer to adopt a new mechanism for authentication. I don't think passwords will be displaced very soon; they are just too easy to implement.
- markkum 15y agoWe currently support OpenID, so any site/service supporting OpenID works with the Mepin keys. Sadly there are a lot of shaky OpenID implementations out there, so yes the implementation is a challenge. And I do also agree that we will never get rid of all the passwords.
- lukeschlather 15y agoNot necessarily. All you need is browser extensions that mimic the built-in remember password functionality, and a hardware-encrypted USB key that serves as a data store for the browser extensions. That does reduce the USB key to a single point of failure though. That risk could be mitigated with a proprietary key copier. A standard way to generate key pairs for authentication would be a lot better though. (Really, there's no reason we couldn't use SSH private keys with some simple client and server plugins.)
- DasIch 15y agoAny physical key that is easily copied is too easily compromised to be a serious alternative to passwords. Just think of the last time you left your phone on a desk or something while going to the bathroom.
- markkum 15y agoOur USB key cannot be easily, if at all, copied. It's based on smartcard technology used by banks and governments around the world. It's not a memory stick.
- 286c8cb04bda 15y agoOur USB key cannot be easily, if at all, copied. It's based on smartcard technology used by banks and governments around the world. There's an implied 'because' between these two sentences, which I think is problematic, since the first sentence does not necessarily follow from the second. I couldn't care less about the second part, but the first is a great idea. When I visit the website in your profile, though, I don't see any mention of hardware, just software. Is there more information available somewhere?
- markkum 15y agoYou are right. The sentences were hastily written. The hardware key is in private beta and will be publicly available soon. We have evaluated half a dozen smartcard technology vendors and are partnering with a couple of them, so we can deliver a key with or without FIPS certification depending on your cost consciousness and security requirements. Please e-mail me for additional info.
- rauar 15y agoUSB keys aka dedicated devices are dead. Noone wants to carry around yet another gadget. Reuse a phone instead. Much more pervasive.
- peterwwillis 15y agoWe all carry keys. I use a key to get into my house, my car, my business. Keys aren't dead. A memory stick is certainly not secure, but one with the right smart card is relatively secure.
- rauar 15y agoI'm not saying the device can't be secure. It' the inconvenience due to the physical impact and the fact that eventually you have to carry around a whole key chain.
- jayfuerstenberg 15y agoI agree with you and I made it so the iPhone you carry around everyday can be your password manager. I'm honestly not trying to spam HN with links to my product but since it's on topic I'll just mention that I developed an iPhone app called KEYBOX ( http://www.jayfuerstenberg.com/keybox/ http://www.jayfuerstenberg.com/keybox/ ). It securely manages passwords and other secrets without dongles or other devices. USB keys are a good idea from a convenience perspective but what makes it convenient for you makes it equally so for a hacker (the nefarious kind) to break into whatever system you're trying to make secure.
- jayfuerstenberg 15y agoI'm obviously biased as I created KEYBOX, an iPhone app for easily managing passwords, amongst a whole host of other secrets. So take my below answer with a grain of salt... I'm surprised by all the attempts to replace the password with non-secret keys be they facial recognition (face prints?), fingerprints, or other... I can login to your facial recognition screen just by holding up your photo. Fingerprints are little more difficult but the technology exists. But if I am not in possession of your password I'm going to be spending a lifetime cracking it. Conclusion: Keys are not secrets and can be easily copied. Passwords ARE secrets. Yes, passwords can be difficult to remember but that's a different problem. If you want to see secret/password management done right check my website ( http://www.jayfuerstenberg.com http://www.jayfuerstenberg.com )
- deleted 15y ago[deleted]
- markkum 15y agoUmm ... your conclusion is kind of funny and wrong. You might not be familiar with cryptography, modern smartcard technologies, and how those can actually keep a secret. I agree with your assessment on facial recognition and fingerprints, though the biggest problems with the fingerprint authentication are the lack of ubiquitous sensors and privacy issues. But password manager software is better than nothing ;)
- jayfuerstenberg 15y agoI'm quite familiar with cryptography and the principles of secret keeping. I am not as knowledgable about smartcards I admit. Is there something that makes a smartcard based USB key work differently when held by a person other than its rightful owner? My impression of them, perhaps incorrect, is that they are akin to Hanko ( http://en.wikipedia.org/wiki/Hanko_(stamp)#Japanese_usage http://en.wikipedia.org/wiki/Hanko_(stamp)#Japanese_usage ). Basically a system of using possession combined with a fairly unique set of data as a means of distinguishing and authenticating its owner. But in practice its far less than perfect.
- DanBC 15y agoI hope you give a couple of prototypes to Richard Clark for testing. (http://www.cl.cam.ac.uk/~rnc1/ http://www.cl.cam.ac.uk/~rnc1/) (http://www.lightbluetouchpaper.org/ http://www.lightbluetouchpaper.org/)
- DanBC 15y agoRichard CLAYTON, not clark.