3 ms·
It would be better to use public keys for authentication instead of password, but it will require to many things to change for this to happen.
by Egregore 15y ago
It would be better to use public keys for authentication instead of password, but it will require to many things to change for this to happen.
- wladimir 15y agoGoogle Authenticator works pretty well already. I don't know the exact algorithm used, but I think it's public/private-key based?
- thirsteh 15y agoGoogle Authenticator facilitates two-factor authentication. It's a very good complement, but it is not public-key authentication nor a replacement for passwords. SRP is probably the closest: http://srp.stanford.edu/ http://srp.stanford.edu/
- wladimir 15y ago6 digits is indeed too easy to brute force as a password replacement (though it depends on the setting). I guess it could be used as a replacement for passwords if the keys were longer, longer sequences or maybe groups of words like S/KEY. Btw: The SRP ciphersuites have become established as the solution for secure mutual password authentication in SSL/TLS, solving the common problem of establishing a secure communications session based on a human-memorized password in a way that is crytographically sound, So I understand it still relies on a human-memorized password? How is it a password replacement?
- thirsteh 15y agoIt is a replacement to sending passwords over the wire. There are no viable replacements to passwords, which are really just secrets, memorized or not--short of issuing secure tokens or installing high-grade optical sensors in all laptops and getting all services on the Internet to add support for those authentication methods, anyway. This is why we're still using them. Even public-key authentication isn't secure if you're storing the private key on a regular machine, and are not protecting it with a password. Getting the regular Joe to actually use certificates is difficult enough, too.