7 ms·
Want to Block Common Passwords? Sorry, That is Patented
- ahi 14y agoIANAL, but foreknowledge of patent infringement can triple damage liability right? So is just having the headline of this story on the front page of HN enough to cause problems for the entire HN community?
- eurleif 14y agoIf that's the case, people should avoid clicking the link, as it mentions other patents. (I saw the list, but I didn't read any of the items in it.)
- npc 14y agoIANAL either, but I assume that they would have to somehow prove that you read it, perhaps by showing that you posted in the comments section.
- user-id 14y agoAlso, just because someone on the internet says "X is illegal", it doesn't actually make X illegal.
- 001sky 14y agoThis comment is a little problematic. Despite the INAL qualifier, you seem to be offering legal advice or strategy. Secondly the logic is stretched,... viz: "enough to cause problems for the [entire] HN community?" Clearly for all of the non-infringing HN readers, and those for whom Ignorance is [not] bliss, here might be some interest in it. That being said, the point is a fair issue to raise. But a better note might be: check with counsel.
- pc86 14y agoAsking a question does not denote offering legal advice.
- 001sky 14y agoThat's my point. The post is cobbling together "foreknowledge" "infringement" "liability" into a statement with a rhetortical, "right?" tacked on. It not obviously a genuine question, though (by definition). viz: foreknowledge of patent infringement can triple damage liability right?
- ahi 14y agoNot rhetorical.
- gonzo 14y agoPasswords are dead. Film at 11.
- dredmorbius 14y agoI'm starting to think the same thing. For serious systems-based access, it's been key-based auth for most of the past decade. Even embedded systems (switches, routers, load balancers, DD-WRT-based WiFi routers) offer SSH key-based auth. Key management presents its own set of problems, but most are vastly preferably to using poorly-selected passwords on a myriad of sites.
- m8urn 14y agoSomewhere along the line, there will always be a password!
- Vivtek 14y agoIt could be a one-time issue used only to set up a secret. I think the fatality in question is the user-selected password, which is proving useless at scale.
- dredmorbius 14y agoPasswords not shared across multiple systems, and used rarely, on physically secured and/or proximate systems. The threat exposure is vastly reduced. The main problems with passwords today are 1) rampant reuse and 2) very effective cracking tools based on known password corpuses. Even a small corpus of a few hundred of the most common passwords will generally access some account on a given system.
- acabal 14y agoI'm always tempted to switch to key-based auth myself, but I travel a lot and the thought of me losing my private key and thus being permanently unable to decrypt my files/log in to my servers scares me to death. That's the fatal flaw in the key-based system: while the chances are slim, if you lose the key or it gets stolen (stolen laptop?), the consequences far outweigh the benefits. I'd rather just remembering a complex password for personal encryption/ssh, use a simple throwaway password for general web app use, and not have to worry about losing a key.
- Lasher 14y agoNot to be melodramatic, but as someone still in a day job this whole patent mess seriously does discourage me from taking the leap and risking everything to try to invent something meaningful only to get hit with a patent troll lawsuit just as we start to find our feet.
- angersock 14y agoIt's better to light a candle than curse the darkness.
- talmand 14y agoAs long as your candle isn't bright enough to attract the attention of trolls hiding in the darkness.
- mdkess 14y agoThat's an excuse if I've ever heard one. You would be so lucky to get sued. "I'd be a famous musician, but I'm worried about the publicity."
- talmand 14y agoBeing famous doesn't cost a musician money. Sure, he would be "lucky" to be in a position of potentially losing his business and/or idea in the course of defending it. There's potentially a huge cost even if he were to win.
- m8urn 14y agoSorry, I believe being in a day job is patented also.
- nekojima 14y agoDespite the massive evidence of prior art, it was found not to be original and the patent was granted.
- tomjen3 14y ago
- utopkara 14y agoRe: IBM patents, IBM has an interesting, and quite unique strategy regarding IP. About 20-25% of IBM patents are software patents, and IBM uses this patent portfolio to protect open source projects, especially Linux (http://www.linuxplanet.com/linuxplanet/opinions/7034/1 http://www.linuxplanet.com/linuxplanet/opinions/7034/1). Also, IBM historically abandons a large portion of its issued patents (http://www.patentlyo.com/patent/2012/03/ibms-patent-abandonment-strategy.html http://www.patentlyo.com/patent/2012/03/ibms-patent-abandonm...), and the abandoned patents become prior art, protecting everybody.
- oelmekki 14y agoThat's a valid point. I still don't understand why there is no (afaik) "general public patent" mechanism of some kind : a procedure to make someone claim a patent on behalf of general public. This would certainly stops patent trolls, and avoid making people suspicious when you claim "protective patents" as you describe.
- tomerv 14y agoWhat you're describing is known as "prior art": simply publish your idea anywhere public, and it automatically becomes invalid for patenting. You don't even need to implement anything.
- vlasta2 14y agoIs there a well know central place for this? I once considered starting a web site for this sole purpose - to let people publish their ideas to establish prior art - but I don't have time to manage yet another web.
- oelmekki 14y agoYep, I'm aware of the prior art rule, except : a) it's about things that should have been actually used, where a patent is about concepts b) scope of the idea is not clearly defined and so could be argued with, when a real patent definition for general public use would prohibit that. And that's excatly the point for IBM to issue protective patents, I think.
- danielnicollet 14y agotime to reform the patent review process. there is so much energy wasted fighting patent trolls. furthermore, this produces nothing, it just leaches on the wealth creation efforts of others.
- ryanhuff 14y agoIts not the concept of blocking passwords that is patented, but specific approaches to block common passwords is.
- redact207 14y agoThese frivolous software patents are actually a blessing in disguise and will ultimately be their own undoing. As more and more "patents" are filed and trolls do their best to sue people into compensation, the media song & dance will get stronger and policy makers will sit up and take note. Then it's just a matter of time until blanket reforms are made.
- m8urn 14y agoThat is what I am hoping!
- s8qnze982y 14y agoBlanket reforms will never happen in real world, because we're talking about huge quantities of money involved - a blanket reform the way, say, "many people would like it", would cause a sudden big loss to loss to big & powerful entities.
- xiaoma 14y agoAbsolutely. That's why we're still firing union workers and working child laborers thirteen hours a day. Once enough money was involved, things just couldn't change and therefore patents never will either. Not in the real world.
- JohnsonB 14y agoHow could there not be prior art for this? I know that patents are more specific than the title of the patent, but if the patent isn't general enough to cover prior cases of blocking common passwords, then the patent doesn't even protect anything for the patent's authors. If it is general, then it is surely an invalid patent, even by US patent office standards. Very confusing.
- Fletch137 14y agoThe problem with blocking common passwords is that quite often you just end up creating a new set of common passwords. I had to set up a management system a while back, and given the sensitivity of the data, it seemed prudent to block passwords such as "password" and "123456". The result? The most common password was "drowssap", even after an email explaining why they needed to use strong passwords. I could have gone back and added something for permutations of common passwords, extended my exclusion list or any number of other solutions, but it seems like every time you find a way to stop a user being a security problem, they find another way.
- antninja 14y agoI remember a paper, from Microsoft I think, where the proposed method was to keep a list of all passwords and prevent any password to be used more than X times. This way no password becomes common. But it would likely be frustrating for users who try to find a password (like trying to find a username on Hotmail: everything is taken!).
- tdrgabi 14y agoDoesn't that mean that you keep the passwords in clear? They don't have a user => password relation, but having a list of passwords to go through will make any bruteforce attack extremely fast.
- Fletch137 14y agoI would expect that you'd just compare the hash, effectively performing half of the log in process to check if the password's okay. I imagine it'd be pretty costly in terms of performance if every time you wanted to create a new user you had to hash the password, then check against a (potentially huge) table to see if that password had been used >X times. Hopefully I'm being short-sighted or missing something that'd mean this could be done simply and quickly, because in theory it sounds like quite a good idea.
- omh 14y ago
- RyanONeill1970 14y agoCould someone clarify something here? If I'm based outside of the US and my servers are outside of the US, these software patents would not affect me and I could implement them without risk? I understand the site could be blocked from US browsing but that would seem extreme, especially if I registered a country TLD like .co.uk. In plain English, I don't these patents apply to my country (UK) and are not enforceable here. But I could be wrong.
- xiaoma 14y agoThere are patent treaties. Edit: Well, who knows? Try it and see. Even in the worst case, you can almost certainly cut a deal.
- RyanONeill1970 14y agoEven when software patents are not allowed by law in the EU? Edit: A quick Google found this, seems I would be OK. http://answers.onstartups.com/questions/21560/what-happens-when-a-uk-company-infringes-a-us-patent http://answers.onstartups.com/questions/21560/what-happens-w...
- neilkelty 14y agoI would not recommend taking advice on complicated matters of international intellectual property law from a Q&A site on the Internet. Go talk to a lawyer.
- angry-hacker 14y agoThinking about it - why big companies don't move then? To avoid software patent cases? I mean they can still have skilled workers working in Silicon Valley, can't they? But the company is registered somewhere where they can't sue them. Or what am I missing here?
- talmand 14y agoI would assume having an office in the country means a presence which means they follow the law. Plus just doing any kind of business inside the country, including contractors, makes them subject to local law.
- thomasfrank09 14y agoI get why you'd want to check for weak or common passwords, but why not just require passwords to contain numbers/special characters? It may be a pain in the butt, but it takes users' lack of care for security out of the equation.