2 ms·
I can't imagine users being satisfied with a solution that requires them to either use a specific machine or have a physical artifact with them to login. It ju
by vec 13y ago
I can't imagine users being satisfied with a solution that requires them to either use a specific machine or have a physical artifact with them to login. It just feels too much like a step backwards when everything else is moving toward living on the cloud. Clef looks interesting, but what's the user story when someone's phone dies?
Every security article I see either tries to drastically expand the entropy of the user's key (password or otherwise) or expand to some sort of two-factor authentication. Obviously that's better, long term, but I get the feeling passwords are here to stay for the foreseeable future. I'd love to see an actually secure authentication solution that can be used by someone with nothing other than their memory. Is anyone doing any work on ways to make authentication more secure with a low key entropy?
- MarkMc 13y agoFor Facebook or Hacker News: Yes, most users want to avoid the need for a physical artefact to log in. For a bank website: No, most users are happy to require a physical artefact because they recognise that it helps protect their money. If your phone dies then you are simply be unable to access your bank account until you recharge it.
- vec 13y agoExactly. Good two-factor authentication is not hard. World of Warcraft, for example, has had an excellent real-world implementation for years now. It's actually sufficiently not hard that I'm not sure there's really room for much innovation in that space (unless you count banks actually using it to be innovation). What I'm saying is we need a better solution for Facebook and HN. There's some large subset of sites for which users will not tolerate a physical artifact or convoluted multi-step process. Within those constraints, and with the understanding that we'll never be able to do as well as 256-bit private keys or two-factor, I'm wondering if we can't still do significantly better than alphanumeric passwords.