4 ms·
An average user reuses passwords, and I have serious doubts about education ever changing that. One of the most common attacks is compromising a small website
by socillion 13y ago
An average user reuses passwords, and I have serious doubts about education ever changing that.
One of the most common attacks is compromising a small website or forum, cracking hashes (hopefully it wasn't plaintext), then leveraging those credentials on other sites.
Fewer points of failures through centralized authentication has a lot of benefits:
* People who know what they are doing are handling the security, instead of making site owners (frequently with proprietary code) navigate a minefield they often understand very little about.
* Most users are already forced to have very few points of failures either because of services like LastPass or because they either can't or won't memorize dozens of passwords.
* A centralized, specialized, service would hopefully at least be cognizant of being hacked. Making that assumption with every website you would like to register on does not work.
* Additional security like GeoIP checks and 2-factor authentication can be implemented in a way that applies to many types of sites that simply can't be bothered to do so currently.
- stephenr 13y ago> A centralized, specialized, service would hopefully at least be cognizant of being hacked. The biggest tech companies in the world have all been hacked - what part of "No system connected to the Internet is 100% hack proof." do you not understand? Right now, it's largely up to users to ensure some sort of post- "password compromised" security, e.g. by using service-sepecific email addresses, service specific passwords, etc. There are third party tools like 1Password that can help with this, and e.g. Apple is integrating similar functionality into Safari for OS X and iOS. Under your plan, the user doesn't have that ability - they have to find an OpenID provider they're happy to use, and hope it has decent security. OpenID has many benefits, and its nice to have it as an option for login, but thinking that a mass adoption of OpenID will solve problems of password security and storage, is naïve.
- socillion 13y agoI don't know enough about OpenID to comment on it. In the quoted sentence I was pointing out that it's not unusual for websites to be completely unaware that they were hacked. It would certainly be unfounded to assume a service couldn't be compromised. I think it's unreasonable to ask consumers to maintain a large variety of unique passwords. It's a noble goal but it just doesn't happen. LastPass/1Password do solve the password duplication issue, but at the cost of centralizing your passwords and having sites still manage authentication. Why trust every site you sign up for to properly handle nuances like password character limits and account reset protocols, what if sites let a third party with a narrow focus handle these details? Password managers are an easier solution to implement, but I don't think they are better than a well designed solution that's similar to Mozilla Persona. If you think otherwise, I'd be happy to hear why.
- stephenr 13y agoThe problem with your suggestion is the phrase "third party with a narrow focus". There are dozens of OpenID providers. The majority, and certainly all the major ones, offer it as part of another service, i.e. Google, Yahoo!, etc. So to authenticate with some-guys-website.com you want me to then register an account with a third party, because that's better than having a different password for this site? The likes of Google, Yahoo, etc already have way too much information about what people do, you seriously want to force people to give them more? I freely admit that there is a problem with the current system, but the solution is not dumping the concept completely and just trusting the likes of Google for authentication everywhere. It's perfectly possible to have very strong password hashes (e.g. bcrypt/blowfish, scrypt, PBKDF2) but when you have idiot developers, you get bad results.