4 ms·
This entire debate around typed passwords feels like we're still trying to create "a faster horse" instead of "building a car". We're talking about letting a m
by digitalengineer 13y ago
This entire debate around typed passwords feels like we're still trying to create "a faster horse" instead of "building a car".
We're talking about letting a machine/program know you are really you. Right now a lot people concerned with this topic also carry around advanced computers (smartphones) with HD camera's, GPS, Compas and Near Field or Bluetooth communication capabilities. Surely it would be possible to use something else than keyboard-input to let a machine know you are really you?
A login by 180° close up picture of your face combined with location and IMEI or something? Combining bio data with location and machine or what not... Any ideas?
- AndrewDucker 13y agoMozilla Persona. No password needed at all - your email provider verifies your identity to your browser, and then your browser uses the key generated from that to sign you in.
- derefr 13y agoAnd how are you signed into your email provider?
- Volpe 13y agoIt's Personas all the way down... ?
- StavrosK 13y agoYour identity provider doesn't need to be your email provider. You can use something like https://www.persowna.net/ https://www.persowna.net/ (disclaimer: I wrote it), which can use any manner of authentication it likes. I may just add client SSL certificates as a way of authentication, that will be interesting. You can also self-host and choose any authentication you want, however specific to you. Also, this isn't directly relevant to what the GP said, but using a standardized, decentralized way to authenticate is a huge win. It effectively turns all sites into requiring arbitrarily strong authentication (at the very least, everything suddenly supports two-factor auth when it supports Persona), but you still don't have to trust a third party with your authentication (you can run it on your home computer).
- RobAley 13y agoYou're confusing authentication with identification. Many (most?) web services and software only require the former, not the later. They don't need to know that you're Joe Bloggs, only that you're the unidentified person that created the account and are the one entitled to use it. This is a more and more important distinction as privacy issues grow.
- digitalengineer 13y agoI think you're right. This makes it simpler. All that is required is an authentication. Right now this is 'input through keyboard' because a keyboard was the only way to provide input. Thinking about other forms of input would help.
- Pxtl 13y agoThe problem with biometrics and the like is that you can always capture the data somewhere along the way and then fake a client to imitate it. So if your passwordish thing gets compromised, your account can be compromised. And once that happens, you can't change a password that is your face.