Live data from Hacker News

Why [Insert Thing Here] Is Not a Password Killer

troyhunt.com

11–20 of 277 posts

Re: Why [Insert Thing Here] Is Not a Password Killer

#11
post #3

I always liked the idea of having a password entry system where a single observation doesn’t provide enough information to reveal the password [0]. However in addition to creating issues with the secure storage of the password... I don’t think people would be able to use it reliably. Still, some banks still seem to use the “enter the Nth letter of your password” scheme” which seems almostly equally unworkable... [0]…

The Nth letter of password thing sounds sketchy to me. Mostly because it sounds like they have my password in plaintext if they can check that.

They may have it in 2-way encryption in a HSM. That's not what will ever be recommended in a beginner guide to handling passwords for your SaaS, but it's a reasonable approach for a bank.

Re: Why [Insert Thing Here] Is Not a Password Killer

#13

A little boring and reactionary, I think. Unguessable capabilities (long unchoosable URLs mostly) have been used to replace passwords. Plenty of systems refuse to let users choose passwords, and many common password problems are totally mitigated by this design.

An URL with a randomized path in it is, technically, a password.

Also note that the transportation mechanism is pretty weak. If the URL is passed over HTTPS, then that keeps your ISP from seeing it, however it can still show up in logs on the server side or the client side, in your history. A URL will be remembered or even cached by your browser, whereas a regular password won't, unless you explicitly allow it.

A regular authentication mechanism doesn't necessarily suffer from these weaknesses. Consider that you can derive the server-side password, like a client-side hash which may even be time dependent, such that the actual password is never sent to the server. You can implement systems in which the password you know is never sent over the wire.

Basically a randomized URL is semi-public and you need to treat it as such.

There aren’t many alternatives to classic authentication mechanisms around. The only one I can think of is having authentication links emailed to you, but that’s also less secure and it simply defers the problem to a third-party.

Re: Why [Insert Thing Here] Is Not a Password Killer

#14

> Despite their respective merits, every one of these solutions has a massive shortcoming that severely limits their viability and it's something they simply can't compete with: > Despite it's many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone. This is (mostly) true, however, there is already evidence that new…

Biometrics is essentially putting a massively complex system in front of your password input, that lets the device read the password off your body, but the consequences are a) you now can't ever change your password, and b) there's this massively complex system in front of (now hidden) password form, and complexity means unreliability and exploitable holes.

The reason it seems to be working in phones and in laptops is just because the protected systems - personal computing devices of random members of general population - are of low importance, so it's unlikely an attacker is going to bother, whereas the convenience benefits are substantial.

Re: Why [Insert Thing Here] Is Not a Password Killer

#15

> Despite their respective merits, every one of these solutions has a massive shortcoming that severely limits their viability and it's something they simply can't compete with: > Despite it's many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone. This is (mostly) true, however, there is already evidence that new…

Fingerprint scan and Facial recognition can not replace password authentication because both face and fingerprint are public information, while password is meant to be private. You cannot hide your face or fingerprint from others.

Re: Why [Insert Thing Here] Is Not a Password Killer

#16

> Despite their respective merits, every one of these solutions has a massive shortcoming that severely limits their viability and it's something they simply can't compete with: > Despite it's many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone. This is (mostly) true, however, there is already evidence that new…

Biometrics is essentially putting a massively complex system in front of your password input, that lets the device read the password off your body, but the consequences are a) you now can't ever change your password, and b) there's this massively complex system in front of (now hidden) password form, and complexity means unreliability and exploitable holes. The reason it seems to be working in phones and in laptops i…

It’s also not the complexity that’s the problem.

Even if it’s flawless, which is impossible, with biometrics you can easily be coerced into giving access without effort, whereas we haven’t invented a mind reader yet.

In other words I can easily imagine kids gaining access to a credit card via fingerprints or facial recognition, while their parents are sleeping ;-)

I wanted to write about law enforcement agencies, but this is so easy that your kids can do it.

Re: Why [Insert Thing Here] Is Not a Password Killer

#17
> Despite it's [sic] many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone.

I think the problem is that people don't understand how to use passwords. They will reuse them among sites. They pick easily-guessable and low entropy ones. They will type them into any website that asks. The end result is that not much security is provided.

(Things are just as bad on the server side, of course. Developers store them in plain text. They will email them to you. They delete entropy so that you can use your password to log in over the phone or from a computer terminal that apparently only has capital letters. I've even seen a website where the password is sent to the browser and the password checking happens in Javascript. Not great guys, not great.)

Re: Why [Insert Thing Here] Is Not a Password Killer

#18

> Despite their respective merits, every one of these solutions has a massive shortcoming that severely limits their viability and it's something they simply can't compete with: > Despite it's many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone. This is (mostly) true, however, there is already evidence that new…

Biometrics is essentially putting a massively complex system in front of your password input, that lets the device read the password off your body, but the consequences are a) you now can't ever change your password, and b) there's this massively complex system in front of (now hidden) password form, and complexity means unreliability and exploitable holes. The reason it seems to be working in phones and in laptops i…

My banking app uses the Iphone fingerprint sensor to fill in your password. From time to time the fingerprint fails a couple of times because my fingers are greasy or whatever and you can manually enter your password.

Re: Why [Insert Thing Here] Is Not a Password Killer

#19
If nobody understands anything other than passwords, how has 2FA taken off at all? How have password managers taken off at all?

What if the password manager were in charge of logging you in _directly_, through some new protocol between browsers and PW managers? How could that _possibly_ be more friction? It would be strictly less. Hell, it could be done without even informing the user that this new feature was being rolled out, and they sure as hell wouldn't complain about inconvenience because of a step removed from the login process.

Asking people to deal with more and more and longer and longer passwords is a usability nightmare. It's a absurdity.

Re: Why [Insert Thing Here] Is Not a Password Killer

#20

> Despite their respective merits, every one of these solutions has a massive shortcoming that severely limits their viability and it's something they simply can't compete with: > Despite it's many flaws, the one thing that the humble password has going for it over technically superior alternatives is that everyone understands how to use it. Everyone. This is (mostly) true, however, there is already evidence that new…

Biometrics are really more equivalent to a user name than they are a password.

Sure, they get used in some applications as a "password" because it's "cool" but it's fair to say biometrics is public information so while many biometric services do their best to avoid being spoofed, they're really more akin to a user name.

I'd also like to point out that fingerprint scanners don't work if you need to use then when you've just gotten out of the bath / been swimming. If something is going to replace passwords then I'd want to be damn sure I can use it 100% of the time I need to (baring when I personally fuck up - eg forgetting my password).

Post reply on HN