Live data from Hacker News

Google uncovers major account-hijacking campaign targeting senior US officials

googleblog.blogspot.com

1–10 of 89 posts

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#5
Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites.

Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flawed and cannot be used as a cradle-to-grave method of identity assurance. Unfortunately, nobody has developed an acceptable alternative.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#8
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

Unfortunately, nobody has developed an acceptable alternative

In that case they're not really obsolete, are they? Things are obsolete because they're replaced by something better, not because they're imperfect.

All you really need to do is to get one of those crypto-card thingies implanted in your brain. Then every time you're prompted for a password you just have to type in the first string of numbers that pops into your head.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#9
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

Public key authentication isn't an acceptable alternative?

You could have users unlock a keyring using a password containing a single, global public key for each machine they own. You could have them do the same with a thumbdrive or mobile phone. You could authenticate using a number of methods. It's really incrediably flexible.

I think the problem is not that there isn't something to replace it, it's that people are used to "username:password" and don't want to switch. Public key authentication has too many options while passwords are just single words.

Re: Google uncovers major account-hijacking campaign targeting senior US officials

#10
post #8
post #5

Bad actors take advantage of the fact that most people aren’t that tech savvy—hijacking accounts by using malware and phishing scams that trick users into sharing their passwords, or by using passwords obtained by hacking other websites. Passwords are obsolete. No improvement in storing or transmitting passwords securely will make them easier to remember or less likely to be shared. The approach is fundamentally flaw…

Unfortunately, nobody has developed an acceptable alternative In that case they're not really obsolete, are they? Things are obsolete because they're replaced by something better, not because they're imperfect. All you really need to do is to get one of those crypto-card thingies implanted in your brain. Then every time you're prompted for a password you just have to type in the first string of numbers that pops into…

Except those crypto-card thingies (not the implantable ones) were duplicated as a result of the recent RSA breakin, which is how Lockheed was attacked.
Post reply on HN