Live data from Hacker News

Google Wants to Replace All Your Passwords with a Ring

technologyreview.com

11–20 of 54 posts

Re: Google Wants to Replace All Your Passwords with a Ring

#11
post #2

Anyone else remember those Java rings? http://en.wikipedia.org/wiki/1-Wire

I do, and I am still waiting for my personalized coffee machine - supposedly they had that at one of the early Java conferences (machine recognizes you by your ring and brews your preferred coffee for you).

Re: Google Wants to Replace All Your Passwords with a Ring

#12
post #5

Isn't this exactly the same concept (if not implementation) as that of the yubikey ( http://www.yubico.com/ ) In fact, google supports yubikey for google mail login. I use mine with Lastpass password vault. Once you have the browser plugin it makes it so easy login and generate secure passwords.

What's using a yubikey like? I've got LastPass premium account and seen it being promoted... How would it work with the password manager on your mobile?

Ahh - just seen it's got NFC build in.

Re: Google Wants to Replace All Your Passwords with a Ring

#14
Hm, I already have a smartphone with Google Authenticator App and NFC, why would I want to carry a ring?

Having recently married and struggling a lot with the ring issue (basically lots of money for a useless piece of metal), the idea of a wedding ring with some badass electronic capabilities has crossed my mind, though.

Re: Google Wants to Replace All Your Passwords with a Ring

#15
post #5

Isn't this exactly the same concept (if not implementation) as that of the yubikey ( http://www.yubico.com/ ) In fact, google supports yubikey for google mail login. I use mine with Lastpass password vault. Once you have the browser plugin it makes it so easy login and generate secure passwords.

Similar concept but the Google proposal is better for a number of reasons (I'm assuming Google's is based of public key cryptography). Yubikeys have to be verified by yubico so you have to trust them. This also means it can be safely used by any untrustworthy source. It also means anyone could produce these. The Google one isn't vulnerable a phishing site with a valid SSL certificate between you and the target site. Lastly, the yubikey is really implemented as just a hack it just pretends to be a keyboard that types the code when you press the button I think a more specific protocol would be better although understandably the yubico one is more compatible.

Re: Google Wants to Replace All Your Passwords with a Ring

#17
post #8
post #2

Anyone else remember those Java rings? http://en.wikipedia.org/wiki/1-Wire

Despite what Google says, I think there's a need for people to have multiple online personas. The ring concept is very cool (I remember those rings, wish I had one), but the physical dimensions of the iButton are too large to have multiple of them on a ring. Say, one for home or family, and another for work. If you're a freelancer, then possibly several for your work customers. Who knows, watches may return, only wit…

They keyfob isn't tied to a unique identity, the goal is to actually prevent websites from correlating account. From the IEEE article:

> One device should be sufficient with a reasonable number of websites for which users have accounts. But, for privacy preservation, the websites mustn’t be able to correlate users based on the device.

Re: Google Wants to Replace All Your Passwords with a Ring

#19

It is bad enough that pick pocketers know the place where 90% of males keep their cash and credit cards...what happens when identity thieves know the exact place people keep their entire digital persona?

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.
Post reply on HN