Live data from Hacker News

Google Wants to Replace All Your Passwords with a Ring

technologyreview.com

21–30 of 54 posts

Re: Google Wants to Replace All Your Passwords with a Ring

#21
post #18

Meanwhile it's rumored apple may add a fingerprint scanner to iphones. Wouldn't this be at least as effective without requiring additional jewelry? http://appadvice.com/appnn/2013/03/report-the-iphone-5s-will...

Not really. Most biometric authentication systems are pretty poor. Add that to the fact that most biometric systems don't use very many features of the signal (e.g. they don't have a lot of key strength / entropy) and you get a pretty lame authentication systems.

A hardware key, on the other hand, can be almost arbitrarily big, is upgradable and totally random.

Re: Google Wants to Replace All Your Passwords with a Ring

#22

So it removes the danger of reusing passwords, but doesn't it introduce the danger of having a lost/stolen ring giving away your logins to every protected site?

Assuming they can figure out your identity on those sites, yes. But you also generally know when you lose it, so you can go deactivate it through a backup channel.

Having a keyfob to log in is pretty standard security practice. The only thing that makes a ring different or interesting is that it's an easier form factor, and I presume it would have wireless capabilities so you don't have to actually plug it in for it to work.

Re: Google Wants to Replace All Your Passwords with a Ring

#23
post #21
post #18

Meanwhile it's rumored apple may add a fingerprint scanner to iphones. Wouldn't this be at least as effective without requiring additional jewelry? http://appadvice.com/appnn/2013/03/report-the-iphone-5s-will...

Not really. Most biometric authentication systems are pretty poor. Add that to the fact that most biometric systems don't use very many features of the signal (e.g. they don't have a lot of key strength / entropy) and you get a pretty lame authentication systems. A hardware key, on the other hand, can be almost arbitrarily big, is upgradable and totally random.

This. Fingerprint scanners are notoriously unreliable. Either they reject the real person's fingerprint way too often, or they accept way too many similar fingerprints.

A real key is 100% reliable if you have it and 100% secure if you don't.

Re: Google Wants to Replace All Your Passwords with a Ring

#24

So it removes the danger of reusing passwords, but doesn't it introduce the danger of having a lost/stolen ring giving away your logins to every protected site?

The ring would most likely be used in addition to another authentication factor like a password. An attacker would need both to authenticate.

Re: Google Wants to Replace All Your Passwords with a Ring

#26
post #19

It is bad enough that pick pocketers know the place where 90% of males keep their cash and credit cards...what happens when identity thieves know the exact place people keep their entire digital persona?

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

It doesn't seem easy to me to steal a ring from someone's finger.

Do you wear a ring? I ask because I used to think similarly, but now that I've worn a ring for a couple of years, I find them incredibly easy to remove.

Admittedly, some might wear smaller and tighter rings, but I think the good ol' twist & pull works in a lot of cases.

Re: Google Wants to Replace All Your Passwords with a Ring

#27
post #4

Most of my passwords are in a file called ring. I never write them out fully, but have mnemonics to help me remember. So many sites and if you want to have more than a few passwords, it really is unmanageable.

Get Lastpass. It's awesome. All my passwords are 20+ completely random characters. I access the password list via a password and 2 factor authentication (google authenticator on my phone).

Re: Google Wants to Replace All Your Passwords with a Ring

#28
post #5

Isn't this exactly the same concept (if not implementation) as that of the yubikey ( http://www.yubico.com/ ) In fact, google supports yubikey for google mail login. I use mine with Lastpass password vault. Once you have the browser plugin it makes it so easy login and generate secure passwords.

What's using a yubikey like? I've got LastPass premium account and seen it being promoted... How would it work with the password manager on your mobile? Ahh - just seen it's got NFC build in.

You can use google authenticator as a second factor for lastpass, that's what I do. Install the free app, hook it up to your account, bam, hugely more secure.

And you can get lastpass to remember certain devices, so you don't have to keep authenticating on your home laptop, for example (and you can always go to the site and revoke access to that machine if it ever gets lost).

It's pretty awesome.

Re: Google Wants to Replace All Your Passwords with a Ring

#29
post #19

Earlier quoted context omitted.

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

It doesn't seem easy to me to steal a ring from someone's finger. Do you wear a ring? I ask because I used to think similarly, but now that I've worn a ring for a couple of years, I find them incredibly easy to remove. Admittedly, some might wear smaller and tighter rings, but I think the good ol' twist & pull works in a lot of cases.

The real question is, how hard is it for someone to steal your ring without you knowing? Because that's the only part that's important. As long as you know it's stolen, you can go in and deactivate it before the thief can do any real damage. (There's usually a backup authentication measure, like a password text messaged to your phone that'll let you log in to deactivate the key).

Re: Google Wants to Replace All Your Passwords with a Ring

#30
I recently found a set of RFID chips that could be bought cheaply in a small set. They were small enough that they EASILY could be fit into a ring. Paired with an RFID reader, you could have some good fun.

The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost interest in hacking something neat.

Post reply on HN