Live data from Hacker News

Google Wants to Replace All Your Passwords with a Ring

technologyreview.com

31–40 of 54 posts

Re: Google Wants to Replace All Your Passwords with a Ring

#31
post #29

Earlier quoted context omitted.

It doesn't seem easy to me to steal a ring from someone's finger. Do you wear a ring? I ask because I used to think similarly, but now that I've worn a ring for a couple of years, I find them incredibly easy to remove. Admittedly, some might wear smaller and tighter rings, but I think the good ol' twist & pull works in a lot of cases.

The real question is, how hard is it for someone to steal your ring without you knowing ? Because that's the only part that's important. As long as you know it's stolen, you can go in and deactivate it before the thief can do any real damage. (There's usually a backup authentication measure, like a password text messaged to your phone that'll let you log in to deactivate the key).

So all someone has to do is break into my locker while I'm at the gym (assuming I remove my ring and cell phone before I go swimming, etc.)?

Re: Google Wants to Replace All Your Passwords with a Ring

#32
post #5

Isn't this exactly the same concept (if not implementation) as that of the yubikey ( http://www.yubico.com/ ) In fact, google supports yubikey for google mail login. I use mine with Lastpass password vault. Once you have the browser plugin it makes it so easy login and generate secure passwords.

Similar concept but the Google proposal is better for a number of reasons (I'm assuming Google's is based of public key cryptography). Yubikeys have to be verified by yubico so you have to trust them. This also means it can be safely used by any untrustworthy source. It also means anyone could produce these. The Google one isn't vulnerable a phishing site with a valid SSL certificate between you and the target site.…

The yubikey hardware interface is actually pretty clever. Having to press the button means there is physical interaction when using it, which means that if the auth was successful, the user actually did something. It also means that if it's left plugged in and the machine is compromised, the attacker can't use it.

It also means you dont have to worry about drivers, and can use it on whatever OS you want (OK, any OS that supports USB keyboards).

Re: Google Wants to Replace All Your Passwords with a Ring

#33

I recently found a set of RFID chips that could be bought cheaply in a small set. They were small enough that they EASILY could be fit into a ring. Paired with an RFID reader, you could have some good fun. The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost…

manufacture an RFID with the same ID to spoof your identity

Uh... actually, since it's just radio waves, I don't think there's any manufacturing involved. If you can transmit an identical signal at the proper time, regardless of the source, you can spoof an object.

An RFID chip is just a transponder. A tiny antenna, wired to a circuit that reacts to radio waves in a specific manner, with a specific transmission. It's not a prerequisite that the antenna and circuit must be tiny and/or embedded in a chip. Any radio equipment that can send and receive radio transmissions will do.

Re: Google Wants to Replace All Your Passwords with a Ring

#34
post #21
post #18

Meanwhile it's rumored apple may add a fingerprint scanner to iphones. Wouldn't this be at least as effective without requiring additional jewelry? http://appadvice.com/appnn/2013/03/report-the-iphone-5s-will...

Not really. Most biometric authentication systems are pretty poor. Add that to the fact that most biometric systems don't use very many features of the signal (e.g. they don't have a lot of key strength / entropy) and you get a pretty lame authentication systems. A hardware key, on the other hand, can be almost arbitrarily big, is upgradable and totally random.

I assume the phone would be the hardware key and the fingerprint would be an additional security measure because people are more likely to lose/misplace their phones.

Re: Google Wants to Replace All Your Passwords with a Ring

#35
My comment on Google+: https://plus.google.com/100221912051999668442/posts/Wf9nDPFQ...

Here's a copy of the most important parts:

---

(One ring to rule them all, anyone? ;) )

Anyway.

"using personal hardware to log in would remove the dangers of people reusing passwords or writing them down"

Shit yes, writing passwords down and putting it in a drawer at home is so much more vulnerable than stealing the one thing with which you secure all of your accounts and take with you. And how is one-factor authentication that someone has to force out of you (password) worse than one-factor authentication that someone has to rip from your finger and run away with? People apparently can steal watches without the bearer noticing, what the hell am I supposed to think of a ring?

"Everyone is familiar with an ATM. What if you could use the same experience with a computer?"

An ATM requires a PIN-code. Your second factor (a 4-digit password) that is validated by the IC on your card and provides some sort of secure authentication.

Re: Google Wants to Replace All Your Passwords with a Ring

#36
post #19

It is bad enough that pick pocketers know the place where 90% of males keep their cash and credit cards...what happens when identity thieves know the exact place people keep their entire digital persona?

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

It doesn't seem easy to me to steal a ring from someone's finger

Maybe, maybe not, but there are all kinds of professions and occupations where rings must be removed for safety and/or security reasons. It would seem easy for a thief to be able to take advantage of those situations to get the "key" to someones online persona.

Re: Google Wants to Replace All Your Passwords with a Ring

#37
post #29

Earlier quoted context omitted.

The real question is, how hard is it for someone to steal your ring without you knowing ? Because that's the only part that's important. As long as you know it's stolen, you can go in and deactivate it before the thief can do any real damage. (There's usually a backup authentication measure, like a password text messaged to your phone that'll let you log in to deactivate the key).

So all someone has to do is break into my locker while I'm at the gym (assuming I remove my ring and cell phone before I go swimming, etc.)?

I think the idea of using a ring for this purpose is that you never need remove it. It would have to be pretty durable, of course, but then you'd basically leave it on while swimming, sleeping, etc. (like the standard approach to a wedding band).

Having it work by proximity makes me a bit more uneasy, though -- I imagine someone brushing by your hand in the subway and authenticating with your bank then & there.

Re: Google Wants to Replace All Your Passwords with a Ring

#38

I recently found a set of RFID chips that could be bought cheaply in a small set. They were small enough that they EASILY could be fit into a ring. Paired with an RFID reader, you could have some good fun. The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost…

manufacture an RFID with the same ID to spoof your identity Uh... actually, since it's just radio waves, I don't think there's any manufacturing involved. If you can transmit an identical signal at the proper time, regardless of the source, you can spoof an object. An RFID chip is just a transponder. A tiny antenna, wired to a circuit that reacts to radio waves in a specific manner, with a specific transmission. It's…

Sure, but I'm imagining that these are produced in some factory and they just have a serialized ID that they use for each one. I'm imagining if there were a breach of security, it would be slipping a $100 bill to the guy and asking him to run a set with {MY_ENEMYS_ID}.

Re: Google Wants to Replace All Your Passwords with a Ring

#39
I would love something like this. And there's plenty of ways to secure it. Put sensors in it, and as soon as it's away from you (after you put it on), the passwords it contains are wiped out.

You'd need to have those passwords backed-up anyway, either somewhere locally or in the cloud, so you can retrieve them later. You could also make it so you have to "reconnect" with your PC account or whatever every 24 hours, every week, etc.

I'm sure there are other ways to keep this safe, too.

Re: Google Wants to Replace All Your Passwords with a Ring

#40
post #35

My comment on Google+: https://plus.google.com/100221912051999668442/posts/Wf9nDPFQ... Here's a copy of the most important parts: --- (One ring to rule them all, anyone? ;) ) Anyway. "using personal hardware to log in would remove the dangers of people reusing passwords or writing them down" Shit yes, writing passwords down and putting it in a drawer at home is so much more vulnerable than stealing the one thing with…

I advise you to read the actual paper rather than this mechanically-recovered article (which doesn't link to it).

http://www.computer.org/cms/Computer.org/ComputingNow/pdfs/A...

Post reply on HN