Live data from Hacker News

Google Wants to Replace All Your Passwords with a Ring

technologyreview.com

41–50 of 54 posts

Re: Google Wants to Replace All Your Passwords with a Ring

#41
post #29

Earlier quoted context omitted.

It doesn't seem easy to me to steal a ring from someone's finger. Do you wear a ring? I ask because I used to think similarly, but now that I've worn a ring for a couple of years, I find them incredibly easy to remove. Admittedly, some might wear smaller and tighter rings, but I think the good ol' twist & pull works in a lot of cases.

The real question is, how hard is it for someone to steal your ring without you knowing ? Because that's the only part that's important. As long as you know it's stolen, you can go in and deactivate it before the thief can do any real damage. (There's usually a backup authentication measure, like a password text messaged to your phone that'll let you log in to deactivate the key).

http://www.youtube.com/watch?v=ZgWvn4yldM4

Re: Google Wants to Replace All Your Passwords with a Ring

#42
post #19

It is bad enough that pick pocketers know the place where 90% of males keep their cash and credit cards...what happens when identity thieves know the exact place people keep their entire digital persona?

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

The attacker punches you in the face, hard, until you give them the ring or until you are weak enough for them to take the ring from you.

Since people have been kidnapped and forced to enter their ATM PIN to withdraw the maximum (often kidnapped near midnight so the gang can make two maximum withdrawals) this violent scenario isn't particularly farfetched. It depends what the ring gives access to.

Re: Google Wants to Replace All Your Passwords with a Ring

#43
post #24

So it removes the danger of reusing passwords, but doesn't it introduce the danger of having a lost/stolen ring giving away your logins to every protected site?

The ring would most likely be used in addition to another authentication factor like a password. An attacker would need both to authenticate.

I was curious about this as this is how other keyfobs/SecureID cards work. But the article seems to imply that there would be no password at all to use with this device.

Re: Google Wants to Replace All Your Passwords with a Ring

#44
post #35

My comment on Google+: https://plus.google.com/100221912051999668442/posts/Wf9nDPFQ... Here's a copy of the most important parts: --- (One ring to rule them all, anyone? ;) ) Anyway. "using personal hardware to log in would remove the dangers of people reusing passwords or writing them down" Shit yes, writing passwords down and putting it in a drawer at home is so much more vulnerable than stealing the one thing with…

> writing passwords down and putting it in a drawer at home is so much more vulnerable than stealing the one thing with which you secure all of your accounts and take with you.

People should be doing a risk analysis of their online services, so they can decide what kind of password security is useful to them.

I'm a big fan of writing passwords down and keeping that list in a secure place. But some people (eg, in offices) don't have a suitably secure place to keep those passwords. This device would be handy for them.

Re: Google Wants to Replace All Your Passwords with a Ring

#45

I recently found a set of RFID chips that could be bought cheaply in a small set. They were small enough that they EASILY could be fit into a ring. Paired with an RFID reader, you could have some good fun. The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost…

Aren't RFID small in terms of storage size? How many bits could each RFID store?

Also, they tend to be mostly passive, so it's just a big string that you present to the computer, rather than a decent challenge / response.

The C/R is what makes the article interesting, and it's what's holding me back from buying a Yubikey. (Which does a convoluted form of C/R, but on Windows.)

Re: Google Wants to Replace All Your Passwords with a Ring

#46
post #45

I recently found a set of RFID chips that could be bought cheaply in a small set. They were small enough that they EASILY could be fit into a ring. Paired with an RFID reader, you could have some good fun. The problem is, there aren't any consumer purchaseably RFID+Asynchronous encryption options out there meaning that someone just has to manufacture an RFID with the same ID to spoof your identity. Kind of why I lost…

Aren't RFID small in terms of storage size? How many bits could each RFID store? Also, they tend to be mostly passive, so it's just a big string that you present to the computer, rather than a decent challenge / response. The C/R is what makes the article interesting, and it's what's holding me back from buying a Yubikey. (Which does a convoluted form of C/R, but on Windows.)

Yup, not very many, yup.

That's why I lost interest. The smart cards that do active (async) encryption for a proper challenge/response are all contact, rather than contact-less.

Re: Google Wants to Replace All Your Passwords with a Ring

#48
post #19

It is bad enough that pick pocketers know the place where 90% of males keep their cash and credit cards...what happens when identity thieves know the exact place people keep their entire digital persona?

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

> It doesn't seem easy to me to steal a ring from someone's finger

There are alternatives: 1. Point gun and say give me the ring with your entire identity on it. 2. Chop finger off and take the ring.

Becoming the bearer bond of my identity seems like a very bad idea.

Re: Google Wants to Replace All Your Passwords with a Ring

#50
post #42
post #19

Earlier quoted context omitted.

It doesn't seem easy to me to steal a ring from someone's finger. Since the key is never transmitted, copying it without having access to the hardware also seems impossible. Proper implementations would also have the user remember a PIN or the like, so that losing the key doesn't exponse your whole identity.

The attacker punches you in the face, hard, until you give them the ring or until you are weak enough for them to take the ring from you. Since people have been kidnapped and forced to enter their ATM PIN to withdraw the maximum (often kidnapped near midnight so the gang can make two maximum withdrawals) this violent scenario isn't particularly farfetched. It depends what the ring gives access to.

Anything is vulnerable to rubber-hose cryptanalysis. The question is whether this is more or less secure than average Joe using the same three passwords for every site he logs into.
Post reply on HN