http://attrition.org/errata/charlatan/steve_gibson/ > Steve Gibson is somewhat of a "fringe" charlatan. In some professional security circles, he is not considered a reputable security professional, rather more of a snake oil salesman peddling third-rate software with bold claims. While many of his claims are a bit outlandish or bold, few, if any, are demonstrably false. However, when asked to speak on security topic…
Not to use a debate cliché, but isn't this a ridiculously shameless ad hominem? He's published the protocol and disavowed any intellectual property claim to it. Let's focus on critiquing the protocol.
SQRL - Replacement for usernames and passwords
31–40 of 138 posts
Re: SQRL - Replacement for usernames and passwords
#32Re: SQRL - Replacement for usernames and passwords
#33Re: SQRL - Replacement for usernames and passwords
#34Earlier quoted context omitted.
An ad hominem attack would be attacking him for unrelated traits, i.e. "we can't trust people with blue eyes!" I believe his history as a snake oil salesman is highly relevant to his current "security" work.
It's still an ad hominem - the merits of his argument should stand independent to who he is or his history on any topic. Doesn't mean it's not worth talking about, though. After all, science is entirely founded on a kind of inductive reasoning, so logical fallacies aren't crazy to consider.
Gibson's personality isn't the thing in question here, the quotation above is specifically about his history in security. If the comment was about how he's a major asshole (just an example, I'm not saying that) in conferences or something like that, it would be an ad hominem, as that sort of information would not be relevant.
Re: SQRL - Replacement for usernames and passwords
#35It would be interesting to know why Google didn't pursue it. Maybe a 20% project? https://plus.google.com/101935995649723391317/posts/P94xEz9D...
Another similar system http://corp.galois.com/blog/2011/1/5/quick-authentication-us...
Re: SQRL - Replacement for usernames and passwords
#36Not exactly a new idea. Here is some prior art http://openaccess.uoc.edu/webapps/o2/bitstream/10609/14761/6... http://www.computer.org/csdl/proceedings/ares/2009/3564/00/3... As far as I know, QR-TAN is being used in Germany for authentication by a number of banks.
drivebyacct2 - your account has been dead for about 100 days and 200 posts, basically no one can seen your messages unless they have showdead on. Here's the "offending" post that you were banned for https://news.ycombinator.com/item?id=5982741 (hint - the ban is completely unjustified)
Re: SQRL - Replacement for usernames and passwords
#37Earlier quoted context omitted.
Not to use a debate cliché, but isn't this a ridiculously shameless ad hominem? He's published the protocol and disavowed any intellectual property claim to it. Let's focus on critiquing the protocol.
An ad hominem attack would be attacking him for unrelated traits, i.e. "we can't trust people with blue eyes!" I believe his history as a snake oil salesman is highly relevant to his current "security" work.
Sources:
http://plover.net/~bonds/adhominem.html
I think this example is pretty much what you did.
A: "All rodents are mammals, but a weasel isn't a rodent, so it can't be a mammal."
B: "I'm sorry, but I'd prefer to trust the opinion of a trained zoologist on this one."
B's argument is ad hominem: he is attempting to counter A not by addressing his argument, but by casting doubt on A's credentials. Note that B is polite and not at all insulting.If you want further reading from other sources you can go to any of the following links. en.wikipedia.org/wiki/Ad_hominem http://www.nizkor.org/features/fallacies/ad-hominem.html http://c2.com/cgi/wiki?AdHominem
Re: SQRL - Replacement for usernames and passwords
#38Thinking about the user experience for this. I want to authenticate, so I hunt down my phone, launch an app, scan a code, press a button in the app to submit. This seems to me like quite a long process versus the traditional typing in a username and password. What about the implications of a stolen phone?
As for losing the phone, he suggests a passphrase-like "local password" on "The user's view of the application" page [1].
Re: SQRL - Replacement for usernames and passwords
#39Earlier quoted context omitted.
It's still an ad hominem - the merits of his argument should stand independent to who he is or his history on any topic. Doesn't mean it's not worth talking about, though. After all, science is entirely founded on a kind of inductive reasoning, so logical fallacies aren't crazy to consider.
Note: https://yourlogicalfallacyis.com/ad-hominem Gibson's personality isn't the thing in question here, the quotation above is specifically about his history in security. If the comment was about how he's a major asshole (just an example, I'm not saying that) in conferences or something like that, it would be an ad hominem, as that sort of information would not be relevant.
His history as a security professional has no bearing on the actual content here. We are all talking about an idea SQRL not Steve Gibson. If you said, "SQRL isn't worth my time because I don't trust Steve Gibson" that's fine, but the author made no note on SQRL at all, he just attacked Steve Gibson and let it be.
Sure there may be precedence to say that SQRL isn't worth your time, but Steve's credentials don't affect this idea at all. For all you know he may have been given the idea by a team of security researchers who wanted to see if the top post on Hacker News would be some bull shit argument about Steve Gibson. Obviously not the case, but come on let's talk about the freaking content here not the man.
The saying "throwing the baby out with the bath water" comes to mind. Let's look at SQRL and see if it actually makes any sense before we throw it all away.
Re: SQRL - Replacement for usernames and passwords
#40How is this better than any other phone-based 2-factor auth scheme?
Well, it's not really 2-factor is it? It's just the phone part of a 2-factor login and no web form part. Presumably the screen shot that showed a login form was for people without the phone app.
Whatever you use to unlock/authenticate to the device would be the other factor.