Live data from Hacker News

Google security exec: 'Passwords are dead'

news.cnet.com

1–10 of 54 posts

Re: Google security exec: 'Passwords are dead'

#3

This article is about how two-factor authentication is great and should be used everywhere. It is not about passwords going away.

Or maybe she didn't really want to divulge how Google plans to make passwords obsolete.

>> Although Adkins didn't offer any real specifics on how Google will innovate beyond today's security, she did say the company is experimenting with hardware-based tokens as well as a Motorola-created system that authenticates users by having them touch a device to something embedded, or held, in their own clothing. "A hacker can't steal that from you," she said.

Re: Google security exec: 'Passwords are dead'

#4

This article is about how two-factor authentication is great and should be used everywhere. It is not about passwords going away.

According to the article, she did say exactly those words:

"password are dead"

"passwords are done at Google"

"our relationship with passwords are done"

Then they go on about how they're experimenting with hardware tokens and stuff, and how all startup should be solving that for them now.

It looks like PR to me, and it also looks like Google has lost it's soul.

Obviously, passwords are far from dead. It's wishful thinking at this point. The only thing everyone can agree on, is that passwords sucks to remember, input, and manage, and that there are many superior technical solutions.

The main issue is and has always been is that those superior solutions are painful to introduce because they're not standard, everyone wants it's proprietary piece of equipment in there, and they're not seamless solution that customers - users, really - are willing to test til something becomes a defacto standard.

Re: Google security exec: 'Passwords are dead'

#6
post #3

This article is about how two-factor authentication is great and should be used everywhere. It is not about passwords going away.

Or maybe she didn't really want to divulge how Google plans to make passwords obsolete. >> Although Adkins didn't offer any real specifics on how Google will innovate beyond today's security, she did say the company is experimenting with hardware-based tokens as well as a Motorola-created system that authenticates users by having them touch a device to something embedded, or held, in their own clothing. "A hacker can…

There isn't really anything magical to make passwords go away, thus, nothing fundamentally new or to hide. A tiny piece of NFC hardware can be used to authenticate users using S/R or HOTPs (look at the yubikey neo for example). Then you can hide it in clothing, rings, bracelets, watches if you want. Way more convenient than a usb stick too, but you need a NFC reader, still.

Google has a huge impact, thus they're the ones most likely to have enough momentum to push for a change. That's different.

Re: Google security exec: 'Passwords are dead'

#7
I was thinking about password alternatives recently because I was designing a website just for friends and family. I wanted enough security to keep out strangers on the Web, but I didn't want to make people I know memorize a lengthy password.

So I came up with a photo that fills up the screen. A small, invisible grid covers the photo, and the user has to click the image in a special sequence in order to unlock the next image. After a few quick rounds, they open up the content.

I realize that it isn't the most secure approach, but it's much easier to memorize and use than a traditional password (not to mention more fun). If anyone has any advice or interesting anecdotes about visual login systems, I'd be interested in learning more about them.

Re: Google security exec: 'Passwords are dead'

#8
post #4

This article is about how two-factor authentication is great and should be used everywhere. It is not about passwords going away.

According to the article, she did say exactly those words: "password are dead" "passwords are done at Google" "our relationship with passwords are done" Then they go on about how they're experimenting with hardware tokens and stuff, and how all startup should be solving that for them now. It looks like PR to me, and it also looks like Google has lost it's soul. Obviously, passwords are far from dead. It's wishful thi…

What are these many superior technical solutions you speak of?

Care to give any examples of such?

Re: Google security exec: 'Passwords are dead'

#9

I was thinking about password alternatives recently because I was designing a website just for friends and family. I wanted enough security to keep out strangers on the Web, but I didn't want to make people I know memorize a lengthy password. So I came up with a photo that fills up the screen. A small, invisible grid covers the photo, and the user has to click the image in a special sequence in order to unlock the ne…

You just described a Windows 8 feature: http://windows.microsoft.com/en-us/windows-8/picture-passwor...
Post reply on HN