I was thinking about password alternatives recently because I was designing a website just for friends and family. I wanted enough security to keep out strangers on the Web, but I didn't want to make people I know memorize a lengthy password. So I came up with a photo that fills up the screen. A small, invisible grid covers the photo, and the user has to click the image in a special sequence in order to unlock the ne…
There is a start up in the UK trying to do something very simlar: http://pixelpin.co.uk/
Google security exec: 'Passwords are dead'
21–30 of 54 posts
Re: Google security exec: 'Passwords are dead'
#22Re: Google security exec: 'Passwords are dead'
#23Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…
Even over SSL connections?
Re: Google security exec: 'Passwords are dead'
#24And still there are "modern" games and services telling me that my password "May only contain letters and numbers" Really? Are you stupid or something?
Re: Google security exec: 'Passwords are dead'
#25Re: Google security exec: 'Passwords are dead'
#26Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…
> Don't login to anything from other people's computers (net cafe, shared computer in a hotel, etc) Even over SSL connections?
Re: Google security exec: 'Passwords are dead'
#27Passwords are long overdue, it's a walking carcass. Hard for users to remember, trivial to intercept, easy to lose, not hard to guess.
If it's a local resource only then all an attacker needs is time and computing resources, but, that's true for key based authentication too.
Re: Google security exec: 'Passwords are dead'
#28Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…
> Don't login to anything from other people's computers (net cafe, shared computer in a hotel, etc) Even over SSL connections?
In practice this doesn't really limit folks too much as how often do you really need to login from somebody else's computer? Can it seriously not wait till later?
Re: Google security exec: 'Passwords are dead'
#29This article is about how two-factor authentication is great and should be used everywhere. It is not about passwords going away.
Well, not quite yet it seems, but this may be part of the set-up for it.
Re: Google security exec: 'Passwords are dead'
#30Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…
> Don't login to anything from other people's computers (net cafe, shared computer in a hotel, etc) Even over SSL connections?