Live data from Hacker News

Google security exec: 'Passwords are dead'

news.cnet.com

31–40 of 54 posts

Re: Google security exec: 'Passwords are dead'

#31
post #19

Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…

I'll go one further on your first paragraph: I'm pretty sure I don't want something implanted in my arm that lets Google identify me.

Passwords may have insecurity - but they also permit anonymity. I think people haven't even started thinking that far yet.

Re: Google security exec: 'Passwords are dead'

#32
I think Google is being less than transparent here, but I couldn't tell you why. The NSA scandal seems to be the straw that broke the camel's back.

How many passwords does Google hold? Maybe a billion? Google has decide it's more cost effective to completely overhaul the password system.

How can passwords be the only system available?

Re: Google security exec: 'Passwords are dead'

#33
This thread seems like a valid place to ask a long-standing question of mine.

Are there any projects aiming for a hardware security token with the following properties?

1) Open hardware running open software.

2) Support for many and long keys.

3) Relatively fast signing on-board - i.e. keys are inaccessible to the host computer. (Obviously, I'm not expecting it to be feasible to sign gigabytes using a USB dongle).

4) Some PIN-entry-like low-grade security obsticle to delay an attacker that physically steals the dongle.

I am aware of CryptoStick [1], but the current version is sold out and also does not satisfy 3 and 4 (and only partially 2, since it only takes three RSA keys and there's no support for EC, as far as I can tell).

I really want to move away from passwords, but it seems very hard to do without a device satisfying 1-4 above.

[1] https://www.crypto-stick.com/

Re: Google security exec: 'Passwords are dead'

#34
post #28

Earlier quoted context omitted.

> Don't login to anything from other people's computers (net cafe, shared computer in a hotel, etc) Even over SSL connections?

Yes even over SSL connections. You don't know if the other person's computer itself is compromised (e.g. key logger). Rather then instruct a not-so-tech-savvy person to make the decision of whether computer X is trustworthy the defacto default is "No it's not, don't use it". In practice this doesn't really limit folks too much as how often do you really need to login from somebody else's computer? Can it seriously no…

my bank tracks my IP and notices when I'm logging in from somewhere new and asks me security questions or sends my phone a code like Google's dounle-auth (which I use). And then it asks me if I want to remember the computer I'm on.

I've been interested in a password manager but haven't tried them. Do my passwords get stored "in the cloud" or is it a local desktop/mobile app? If it's a local desktop app, can I copy my password DB to another computer I trust like say my work computer?

been meaning to start creating new emails for different accounts. I might start doing that and just have google aggregate them into one inbox

Re: Google security exec: 'Passwords are dead'

#35
It's funny, but Blizzard's been playing this game for years with their two-factor auth, particularly the part where people's accounts without two-factor would get compromised and the thief would then turn on the two-factor auth, thus making it that much more difficult to recover the account.

Blizzard's been doing this for longer than Google has, maybe Google could learn something.

Re: Google security exec: 'Passwords are dead'

#36

I'd like to learn more from these spam-bots about how they are making money off my passwords. Perhaps I can quit my (wonderful) day-job and sell v1agra.

Emails are (almost) free to send, and the payout (identity theft) is generally worth thousands, so all it takes is one or two clicks to make it worth the investment.

Re: Google security exec: 'Passwords are dead'

#37
"... she did say the company is experimenting with hardware-based tokens as well as a Motorola-created system that authenticates users by having them touch a device to something embedded, or held, in their own clothing. 'A hacker can't steal that from you,' she said."

Something embedded in their clothes? Users have to wear the same jacket or dress every day? Anyone, not just a "hacker" can steal your jacket if you take it off. If it relies on something physical, it's easier for anyone to steal. You still need a password/passphrase.

Re: Google security exec: 'Passwords are dead'

#38
post #28

Earlier quoted context omitted.

Yes even over SSL connections. You don't know if the other person's computer itself is compromised (e.g. key logger). Rather then instruct a not-so-tech-savvy person to make the decision of whether computer X is trustworthy the defacto default is "No it's not, don't use it". In practice this doesn't really limit folks too much as how often do you really need to login from somebody else's computer? Can it seriously no…

my bank tracks my IP and notices when I'm logging in from somewhere new and asks me security questions or sends my phone a code like Google's dounle-auth (which I use). And then it asks me if I want to remember the computer I'm on. I've been interested in a password manager but haven't tried them. Do my passwords get stored "in the cloud" or is it a local desktop/mobile app? If it's a local desktop app, can I copy my…

I use Keepass, it's a local DB but I store a copy on dropbox for safety and convenience. You may not want to do that if you're really paranoid.

Re: Google security exec: 'Passwords are dead'

#39
post #19

Passwords are not dead. Simple single factor authentication using short passwords is dead. That's not a new thing either and they're not going away either. Biometric implants are cool but it's a long ways away ( and I'm pretty sure I don't want anything inserted into my arm... ). Ditto for security rings and other gadgets. Yes they work but the general populace is not going to be using them for a long while. I'd love…

>> (or having my bio-implanted arm chopped off though I'd assume at that point they could just use a $5 rubber hose to get the in memory one).

Trust me, at the point they get the bone-saw out, they can save the 5 dollars on the rubber hose and simply ask ...

Re: Google security exec: 'Passwords are dead'

#40

It's funny, but Blizzard's been playing this game for years with their two-factor auth, particularly the part where people's accounts without two-factor would get compromised and the thief would then turn on the two-factor auth, thus making it that much more difficult to recover the account. Blizzard's been doing this for longer than Google has, maybe Google could learn something.

That's impossible. I'm a Google lover. How could you have unknowingly betrayed my allegiance???
Post reply on HN