IBM Applies for Password Manager Patent
An anonymous reader writes "As of August 21, IBM has applied for a patent on "A convenient and secure system and method for access to any number of password-protected computer applications, web sites and forms without adding to the user cognitive load and without circumventing the inherent security of such password-protection schemes. An existing password field on a device display is overlaid with password wallet pop-up field which allows a wallet "master" key to unlock the wallet. An application-specific and/or user-specific password is automatically retrieved from the wallet and entered into the password field with no other user action required." This isn't much different from Mozilla's "Master Password"."
Said another way, IBM having the patent just prevents some VC-backed cyber squatter patent the idea and then demand royalties from everyone under the sun.
Sig (appended to the end of comments you post, 120 chars)
the only thing the USPTO considers as prior art are previous patents, until the said patent challenged in the courts.
Not true at all. The USPTO does dog food as a preference, but if you try to patent something and include references to scientific literature in the patent, it is quite likely that the examiner will turn around and use those references against you.
Don't start slapping IBM and putting on your tinfoil hats people. If IBM doesn't patent this, chances are someone else will, and then sue IBM. Yes, it might be the most obvious thing in the world, and I hate myself for not applying for this patent myself, but in the hands of IBM, it's more or less safe. IBM's not going to sue anyone unless they start spewing FUD like SCO. Hell, I'd prefer this patent in the hands of MS than in anybody SCO-like. Say what you want about MS, but they have tons of patents as well, but they're very lax about enforcing them. Better a patent with IBM/MS than with someone like SCO or Eolas.
So the user thinks they are typing their password into site XYZ's mega secure web site, when they are actually typing it into IBM's not so secure widget? What are the consequences when this 'password widget' gets cracked? The user is not aware of even the possibility of a crack because they are not aware the widget exists.
Not to mention the possibilities for a virus/worm installing its own version of a 'password widget', which the user will again not be aware of.