Slashdot Mirror


NYT Password Security Discussion Overlooks Universal Logins

A recent NYT piece explores the never-ending quest for password-based security, to which reader climenole responds with a snippet from ReadWriteWeb that argues it's time to think more seriously about life beyond passwords, at least beyond keeping a long list of individual login/password pairs: "These protective measures don't go very far, according to the New York Times, because hackers can get ahold of passwords with software that remotely tracks keystrokes, or by tricking users into typing them in. The story touches on a range of issues around the problem, but neglects to mention the obvious: the march toward a centralized login for multiple sites."

1 of 127 comments (clear)

  1. Re:Torn by houghi · · Score: 4, Informative

    There used to be a time that you could easily host your own OpenID with e.g. http://siege.org/phpmyid.php
    You point to http://yoursite.example.com/ instead of the one from Google or any other OID provider.
    That way you limit the chance of giving somebody else access as you manage your own login and password.

    Some others might be found here : http://openid.net/developers/libraries

    --
    Don't fight for your country, if your country does not fight for you.