DARPA Wants To Kill the Password
jfruh writes Many security experts agree that our current authentication system, in which end users are forced to remember (or, more often, write down) a dizzying array of passwords is broken. DARPA, the U.S. Defense Department research arm that developed the Internet, is trying to work past the problem by eliminating passwords altogether, replacing them with biometric and other cues, using off-the-shelf technology available today.
Kill and eliminate passwords? Violence is not the answer.
Get free satoshi (Bitcoin) and Dogecoins
You can change a password, you can't change your retina print. What do you do when your account is compromised? Get new eyes?
Ultimately whatever password replacement you come up with gets turned into TCPIP packets over the intertubes. Whether you are measuring my height, fingerprint, penis size or whatever metric you come up with, it gets turned into 0's and 1's that I can grab and duplicate. It is still information on a remote server than can be hacked and used by third parties.
And worse... once hacked, I can't do much to change my biometrics... so I'm totally screwed once the host server is hacked and a million biometric accounts are compromised.
...when the NSA wants to tap into various accounts, they can track exactly who they belong to and who accesses them because it will be linked to your personally identifiable biometrics
I can change my password anytime if I think somebody copied it. I cannot change my fingerprint or retina. There is no way I'm giving random webshops or google my biometric data.
If an experiment works, something has gone wrong.
I'm ready to switch passwords for anything else as long as:
1 - It can't be extracted from me by an easier method than torture or blackmail.
2 - It stops working forever if I'm dead.
Otherwise, some blood will have to wash away the naivete. Again.
In the 80s we didn't even bother with passwords, okay maybe by the late 80s. And every machine on the network had an IP that was directly on teh internets. As for this article, it's yet another example of how stupid people, even the intelligent, are when it comes to passwords. Who the fsck writes down a dizzying array of passwords? I know about 5 passwords off by heart at any given time, and use a password manager and an encrypted database to hold all of my passwords. Of course, without 2-factor auth those lists of passwords are seriously dangerous and that, dear humans, is where the danger lies. If anyone manages to crack my passowrd manager or my encrypted database, I'm fscked. Okay, let's hear what the folks have to say about this age old problem.
Passwords don't need to be killed. If you're thinking about replacing it with biometrics, I think that's thinking about the problem the wrong way too. The fact is, we already have all the technology we need to solve this problem much better than we do today. It's simple: instead of passwords, you should have a password protected private key, with a single password, and then use public keys for authentication. That way, you only need to know one password, and you've also eliminated a lot of the danger of snooping on connections because the private key isn't being sent.
Of course, it would require that everyone pretty much agree on one set of standards for how it's supposed to be implemented, and than developers have to build their products with those standards. Then you probably also want some trustworthy and inexpensive/free Certificate Authorities. Ideally you'd want to be able, though not required, to use the same private key for everything-- email encryption, ssh logins, maybe even credit card purchases-- so you'd need mechanisms for managing your keys, keeping them safe but also making them available when needed. Throw in some dual-factor authentication where you want a high level of security, and you've basically solved the issue.
You can kill the password in favor of strong security tokens but if the underlying code is poorly written and full of security holes, then it won't be any more secure than what we have now. If you can steal a few retinal images through an exploit, you could, in theory, make a model with the retinal pattern.
Not as hard to implement as some of the pipe dreams out there. Of course, it does require a degree of tech savvy on the part of users - and more importantly, enforcing it's use, to avoid laziness bypassing.
Then your challenge becomes certificate transport - you'll need a way to carry around your cert, or somehow get hold of it when you need it, which is easier said than done. The real advantage of passwords is their portability. Biometrics have a similar advantage, but as already noted - are a bit harder to revoke/change.
Any biometric password should be based on a certificate, not a direct digital representation of the biometric.
Is it just my observation, or are there way too many stupid people in the world?
And he causes all, the small and the great, and the rich and the poor, and the free men and the slaves, to be given a mark on their right hand or on their forehead, and he provides that no one will be able to buy or to sell, except the one who has the mark, either the name of the beast or the number of his name. Rev 13:17
What happens if you get sick or injured? Can you imagine pink eye with retinal scanners?
Yes, this is the serious problem-- just as serious as the problem of people fooling the password-alternative is the problem of the false negatives: getting locked out.
Notice that most of these weren't fingerprint scanners or retinal scanners-- they were stuff like gait monitors, or even more bizarre stuff, like listening to your heartbeat. So, if you twist your ankle--or even buy a new pair of shoes-- you're out of luck. Taking pseudoephedrine for a cold? Ooops, your heartrate is different. You're locked out.
--instead of using these instead of password, however, what about if you use alternate ID as a second check. It doesn't lock you out, but it does trigger a watchdog alert that pays attention to what you're doing.
You can change a password, you can't change your retina print. What do you do when your account is compromised? Get new eyes?
Yes, we've all seen dozens of those science fiction stories where they steal people's eyes, or cut off their fingers, or take swabs of their DNA.
http://www.geoffreylandis.com
Pam: Oh, OK, then good luck with all the biometric scanners. Unless you wanna cut off my fingers and scoop out my retinas.
Kidnappers look at each other.
Pam: Oh, don't be dicks!
Koans and fables for the software engineer
Every single site has a different way of giving you a way to change your password. This makes it impossible to write programs to write programs to change your password....like a password manager for instance. Imagine if you could just type in your new password into your password manager program, and it changes all the passwords it manages with one click. They could all be randomly generated and different for every site. Hints, recovery, email addresses, could all be updated with one click. With a history as to the previous versions in case something went south.
Instead of struggling with writing all the captcha's, and strength meters, and interfaces, and all the CRAP that the every site on the planet does differently. Just standardize the interface and maintenance of passwords. And then standardize the strength of the generator programs. And voila, permanent security that is controlled where it should be: in your hands.
The good part is that they are concerned about passwords. The bad news is that they do not come up with a good alternative.
There are two issues with passwords. The first is that we are looking for a technical problem with what is essentialy a social problem. Security in itself is already a social problem. How many people will give uup their password to the IT guy or their boss without any question? To their SO, kids or parents?
The second isssue is that we have way too many passwords to remember and there is no single solution. (1) IT people are only looking to how THEIR system is secured and look at it from an, again, technical and not a social point of view. They do not count in the weakest point : humans.
And as long as you do not caqlcualte those in, it won't be solved. ..." they should have said "We want to replace it". That way you are open for a REAL solution.
So instead of saying 'We want to replace it with
(1) If you have a solution, please let me know. It must be one that I can use at home (Linux), at work (Windows, but I am not allowed to install anything and have no Internet access and am not allowed to use any cellphone or other device), on my phone, on PCs that are not mine, on my ATM machine.
Don't fight for your country, if your country does not fight for you.