Skip to main content

Passwords May Soon Be Passé


The early January theft of more than 320,000 user emails and passwords from cable giant Time Warner gave validation to the argument that simple password authentication is becoming less and less reliable.
But the Time Warner Cable hack is far from being the worst case of identity theft.
In fact, it’s quite insignificant compared to some of the more severe cases we’ve seen in the past year, including the five million user records stolen from toy manufacturer VTech, the 21 million federal employee records stolenfrom the Office of Personnel Management and the 80 million customer records stolen from healthcare service provider Anthem.
When it comes to stealing identities, hackers seem to have an unlimited stash of weapons, including brute-force attacks, dictionary attacks, phishing, social engineering, man-in-the-middle, key-loggers, password resets from recovery emails and wholesale theft of passwords from databases.
And when hackers gain access to our credentials, they can virtually ruin our entire lives by stealing our information or money, or by defaming us through doxing our secrets or posting profanity and obscenities in our names.
On the other hand, when it comes to protecting passwords, there seems to be no end to the pitfalls that one has to avoid, including weak passwords, shared passwords, unchanged passwords, default passwords… And even if you stay true to all the security best practices, some things remain out of your control, including how committed your provider is to encrypt and protect your credentials on its server.
The password dilemma isn’t new, and has been raised on numerous occasions inprevious years. However, the solutions offered have often proven to be frustratingly complex and expensive, or flawed in their own way.
Whatever’s destined to substitute passwords will have to be simple, robust, affordable and flexible.
For the most part, we prefer to continue relying on plain passwords for our online accounts. In light of the continuing rise of data-breaches and identity fraud cases, tech firms are addressing this issue in earnest, and are focusing on ways to strengthen and facilitate the password paradigm, or to have it replaced altogether. Here are some of the newer trends that might change our authentication habits in the near future.

PIN and software token

While classic two-factor authentication methods have proven to be fraught with frustrating user experience or hardware complexities, the PIN and software token combines the simplicity of password entry with the added security of two-factor authentication.
This is the method adopted by British tech firm MIRACL through its new technology, the M-Pin crypto application, a two-factor authentication protocol that involves a user-selected four-n length PIN and a related software token to create a unique key that runs a zero-knowledge proof authentication protocol against its server.
The token is stored on the user’s browser or mobile device, and the PIN is only known to the user. The fact that M-Pin stores no passwords on the server “will make password smash n’ grab attacks a thing of the past,” says Brian Spector, the company’s CEO.
The technology adds further safeguards by distributing its master keys between two D-TAs (Distributed Trust Authorities), one being the customer server, where the server application resides, and the other being the central MIRACL D-TA. This further complicates identity theft by requiring attackers to breach four different sources for each account they wish to hack.
MIRACL offers M-Pin in two flavors, a JavaScript code snippet and library embedded within websites, or a mobile version that allows users to control browser access to their accounts through a mobile app.
M-Pin will get its shot at delivering on its promise of improving both simplicity and security, as it was recently selected by certified identity assurance provider Experian to provide highly secure authentication to millions of U.K. citizens in a government-led project aimed at providing in a safe, secure and straightforward manner services such as driving license renewal and tax-form filing.

NFC two-factor authentication

Two-factor authentication through physical USB keys has been around for a while on desktop computers, but mobile devices have been slow to catch up. That has changed, as tech company Yubico launched a physical device that allows you to log in to your online accounts through Near Field Communication (NFC) technology.
Dubbed YubiKey NEO, the device is meant to be held against the back of an NFC-enabled phone and tapped to confirm user authenticity during login. The key generates a login code specific to the user and service at hand each time it’s pressed. After account access has been confirmed through YubiKey, that account can remain authenticated for a period of time (depending on the service), unless the service provider detects unusual activity, in which case the user will be prompted for YubiKey authentication again.
YubiKey NEO also offers the same multiple protocol support (OTP, U2F, PIV, OpenPGP) as the YubiKey 4, which means the device can be plugged into desktop computer USB ports to be used as a normal physical USB key during logins. YubiKey has been well received by some of the leading names in the tech industry, including Google, Dropbox and GitHub.
The YubiKey stores no personal details and is linked to an account, meaning that anyone with your credentials will also need the key to log in to your account. The only catch is that you’ll have one more device that you have to avoid losing.

Fingerprint authentication as a service

With more mobile devices sporting fingerprint scanners and cloud computing becoming cheaper, Qondado, a Puerto Rican tech startup, is trying to ease the way for developers to integrate biometric authentication into their web applications through a flagship platform it calls KodeKey.
The system, which is composed of a mobile app and a web service, ties users to their phone numbers via biometrics and allows clients to use that number and a PIN for authentication. The authentication platform can be integrated into any client site via an API or plug-ins (there’s currently a WordPress plug-in available).
When it comes to stealing identities, hackers seem to have an unlimited stash of weapons.
Registered users enter their phone number plus the associated PIN in the log-in page; they subsequently receive a notification on the KeyKode app which prompts them to scan their fingerprint. The web service will only allow access to the account if the mobile’s fingerprint scanner authenticates the user. The app is available on both Android and iOS, but will only function on newer handsets that have fingerprint scanners.
The company hopes to provide enterprise-level security for banks, credit card companies, cable providers, wireless providers and cloud services, and plans to develop plug-ins for a wide range of platforms in the future.

Mobile authentication

As the use of mobile devices is becoming increasingly widespread, users have an ever-present and personal tool to store and present their digital identity. This is becoming especially more feasible as newer mobile operating systems are offering trusted execution environments and hardware-secure elements to store sensitive data, such as cryptographic credentials.
This is a trend being embraced by two

Comments

Popular posts from this blog

How ad-free subscriptions could solve Facebook

At the core of Facebook’s “well-being” problem is that its business is directly coupled with total time spent on its apps. The more hours you pass on the social network, the more ads you see and click, the more money it earns. That puts its plan to make using Facebook healthier at odds with its finances, restricting how far it’s willing to go to protect us from the harms of over use. The advertising-supported model comes with some big benefits, though. Facebook CEO Mark Zuckerberg has repeatedly said that “We will always keep Facebook a free service for everyone.” Ads lets Facebook remain free for those who don’t want to pay, and more importantly, for those around the world who couldn’t afford to. Ads pay for Facebook to keep the lights on, research and develop new technologies, and profit handsomely in a way that attracts top talent and further investment. More affluent users with more buying power in markets like the US, UK, and Canada command higher ad prices, effectively...

Windows 7 and 8.1 Update to Windows 10 automatically

Windows 10 downloader While it might be a bit too early to start getting excited over the  Windows 10 update , which isn't expected to arrive until summer, Microsoft seems to already be warming up people's computers just the same. A recommended, and therefore purely optional, update for Windows 7 Service Pack 1 and Windows 8.1 has been discovered to be laying the groundwork for those machines' eventual upgrade to Windows 10. Although the  Windows 10 release date  was not announced officially, the details of this update also reveal how Microsoft might try to convince users to update to the latest Windows 10 version.  The  KB3035583  update "enables additional capabilities for Windows Update notifications when new updates are available to the user", which sounds pretty common. That is, until you dig into the update files and see a certain  GWXUXWorker.exe which, upon further inspection, would actually "Download Windows 10". So this rather ...

Anyline Raises €1.5M To Let You Add Optical Character Recognition To Your App

Anyline , the Austrian startup that provides mobile OCR tech to enable developers to add text recognition to their own apps, has raised €1.5 million in funding. The list of investors is interesting, too. It includes angel investor Johann ‘Hansi’ Hansmann, busuu co-founder Bernhard Niesner, Lukas Püspök, and the U.S.-based VC-fund iSeed Ventures. However, most notable is that the round was led by Gernot Langes-Swarovski Group. As one investor put it to me, “the fact that the Swarovski family led the round shows that finally ‘old’ money is moving into Austrian startups”. Offering its own mobile Optical Character Recognition (OCR) technology — which uses a smartphone’s camera to accurately scan and recognise any kind of text, code or number — Anyline co-founder and CEO Lukas Kinigadner tells me the startup is built on the premise that “people screw up a lot”. “Mistakes happen easily when you’re writing down a 10-digit-number and then have to type it in again a few moments later...

Three Reasons Why You Need Better Personal Cyber security

From the infamous Sony hack to the recent WannaCry virtual catastrophe that affected over 300,000 computers, the need for reliable personal cyber security has never been more apparent. Rubica's skilled team of experts want to remind every one of the importance of cyber security and the three reasons why it is becoming a more pressing issue every day. With top-notch personal cyber security, most attacks are preventable. 1. Larger Number Of Attacks Americans have heard of the most notable attacks on major corporations or government entities over the past several years. However, most people who are not in the information security field do not learn just how much the attack frequency is growing. The number of cyber attacks carried out worldwide in 2015 was quadruple a number of attacks recorded in 2013. Although the cost associated with the number of annual recorded attacks is in the $500 billion range right now, experts say that it will grow well into the trillions by ...

Insure Your Family by Controlling Devices Through an App

AIR: YOUR SMART HOME Have you ever rushed to your house suspecting that you may have accidently kept the iron turned on?  How do you deter a burglar  from breaking into your house? You probably would rush to your house and manually turn off the switch in the first instance, and get a burglar alarm for the next. But what if there were a single solution for both? Humans are delegating a lot of menial and repetitive tasks to machines. And as far as errands in your house and offices are concerned, the good news is – you can control appliances through your smart phone. INTRODUCING AIR: YOUR SMART HOME Air app, which is available on both Android and Apple platforms, interacts with your devices and switches them off with a single tap. AIR MOBILE APP The app is complemented with a package that consists of a pentagonal-shaped unit and switchboard module. Once you install air unit; your smartphone can interact with it using the Air App. Thereafter, the unit instructs the...