republican-creole
site Search:


 
    All Forums Hot Topics Gallery






how-to block ads


 
Search Topic:
Share Topic
Posting?
Post a:
Post a:
Links: ·Hijack This logs? ·Panda Free Tools ·Vundo Removal
AuthorAll Replies

dave
Premium,MVM
join:2000-05-04
not in ohio
kudos:8

reply to antdude

Re: Google Declares War on the Password

Does no-one in the security forum except me actually use a hardware logon token for anything? There seems to be a lot of resistance to having any physical thing that helps logon security.

For the record, the problems with the current hardware logon-token approaches are:

1. As far as I know, it's site-specific [my RSA token has to be known to the web site in question], so isn't going to scale

2. I have to copy the digits from the token to the password-entry form: but this is fixable by having a token with a USB interface

3. It doesn't eliminate passwords, and nor should it (for the same reasons that having an ATM card doesn't eliminate PINs). But it does reduce required password complexity.

I don't see that the Wired article is suggesting much more than using the same sort of approach but making it more ubiquitous. And smaller.

Since it's actual money involved with the web site in question, I'm glad of the incremental protection of the token on top of the password.

For the record, I've never lost it, forgotten it, or suffered more inconvenience than having left the token in my coat downstairs when I'm upstairs.

The technology question we perhaps ought to consider here is: how secure is it to rely on a single authentication service?


sivran
Opera convert
Premium
join:2003-09-15
Arlington, TX
kudos:1

I have a paypal fob.

I barely use it anymore as I rarely log into paypal.


Thursday, 23-May 09:57:53 Terms of Use & Privacy | feedback | contact | Hosting by nac.net - DSL,Hosting & Co-lo
over 13.5 years online © 1999-2013 dslreports.com.
Most commented news this week
Hot Topics