

{"id":2086,"date":"2011-08-10T05:24:25","date_gmt":"2011-08-10T09:24:25","guid":{"rendered":"http:\/\/streamingradioguide.com\/startingover\/?p=2086"},"modified":"2011-08-10T05:24:25","modified_gmt":"2011-08-10T09:24:25","slug":"the-future-of-passwords","status":"publish","type":"post","link":"https:\/\/streamingradioguide.com\/startingover\/?p=2086","title":{"rendered":"The future of passwords"},"content":{"rendered":"<p>Passwords have no future.\u00a0\u00a0\u00a0 I don&#8217;t know if it will be the government that forces it or private industry (like banks), but we&#8217;re past the point that using passwords and cookies for authentication is a reasonable method.<\/p>\n<p>There was a video on a local news site &#8211; it was not things I didn&#8217;t know, but made the point even clearer.\u00a0\u00a0 WiFi hot spots are now a trap to lose control of your accounts &#8211; especially in public places by airports.\u00a0\u00a0 A couple of my visitors recently had their email accounts taken over which I recognize when I get the &#8220;no subject&#8221; emails with someone&#8217;s entire address\u00a0book in the cc: trying to get me to visit a web site in Eastern Europe with a trojan downloader.<\/p>\n<p>The aspect they connected was that if you lose control of your Facebook account &#8211; because you aren&#8217;t using secure login, and Facebook says they don&#8217;t have the capacity to use encryption on everyone, if you&#8217;ve used those features &#8220;Link my facebook account to [something else],&#8221; you just gave access to all of your linked accounts as well.<\/p>\n<p>The next domino in the chain is the growth of the &#8220;Reset my password by sending me a reset message&#8221;\u00a0 (That&#8217;s what I use here).\u00a0\u00a0\u00a0 If a person has control of your primary email account, then they can run through all the likely accounts you have (linkedin, facebook twitter, yahoo, hotmail)\u00a0\u00a0and reset all your passwords and reset all your password recovery options.\u00a0\u00a0 Some of the smarter folks force a Security Question at that point &#8220;What was the name of your best friend as a child?&#8221;, but some of those are really not at all thought out well.\u00a0\u00a0\u00a0 Virtually every question they offer as an alternative is something my brother or sister would know (perhaps that&#8217;s the point in case I die so they can get control of my account without a court order?).\u00a0\u00a0 What was the address you grew up at, what school did you go to in 1st grade, what was your mother&#8217;s maiden name, what was the name of your dog, what was the name of your 1st grade teacher, etc&#8230;.<\/p>\n<p>People with a serious need for tight security carry around SecurID cards with ever changing passcodes, but that authentication was broken a few months ago.\u00a0\u00a0\u00a0 With government &#8220;actors&#8221; (China in particular) working to breach security and millions of hands available to do brute force breakins, the way we tell the internet who we are and prove it is going to have to change.<\/p>\n<p>IPv6 was supposedly going to partly address that by making your device&#8217;s MAC ID visisble on the packets it sends (at least part of it).\u00a0 Hard drives these days also have a unique identifier that could be used as a method of positive identification if it is tightly enough controlled and not spoofable.\u00a0\u00a0 I don&#8217;t know.\u00a0 I don&#8217;t have the answers, but it feels like we&#8217;re going into a war wearing just loincloths.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Passwords have no future.\u00a0\u00a0\u00a0 I don&#8217;t know if it will be the government that forces it or private industry (like banks), but we&#8217;re past the point that using passwords and cookies for authentication is a reasonable method. There was a &hellip; <a href=\"https:\/\/streamingradioguide.com\/startingover\/?p=2086\">Continue reading <span class=\"meta-nav\">&rarr;<\/span><\/a><\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[15],"tags":[],"class_list":["post-2086","post","type-post","status-publish","format-standard","hentry","category-american-politics"],"_links":{"self":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/2086","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=2086"}],"version-history":[{"count":1,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/2086\/revisions"}],"predecessor-version":[{"id":2087,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=\/wp\/v2\/posts\/2086\/revisions\/2087"}],"wp:attachment":[{"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=2086"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=2086"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/streamingradioguide.com\/startingover\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=2086"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}