Boston Linux & UNIX was originally founded in 1994 as part of The Boston Computer Society. We meet on the third Wednesday of each month at the Massachusetts Institute of Technology, in Building E51.

BLU Discuss list archive


[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[Discuss] Most common (or Most important) privacy leaks



On 02/17/2015 12:51 PM, Kent Borg wrote:
> I think the only way to fix the password problem is to get people to
> discard security theater and think and understand and be disciplined.
> But if you can fix the password problem, I think the next problems
> ~start~ to fix themselves.
>
> But I don't know, because everyone does passwords wrong.

Most of the people I want to "think and understand" are actually the 
people running systems that need passwords and coming up with obnoxious 
requirements for passwords that essentially force you to write 
everything down.  You can make people choose good passwords, but you 
can't make them have good habits.

The only way to solve the password problem is to do away with them. 
There are all manner of physical tokens that can be used (SecurID, 
SmartCards, etc) in conjunction with a "something you know"/PIN that can 
actually be memorized.

Apparently this isn't so far fetched.  Banks in Germany (and now some in 
the US) give their customers SecurID tokens to use for login and ACH 
transfers.

I would love if there were a way to marry OpenID with 
SmartCards/certificates... (maybe there is, I haven't paid much 
attention to OpenID in a while)

Matt



BLU is a member of BostonUserGroups
BLU is a member of BostonUserGroups
We also thank MIT for the use of their facilities.

Valid HTML 4.01! Valid CSS!



Boston Linux & Unix / webmaster@blu.org