Hitoshi Kokumai

4年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Context-dependent Descriptions of ‘Password-less’ Authentication

Context-dependent Descriptions of ‘Password-less’ Authentication

Illusions

LLL

Zz,
5555555

 

KN AV Distractions

Hn

The word 'Password-less' seems to be multi-semantic depending on the context. Let us break it down.

1. Where the entire family of passwords is removed from digital identity altogether, we would have only two authenticators - physical token and biometrics.

Since biometrics requires another factor as a fallback measure against false rejection, this means that we would have only two types of solutions in the world - (a) authentication by physical token alone, security effect of which is illustrated below, and (b) authentication by biometrics used with a physical token in 'multi-entrance' deployment, which provides the level of security yet lower than the authentication by a physical token alone.

he lock authenticates the key.
The key authenticates the lock.

  

Does the key authenticate
the person who holds it?Very nice news to bad guys, isn't it?

2. Where PIN is viewed as not belonging to the family of passwords, advocates of ‘password-less’ authentication should be able to achieve a password-less authentication by relying on the PIN that is no more than a numbers-only password.

Some people allege that a PIN linked to a physical device is more reliable than a password not linked to a physical device. Those people would not reply to the question "What about a password linked to a physical device?"

A small child with a sharp sword might be able to repel an unarmed adult, but what if the adult is also armed with a similar sword?

3. Where a default/backup password is not viewed as the password, there could be a 'Password-less authentication achieved by biometrics that is dependent on a backup password'

In their world where a default/backup password is not the password, a second-entrance is not the entrance

Attempts to remove secret credentials and bring in biometrics don’t help but only make the matter even worse. We would like advocates of ‘password-less’ authentication to understand what they are advocating for whom.

Worry about a backdoor?

< Related Articles >

Digital Lemming’s Congested Competition for Bestseller Snakeoil

 Biometrics and Me

 Publication on EDPACS of Taylor & Francis


< Reposting of “Entertaining Security Topics” >

Current foot brakes are far from sufficient in the slip distance. This means that the foot brake system is dangerous. We have now removed the dangerous foot brake system from the cars we sell. We instead offer the safer cars that are equipped with better steering handles, better acceleration pedals and better hand brakes.

Physical keys are often stolen, copied and abused. This means that the lock/key system is dangerous. We have now removed the dangerous lock/key system from the houses that we sell. We instead protect our houses by making the door panels thicker and heavier

Passwords are often stolen, leaked and abused. This means that the password system is dangerous. We have now removed the dangerous password system from digital identity. We instead protect the digital identity of our clients by offering the safer choice of ‘physical tokens and biometrics’ instead of the dangerous choice of ‘passwords’, ‘physical tokens’ and ‘biometrics’.

Can a paper-knife do

what the knife cannot do?A house with two entrances provides better security than a house with one entrance. We suggest the owners of one-entrance houses to place an extra entrance for better security in the regions where we do not have to care about the definition of ‘better’ or for whom it is ‘better’.

Biometrics, when used as an authenticator in cyber space, needs to be deployed in ‘multi-entrance’ method with a password/PIN as a fallback measure against false rejection. We now offer the password/PIN-dependent biometrics that provides better security than the password­-only authentication. Our proposition is viewed as valid where they do not ask the definition of ‘better’ or for whom it is 'better'.

cc4f829e.png

A paper knife (specific/subordinate concept) belongs to the knife (general/superordinate concept). Therefore a paper knife must be able to perform what the knife is unable to perform.


A PIN, which is a weak form of numbers-only password, belongs to the password. Therefore, a PIN (specific/subordinate) must be able to offer the high level security that the password (general/superordinate) is unable to offer, possibly in a cyber version of Alice’s Wonderland.


#identity #authentication #password #security #safety #biometrics #ethic #privacy #civilrights #democracy


コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

The quantum computer held in a bad guy’s hand is indeed a big threat. So is the artificial intellige ...

2年前 · 2 分の読書時間

Some friends directed my attention to this news report - · “Biometric auth bypassed using fingerpri ...

2年前 · 2 分の読書時間

We today take up this report “NSA: We 'don't know when or even if' a quantum computer will ever be a ...

この職種に興味がある方はこちら

  • 株式会社 綜合キャリアオプション

    物流・配送・軽作業

    次の場所にあります: beBee S2 JP - 5日前


    株式会社 綜合キャリアオプション 芳賀郡市貝町, 日本 TEMPORARY

    株式会社 綜合キャリアオプション · 重いモノ基本ナシ/容器やキャップのチェック&梱包/日払いOK · ====仕事内容==== · 人気の軽作業のオシゴト · 扱う物はプラスチック製のキャップや容器だから軽くてラクラク♪ · 負担少な目で製造ワークが初めての方もデビューしやすい · 製造のお仕事をしてみたいけど重い物は...なんて方にオススメ♪ · ていねいな研修があるので未経験からスタートでも安心☆ · モクモク作業で重いモノも基本なし · 3交替だけど大型連休があります♪ · 制服ありで事前の準備は不要 · 通勤はクルマ・バイク・自転車OK◎もちろ ...

  • グリーンホスピタリティフードサービス株式会社

    社員食堂の洗い場

    次の場所にあります: Whatjobs JP C2 - 6日前


    グリーンホスピタリティフードサービス株式会社 千代田区 大手町, 日本

    **社員食堂の洗い場**: · **大企業内の社員食堂で安定的にお仕事&土日祝お休み** · **食器の洗浄作業です** · - お客様と直接の接客はありません。不安な方でも安心 · **募集要項**: · **仕事内容** · - 社員食堂での食器洗浄のお仕事です。 · - 作業はとっても簡単未経験でも丁寧にお教えします(^^)/ · - 誰でも知っている大企業内の食堂で、安定的に働けます · - どんな職場なのか 気になる方は職場見学からでもOK · - ご応募の際にお気軽にお申し出ください。**掲載企業名** · - グリーンホスピタリティフードサ ...


  • パクテラ・コンサルティング・ジャパン(株) Tokyo, 日本

    日本をヘッドクォーターとする大手製造業様の本社セキュリティチームと海外拠点の橋渡しとして、PMO等の各種サポートを行い、プロジェクトを推進していただきます。 · 【具体的には】 · ■セキュリティ関連施策の海外への展開支援(計画検討、課題管理、コミュニケーション管理、会議体運営・ファシリテーション、議事録作成、関係構築、プロジェクト計画書、管理計画書その他各種資料作成、ツール説明資料レビュー等) · ■日常的に国内に向けてはクライアントマネジメント層、他ベンダーと折衝し、海外向けには現場からマネジメント層まで幅広く対応します。 ...