Hitoshi Kokumai

5年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Cyber Predicament by Text-Only Password Systems

Cyber Predicament by Text-Only Password Systems

d28e9b28.png 

Abstract

It is obvious that we can no longer continue to rely on the conventional form of password systems. Nor can the conventional forms of deploying biometrics, ID-federations and multi-factor authentications that have relied on the conventional password, as a fallback means, a master-password and one of the factors respectively. However, we do not have to despair. There exists an incredibly simple solution to it, though little known to the public as yet. 

The global password predicament will melt away when people are offered a broader password choice.

Password Predicament

You are probably aware of the huge data breach that a student brought about in Germany. A NYT report on 8/Jan (*1) reads "A 20-year-old German student took advantage of passwords as weak as “ Iloveyou” and “1234” to hack into online accounts of hundreds of lawmakers and personalities whose political stances he disliked, officials revealed Tuesday, shaking Berlin’s political establishment and raising questions about data security in Europe’s leading economy."

If attacking the targets with the passwords such as "Iloveyou” and “1234” is like taking candy from a baby for a student, it must be like taking candy from a sleeping baby for organized criminals. What happened in Germany could no doubt have happened everywhere else.

Half-baked Propositions

We now anticipate that a number of security professionals will be yet more ardently urging people to

1. throw away easy-to-remember passwords while neither writing down the passwords on a memo nor re-using the same passwords across many accounts, in other words, do what humans are unable to do.

2. take up biometrics instead of passwords, probably without mentioning that the biometrics has to be deployed together with a password in a security-ruining'multi-entrance' method (*2).

3. adopt a password-manager, probably without mentioning that it comes with a risk of creating a single point of failure like putting all the eggs in a single basket and that a high-entropy password is indispensable as the master-password.

4. consider a multi-factor authentication, probably without mentioning that the password would be the last resort when something-to-possess is broken, left behind, lost, copied and stolen.

5. eliminate the use of passwords altogether, probably without mentioning that we would be thrown into a 1984-like dystopia when identity authentication happens without our knowledge or against our will.

And, tech/biz media will be busy with yet more loudly spreading all those wrong or inaccurate perceptions and suggestions.

However, the real picture is actually so plain and clear; the current password predicament is caused by the conventional password systems that do not allow people to use anything but numbers/characters.

Expansion of Password System

There exists an incredibly simple solution to it. The existence of this solution is little known to the public as yet, though, largely because it does not offer big incentives to the people who have been advocating, endorsing and promoting the above (1) to (5) propositions.

It is called ‘Expanded Password System’ and an OASIS project is progressing for the standardization in view of such desirable features as follows.

- It is not only stress-free for users but fun to use, as opposed to the dread and overhead that come today with creating, memorizing and storing passwords

- It turns a low-entropy password into high-entropy authentication data

- It eases the burden of managing the relationship between accounts and passwords

- It deters phishing attacks

- It can be deployed under any type of circumstance, including combat

- It supports existing schemes, such as:

    - Biometrics which require passwords as a fallback means

    - Two/multi-factor authentications that require passwords as one of the factors

    - ID Federations such as password managers and single-sign-on services that require passwords as the master-password

    - Simple pictorial/emoji-passwords and patterns-on-grid can be deployed on this platform.

- It is relevant whenever text passwords and pin numbers are in use

- And, nothing would be lost for people who want to keep using text passwords

- Last but not least, it continues to rely on free will.

The proposition of Expanded Password System is in the ‘Draft Proposal’ stage at OASIS OpenProjects (*3). Should you be concerned about the current status of identity assurance, you might be interested to keep an eye on it and help us where possible.


Footnote

*1 German Man Confesses to Hacking Politicians’ Data, Officials Say

https://www.nytimes.com/2019/01/08/world/europe/germany-hacking-arrest.html

*2 Horrific Distinction between ‘Multi-Layer’ and ‘Multi-Entrance’ Deployments

https://www.linkedin.com/pulse/horrific-distinction-between-multi-layer-deployments-hitoshi-kokumai

*3 Draft Charter

https://docs.google.com/document/d/1lHFWGMmFHN4xwm9q6ajQ1vZtFFaKNNgHJKHMnvcNS0s/edit#

                        (Shot ofExpanded Password System Deployed on Mobile Phone)

"
コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

Today's topic is BBC's “Facebook to end use of facial recognition software” · https://www.bbc.com/n ...

2年前 · 2 分の読書時間

Today's topic is this report - “How blockchain technology can create secure digital identities” · h ...

2年前 · 2 分の読書時間

Another topic for today is “Passwordless made simple with user empowerment” · https://www.securitym ...

この職種に興味がある方はこちら

  • 株式会社多田自動車商会

    正社員/リサイクル部品販売・廃車買取

    次の場所にあります: Whatjobs JP C2 - 6日前


    株式会社多田自動車商会 大阪市 住之江区, 日本

    **☆フロントスタッフ募集☆未経験OK実働7時間の働きやすい職場です♪** · **▼求職者の方へメッセージ▼** · 頑張るあなたを全力で応援します · 安心して働ける思い切り働けるそんな新しいステージであなたらしく活躍しませんか?? · 【1日の流れ】 · 8:45~ 朝礼・ラジオ体操 · 9:00~ 各業務 · 12:00~ ≪お昼休憩≫ · 13:00~15:00 各業務 · 15:00~15:15 休憩(おやつタイム♪) · 15:15~17:00 各業務 · 実働7時間なのでプライベートも充実させることが出来ます♪ · 残業は職種により異なり ...

  • 寿司はせ川

    予約制の寿司屋でホールスタッフ(高校

    次の場所にあります: Whatjobs JP C2 - 4日前


    寿司はせ川 Osaka, 日本

    **予約制の寿司屋でホールスタッフ(高校生可) |1日3時間から**: · **\週2日~、1日3時間からOK2週間毎のシフト制/絶品のまかないあり** 「初めての飲食アルバイト」「初めてのバイト」も歓迎**学んだ英語を活かせます** · < 18時や18時半からの勤務開始も応相談 > · 自転車通勤OK**さらに交通費も支給します** · 基本予約制のため店内は比較的落ち着いた雰囲気です · **募集要項**: · **仕事内容** · 落ち着いた雰囲気のお店でホール業務をお任せします。 · 基本ご予約中心なので、慌ただしく店内を走り回る必要はありませ ...


  • 八重洲無線(株) 福島県, 日本

    船舶用・航空機用無線通信機等の業務用の無線機から、アウトドアに使用される無線機など幅広い製品を揃える無線通信機器メーカーの当社にて、 · 貿易事務業務(製品の受注、納期・出荷管理)をお任せします。 · 【具体的には】■海外取引先からの受注入力・納期管理、出荷・船積業務管理、売掛回収 · ■海外取引先への納期回答業務、各種問い合わせ対応 · ■海外代理店の販売管理、販売促進活動サポート · ■海外協力工場の生産納期管理業務 · ■出荷指示業務(基幹システム操作) · ■海外市場への販売予測とそれに基づく生産計画業務 ...