Hitoshi Kokumai

5年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Cyber Predicament by Text-Only Password Systems

Cyber Predicament by Text-Only Password Systems

d28e9b28.png 

Abstract

It is obvious that we can no longer continue to rely on the conventional form of password systems. Nor can the conventional forms of deploying biometrics, ID-federations and multi-factor authentications that have relied on the conventional password, as a fallback means, a master-password and one of the factors respectively. However, we do not have to despair. There exists an incredibly simple solution to it, though little known to the public as yet. 

The global password predicament will melt away when people are offered a broader password choice.

Password Predicament

You are probably aware of the huge data breach that a student brought about in Germany. A NYT report on 8/Jan (*1) reads "A 20-year-old German student took advantage of passwords as weak as “ Iloveyou” and “1234” to hack into online accounts of hundreds of lawmakers and personalities whose political stances he disliked, officials revealed Tuesday, shaking Berlin’s political establishment and raising questions about data security in Europe’s leading economy."

If attacking the targets with the passwords such as "Iloveyou” and “1234” is like taking candy from a baby for a student, it must be like taking candy from a sleeping baby for organized criminals. What happened in Germany could no doubt have happened everywhere else.

Half-baked Propositions

We now anticipate that a number of security professionals will be yet more ardently urging people to

1. throw away easy-to-remember passwords while neither writing down the passwords on a memo nor re-using the same passwords across many accounts, in other words, do what humans are unable to do.

2. take up biometrics instead of passwords, probably without mentioning that the biometrics has to be deployed together with a password in a security-ruining'multi-entrance' method (*2).

3. adopt a password-manager, probably without mentioning that it comes with a risk of creating a single point of failure like putting all the eggs in a single basket and that a high-entropy password is indispensable as the master-password.

4. consider a multi-factor authentication, probably without mentioning that the password would be the last resort when something-to-possess is broken, left behind, lost, copied and stolen.

5. eliminate the use of passwords altogether, probably without mentioning that we would be thrown into a 1984-like dystopia when identity authentication happens without our knowledge or against our will.

And, tech/biz media will be busy with yet more loudly spreading all those wrong or inaccurate perceptions and suggestions.

However, the real picture is actually so plain and clear; the current password predicament is caused by the conventional password systems that do not allow people to use anything but numbers/characters.

Expansion of Password System

There exists an incredibly simple solution to it. The existence of this solution is little known to the public as yet, though, largely because it does not offer big incentives to the people who have been advocating, endorsing and promoting the above (1) to (5) propositions.

It is called ‘Expanded Password System’ and an OASIS project is progressing for the standardization in view of such desirable features as follows.

- It is not only stress-free for users but fun to use, as opposed to the dread and overhead that come today with creating, memorizing and storing passwords

- It turns a low-entropy password into high-entropy authentication data

- It eases the burden of managing the relationship between accounts and passwords

- It deters phishing attacks

- It can be deployed under any type of circumstance, including combat

- It supports existing schemes, such as:

    - Biometrics which require passwords as a fallback means

    - Two/multi-factor authentications that require passwords as one of the factors

    - ID Federations such as password managers and single-sign-on services that require passwords as the master-password

    - Simple pictorial/emoji-passwords and patterns-on-grid can be deployed on this platform.

- It is relevant whenever text passwords and pin numbers are in use

- And, nothing would be lost for people who want to keep using text passwords

- Last but not least, it continues to rely on free will.

The proposition of Expanded Password System is in the ‘Draft Proposal’ stage at OASIS OpenProjects (*3). Should you be concerned about the current status of identity assurance, you might be interested to keep an eye on it and help us where possible.


Footnote

*1 German Man Confesses to Hacking Politicians’ Data, Officials Say

https://www.nytimes.com/2019/01/08/world/europe/germany-hacking-arrest.html

*2 Horrific Distinction between ‘Multi-Layer’ and ‘Multi-Entrance’ Deployments

https://www.linkedin.com/pulse/horrific-distinction-between-multi-layer-deployments-hitoshi-kokumai

*3 Draft Charter

https://docs.google.com/document/d/1lHFWGMmFHN4xwm9q6ajQ1vZtFFaKNNgHJKHMnvcNS0s/edit#

                        (Shot ofExpanded Password System Deployed on Mobile Phone)

"
コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 3 分の読書時間

Today's topic is “Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of cr ...

2年前 · 2 分の読書時間

Our password headache may well be the consequence of these dual causes - · ‘Use of Impracticable Pas ...

2年前 · 2 分の読書時間

We today take up this report “NSA: We 'don't know when or even if' a quantum computer will ever be a ...

この職種に興味がある方はこちら

  • 北野田医療生活協同組合 にじのさと北野田

    介護職・ヘルパー(大阪府堺市東区の小

    次の場所にあります: Whatjobs JP C2 - 3日前


    北野田医療生活協同組合 にじのさと北野田 堺市 東区, 日本

    【おすすめポイント】 · 《常勤》【堺市東区・駅チカ】小規模多機能にて介護スタッフの募集ですブランクのある方も歓迎ですマイカー通勤OK · スタッフ同士が協力し合いながら業務に取り組む明るい職場なので、働きやすさも抜群です · 【仕事内容】 · 小規模多機能にて介護業務全般をお願い致します。明るくアットホームな雰囲気が特徴で、スタッフ同士いつも助け合って働いています 経験の浅い方や、ブランクのある方も先輩スタッフによる丁寧な指導がありますので、安心してお仕事をスタートすることができます お持ちの資格・経験を活かせるお仕事です一緒に頑張ってくださる方ご応募 ...


  • SUR 合格指導会 大学受験 堺東校 堺市堺区, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 集団指導(10名以上) · グループ指導(10名以下) · 大学受験に向けた高校生の集団指導・質問対応・生徒懇談などをお願いします。不安な方は、チューターからのスタートも可能です · 給与 · 時給4,000円 · 別途昇給機会あり · 模擬授業などの研修やチューター業務については時給1065円 · (チューター業務...質問対応・生徒懇談・事務作業など) · 最寄駅 · 堺東(南海高野線)駅より徒歩2分 · 花田口駅より徒歩18分 · 妙国寺前駅より徒歩18分 · 堺タカシマヤ内 7階 · 待遇 · 交 ...

  • ROW 銀座

    美容師スタイリスト【正社員】

    次の場所にあります: beBee S2 JP - 18時間前


    ROW 銀座 中央区銀座, 日本 フルタイム

    ROW 銀座の美容師・美容室の求人情報 · 【自分らしく働けるサロン】個室完備×顧客単価13,911円 · ★2024年NEW OPEN · ・1月5日:Dijon 渋谷(東京) · ・2月1日:newi 所沢(埼玉) · ・3月1日:newi 銀座(東京) · ・6月:ROW 川崎 (神奈川) · 続々オープン予定 · オープニングスタッフ募集♪ · 【正社員】 · ・基本給+歩合制度 · ・社会保険完備 · ・顧客単価13,911円/月平均 · ・集客1821名/月平均 · ●storageの正社員はココがポイント · 1出勤時間の設定=自由 · 2 ...