Hitoshi Kokumai

4年前 · 2 分の読書時間 · ~10 ·

ブログ作成
>
ブログ Hitoshi
>
Removal of Passwords and Its Security Effect

Removal of Passwords and Its Security Effect

 

Assume that the password has been removed from digital identity. Then digital identity platforms would have only two authenticators - physical tokens and biometrics.

Biometrics by its nature requires a fallback measure against false rejection, and only the physical token could be the fallback measure for biometrics here. We have only two scenarios.

(1) authentication by a physical token, with an option of adding another token. Its security effect is plainly illustrated below.

he lock authenticates the key.
The key authenticates the lock.

  

Does the key authenticate
the person who holds it?

(2) authentication by a biometrics deployed in ‘multi-entrance’ method with a physical token as the fallback measure, with an option of adding another token. Its security is even lower than (1) as quantitatively examined at  https://www.bebee.com/producer/@hitoshi-kokumai/quantitative-examination-of-multiple-authenticator-deployment

We reckon that quite a few professionals of cyber security and identity management are well aware of these facts but something seems to prevent them from speaking out. Possibly, once they had touted those powerless solutions and recommendations to millions of clients, it might be embarrassing to admit the facts.

But it’s never too late to return. They are expected to speak out.


< Excerpt from Quantitative Examination .... >

Vulnerability (attack surface) of an authenticator is generally presented as a figure between 0 and 1. The larger the figure is, the larger the attack surface is, i.e., the more vulnerable. Assume, for instance, as just a thought experiment, that the vulnerability of the PKI-enabled token (x) be 1/10,000 and that of the password (y) be 10 times more vulnerable, say. 1/1,000. When the two are deployed in ‘multi-layer’ method, the total vulnerability (attack surface) is the product of the two, say, (x) and (y) multiplied. The figure of 1/10,000,000 means it is 1,000 times more secure than (x) alone.

 On the other hand, when the two are authenticators deployed in ‘multi-entrance’ method, the total vulnerability (attack surface) is obtained by (x) + (y) – (xy), approximately 0.0011. It is about 11 times less secure than (x) alone.

 So long as the figures are below 1, whatever figures are given to (x) and (y), deployment of 2 authenticators in ‘multi-layer’ method brings higher security while ‘multi-entrance’ deployment brings lower security. As such ‘multi-layer’ and ‘multi-entrance’ must be distinctly separated when talking about security effects of multiple authenticators.

The same calculation applies to biometrics used in cyber space where it has to rely on a fallback password/PIN deployed in ‘multi-entrance’ method against false rejection. You might assume that biometrics deployed with a password/PIN in ‘multi-layer’ method should bring us a very high security. But, very sadly, this scenario never comes true. When rejected by biometrics, what can we do? We will only see that we are unable to login even if we can feed our password/PIN. 


< Related Articles >

Big Myths in Digital Identity

History, Current Status and Future Scenarios of Expanded Password System


コメント

Hitoshi Kokumaiの記事

ブログを見る
2年前 · 2 分の読書時間

Taken up today is this TechRepublic report on voice print as a new password - https://www.techrepubl ...

2年前 · 3 分の読書時間

Today's topic is “Microsoft Exchange Autodiscover protocol found leaking hundreds of thousands of cr ...

2年前 · 2 分の読書時間

Another topic for today is “Passwordless made simple with user empowerment” · https://www.securitym ...

この職種に興味がある方はこちら

  • 横浜タカシマヤ百貨店

    婦人ニットカジュアル販売

    次の場所にあります: Whatjobs JP C2 - 1週間前


    横浜タカシマヤ百貨店 Yokohama, 日本

    (【横浜高島屋】婦人ニットカジュアル【pierre cardin signe】販売スタッフ募集) · 【今までの経験を活かして働きませんか?】 · 横浜駅前、抜群のアクセスで通勤がらくらくのデパート。 · 心地よいBGMと空調が整った店内。 · 何よりも落ち着いたお客様が多いので、ゆったりと上品に接客できるのが魅力。 · 【詳細】 · ・社員食堂利用可能 · ・休憩スペースやお昼を食べる場所あり · ・従業員割引にて購入可能 · 【ブランド説明】 pierre cardin signe / ピエール・カルダン シーニュ · 世界的に有名なブランドのニット ...

  • ナビ個別指導学院 日高中央校

    塾講師 アルバイト 個別指導/事務スタッフ

    次の場所にあります: beBee S2 JP - 1週間前


    ナビ個別指導学院 日高中央校 日高市, 日本 パートタイム

    雇用形態 · アルバイト · 職種・指導形態 · 個別指導 · 事務スタッフ · ※個別指導のほか、授業以外の雑務や、自習室の対応をお願いすることがあります。 · 給与 · 1コマ90分1,700円〜2,200円 · 時給で1134~1467円 · 最寄駅 · 高麗川駅より徒歩4分 · 待遇 · 研修期間中は1コマ(90分)1542円 · 授業以外の雑務、自習室対応の場合は、時給1028円 · 昇給あり 正社員登用あり · 仕事内容 · 自分自身のことを振り返りノウハウを伝えたり、成績UPを一緒に喜んだり · 初めての方も安心充実の「研修制度」がありま ...

  • 社会福祉法人華陽会 サービスネットワーク南陽

    介護職・ヘルパー(その他) (経験者)

    次の場所にあります: Whatjobs JP C2 - 1週間前


    社会福祉法人華陽会 サービスネットワーク南陽 Nagoya, 日本

    **タイトル**: · 介護職・ヘルパー(その他)(経験者) · **このお仕事の特徴**: · 急募 即日勤務OK · **勤務先名**: · 社会福祉法人華陽会 サービスネットワーク南陽 · **職種**: · 介護職・ヘルパー(その他)(経験者) · **仕事内容**: · - 介護支援専門員(ケアマネジャー)資格を活かして心機一転スタートしませんか? · 【こんな仕事をお任せします】 · 経験、未経験を問わずにマンツーマンにて指導します。土日休の週休2日日勤のみ、残業もほとんどありません子育てや家庭との両立をお考えの方にもオススメです大手法人のた ...