Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Ah, this is true but you've just made a very big leap from simply obtaining a password to now successfully installing a rootkit and key logger and obtaining both the keychain and password. We could go back and forth about the likelihood of this on a patched, virus protected machine (ok, there are still zero days), but we're starting to greatly reduce the probability as it is.

I'd love to see two factor auth or at least the option of RSA style tokens and we're gradually seeing that in some places but unfortunately we're still stuck with the status quo for the vast majority of sites for the foreseeable future.



I don't disagree with that, but I am making a different point. Password systems, by their nature, require lots and lots of actions from users: making up passwords, resetting them when expired, making a keyfile and keeping it safe and backed up (if using a password manager), remembering a long and random master password, and the list goes on - e.g. remembering not to reuse passwords or use similar passwords. It's been proven over and over and over and over again that users will not do these things. It's not like password managers are new; they've been around for 15 years, and haven't made a dent. We can keep banging our heads against that wall, or we can give users a solution that doesn't depend on them doing and remembering dozens of technical actions. "This is the key to your bank account. Don't lose it, but if you do, call us." This can work.

And from a technical point of view, all password systems have a weakness of having long-term credentials - a stolen password can be used for months, at any time, until it expires. That part is not fixable.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: