Abolish passwords.
Conversation
Notices
-
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:46:18 JST CEO of Anti-Clock Society -
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:46:14 JST CEO of Anti-Clock Society Password managers are to passwords like address sanitizer is to memory unsafe programming languages. They're mitigations, but do not solve the problem. The only way to solve the problem is to switch to a fundamentally different solution.
-
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:46:15 JST CEO of Anti-Clock Society I wish people talked about passwords the same way they talk about memory unsafe programming languages.
Adrian Cochrane repeated this. -
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:46:16 JST CEO of Anti-Clock Society Authenticating with remote servers by exchanging a shared secret is a bad idea and always has been.
-
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:46:17 JST CEO of Anti-Clock Society Infosec people be like yelling at users to use password managers instead of yelling at developers to implement WebAuthn.
-
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 02:47:12 JST CEO of Anti-Clock Society @downey There are profits to be made in selling FIDO authenticators and consulting with organizations to switch to WebAuthn.
-
Michael Downey 🇺🇳 (downey@floss.social)'s status on Saturday, 24-Dec-2022 02:47:13 JST Michael Downey 🇺🇳 s/Infosec/corporate/
The latter isn't profitable.
Adrian Cochrane repeated this. -
CEO of Anti-Clock Society (be@floss.social)'s status on Saturday, 24-Dec-2022 06:34:32 JST CEO of Anti-Clock Society Why do memory unsafe programming languages get so much more attention problemitizing them than passwords? I think passwords are a much bigger risk for most people than unsafe memory access which will most likely cause the affected program to crash. Passwords are routinely exploited by phishing and mass leaks of password hashes from hacked servers.
-