jducoeur: (Default)
jducoeur ([personal profile] jducoeur) wrote2007-02-13 10:31 am
Entry tags:

The mark of a new trend is the growth of spoof sites...

... and therefore, the sign that the whole "Identity 2.0" thing is starting to matter is the appearance of Useless Account. Nothing like a cry of frustration to illustrate that there's a problem...

[identity profile] goldsquare.livejournal.com 2007-02-13 03:46 pm (UTC)(link)
My concern is password pollution.

Either you have a single password used everywhere - and you are going to be dead if one of those sites is evil or bad and divulges that password.

Or you have 10,000 passwords, and are drowing.

Yes, a password keeper exists, but that's all eggs and baskets now, isn't it? (We've had one co-worker keep all his passwords in his Palm. Then it broke. He couldn't do much work for the next few days until he replaced it.)

[identity profile] metahacker.livejournal.com 2007-02-13 04:30 pm (UTC)(link)
Hear, hear.

[identity profile] dlevey.livejournal.com 2007-02-13 04:41 pm (UTC)(link)
"Either you have a single password used everywhere - and you are going to be dead if one of those sites is evil or bad and divulges that password."

That becomes worse rather than better if we move to biometric factors, doesn't it? If you use the same password for 100 sites and it gets cracked, you can change passwords. Changing fingerprints or retinal prints is a bit more difficult.

[identity profile] goldsquare.livejournal.com 2007-02-13 04:43 pm (UTC)(link)
Good point.

Although most of us have 9 more fingers, and one spare eye...

[identity profile] dlevey.livejournal.com 2007-02-13 04:47 pm (UTC)(link)
Well OK, spoilsport!
The options would be limited regardless. And of course now I'm picturing some of the high-tech crime shows we get now, and a market for recently-severed fingers...

The future is...wait, wasn't this in Minority Report?

[identity profile] metahacker.livejournal.com 2007-02-13 05:45 pm (UTC)(link)
Hacked? Buy new fingerprints and eyeballs! Ask Medicare for coverage!

Re: The future is...wait, wasn't this in Minority Report?

[identity profile] dlevey.livejournal.com 2007-02-13 06:07 pm (UTC)(link)
Was it? I honestly don't know - I tend to stay away from Tom Cruise movies. Perhaps I should write them, instead.
mindways: (Default)

[personal profile] mindways 2007-02-13 06:48 pm (UTC)(link)
Either you have a single password used everywhere - and you are going to be dead if one of those sites is evil or bad and divulges that password.

Or you have 10,000 passwords, and are drowing.


There is a middle ground: using a single password for each class of sites - a social-sites password, an e-commerce password, a sign-up-to-read (news, etc) password, and so forth. If one of your credentials is then cracked, the *extent* of the ensuing problems may be greater than if one were drowning in 10,000 passwords, but the *nature* of the troubles will be confined to the type of site in question.

(Not necessarily a good idea for very high-stakes things like financial websites. But for just about everything else, it seems like a reasonable compromise.)

[identity profile] goldsquare.livejournal.com 2007-02-14 12:56 am (UTC)(link)
I used to work on a single-sign-on/web of trust product, so I continue to follow the literature from time to time.

Not only are there the security issues that you specify - there is the entire "availability" issue to consider. Every intermediary you employ, must be functioning flawlessly.

Meh.

[identity profile] its-just-me.livejournal.com 2007-02-13 07:06 pm (UTC)(link)
Oh that's lovely!