Author Topic: White House goal: Kill the password  (Read 888 times)

0 Members and 1 Guest are viewing this topic.

Offline mystery-ak

  • Owner
  • Administrator
  • ******
  • Posts: 384,828
  • Let's Go Brandon!
White House goal: Kill the password
« on: February 13, 2015, 01:31:16 pm »
http://thehill.com/policy/cybersecurity/232684-white-house-goal-kill-the-password

By Cory Bennett - 02/13/15 06:00 AM EST
The White House is funding efforts to wipe out the password as the primary security code used to access sensitive data online.

Officials and cybersecurity experts say the password is inherently weak and frequently misused, with easily hacked phrases like “password” and “123456” putting bank accounts, Social Security numbers and other sensitive information at risk.

“It’s probably the highest vulnerability there is,” said Keith Ward, CEO of the Translogbal Secure Collaboration Program (TSCP), a company chosen by the White House to work on securely transmitting sensitive data between defense companies.

For many, the ultimate goal is to “kill the password,” which has become a favorite refrain for White House Cybersecurity Coordinator Michael Daniel.
Lisa Monaco, President Obama’s homeland security advisor, has said eradicating passwords is one of the administration's four cyber goals.

Since 2012, a White House program, the National Strategy for Trusted Identities in Cyberspace, has backed a number of pilot projects aimed at finding new ways to identify people without a password.

The companies are testing password alternatives that would have people authenticate their identity online using mobile devices, digital rings and even bracelets. The White House has also bankrolled efforts to securely identify children online and streamline the login process across different financial accounts.

Working with a $16.5 million budget, the program has pushed password alternatives from niche markets toward the mainstream.

“The whole program has really helped speed two things,” said Matt Thompson, co-founder of ID.me, which verifies whether users are active-duty military, veterans, first responders, teachers or students. “One, the commercial adoption of our platform. Secondly, the adoption by government agencies of our technology.”

Daniel has estimated some of the White House-backed solutions could hit the mass market sometime in 2015.

That would be a relief to observers who say companies and consumers are “willfully blind” to the problems with passwords.

“That is the reason why all these breaches are just going to keep happening,” said Joe Siegrist, CEO of LastPass, a password management company.

With studies showing individuals now juggle more than 20 total passwords at a time, typing out an average of eight per day, systems are more vulnerable than ever before.

“The complexity of the problem has grown,” said Emmanuel Schalit, CEO of Dashlane, another password management company.   

A slew of recent hacks have shown just how damaging a password breach can be.

The highest-profile incident came last fall, when dozens of celebrities, including Jennifer Lawrence, Kate Upton and Kim Kardashian had nude photos stolen from their Apple cloud accounts. The hackers used software that simply guessed at their passwords.

While the digital thieves couldn’t crack Apple’s online storage unit, figuring out the login for individual users was easy.

More recently, hackers broke into the system of the health insurer Anthem Inc., likely after using fraudulent emails to infiltrate network administrator’s computers and steal login credentials. The infiltrators eventually made off with data from up to 80 million customers, including hard-to-replace Social Security numbers.

And following the massive Sony hack, one of the more amusing — and troubling — discoveries in the data dump was a document titled “Password” that contained, well, passwords.

The hacking incidents show companies and individuals are paying little attention to login security, experts say.

Companies let employees share sign-in data, allow unfettered access to anyone with a login and implement policies that actually encourage bad habits. If forced to rotate their password each month, for instance, staffers will often choose passwords like “April2014” and “May2014.”

“Everyone is trying to use the same key for every lock in their entire life,” Siegrist said, adding that 60 to 80 percent of companies LastPass has worked with were reusing login credentials.

“It’s just a complete disaster,” he said.

Despite the push from the White House, experts say there’s a long way to go before passwords are a thing of the past.

“I don’t think anyone really sees username and password really leaving,” said TSCP’s Ward. “It’s a generational thing.”

Companies like LastPass and Dashlane have turned the password problem into a business opportunity, offering products that store all of a user’s passwords in an encrypted vault, with only one master password required to access them all.

LastPass has grown to 6.3 million users, with the entire password manager market hitting roughly 15 million users, Siegrist estimated.

Security experts like Siegrist stress the importance of two-factor authentication. In addition to the password, two-factor logins require a second type of verification, like a personal question or a code sent to a mobile phone.

“You do those two things, you’re so far ahead of the game,” he said. “Almost untouchable compared to the rest of the world.”
Proud Supporter of Tunnel to Towers
Support the USO
Democrat Party...the Party of Infanticide

“Therefore do not worry about tomorrow, for tomorrow will worry about itself. Each day has enough trouble of its own.”
-Matthew 6:34

Offline flowers

  • Hero Member
  • *****
  • Posts: 18,798
Re: White House goal: Kill the password
« Reply #1 on: February 13, 2015, 03:20:15 pm »
 White House goal: Killthe password everything that gives the masses freedom. Fixed it.


Offline GourmetDan

  • Hero Member
  • *****
  • Posts: 7,277
Re: White House goal: Kill the password
« Reply #2 on: February 13, 2015, 03:22:51 pm »
The companies are testing password alternatives that would have people authenticate their identity online using mobile devices, digital rings and even bracelets.

Only a very short step to a chip under the skin of your hand...


"The heart of the wise inclines to the right, but the heart of the fool to the left." - Ecclesiastes 10:2

"The sole purpose of the Republican Party is to serve as an ineffective alternative to the Democrat Party." - GourmetDan

Offline jmyrlefuller

  • J. Myrle Fuller
  • Cat Mod
  • *****
  • Posts: 22,413
  • Gender: Male
  • Realistic nihilist
    • Fullervision
Re: White House goal: Kill the password
« Reply #3 on: February 13, 2015, 03:30:40 pm »
What they really want is something the government can hack.
New profile picture in honor of Public Domain Day 2024

Offline aligncare

  • Hero Member
  • *****
  • Posts: 25,916
  • Gender: Male
Re: White House goal: Kill the password
« Reply #4 on: February 13, 2015, 03:37:29 pm »
I despise this White House, but they are right. The password must go. It is the weak link. The good news is that within a year, perhaps two, authentication will occur at the point of entry to the Internet, on your device or computer, most likely using fingerprint technology already in use by Apple, rather than identity being confirmed at every individual website you visit.

Offline olde north church

  • Hero Member
  • *****
  • Posts: 5,117
Re: White House goal: Kill the password
« Reply #5 on: February 16, 2015, 12:05:15 am »
I wonder which is worse, a couple of housewives in Boca Del Vista using "password" or some bureaucrat trying to make time with some bimbo in a bar outside Cleveland leaving his Uncle Sam issued laptop in the Tiki Lounge?
Why?  Well, because I'm a bastard, that's why.

Online DCPatriot

  • Hero Member
  • *****
  • Posts: 46,298
  • Gender: Male
  • "...and the winning number is...not yours!
Re: White House goal: Kill the password
« Reply #6 on: February 16, 2015, 12:31:41 am »
I never understood why Windows never had a feature where you could password protect a specified Word or Excel file.

Something sinister about that, when it's your own damned property.
"It aint what you don't know that kills you.  It's what you know that aint so!" ...Theodore Sturgeon

"Journalism is about covering the news.  With a pillow.  Until it stops moving."    - David Burge (Iowahawk)

"It was only a sunny smile, and little it cost in the giving, but like morning light it scattered the night and made the day worth living" F. Scott Fitzgerald

Oceander

  • Guest
Re: White House goal: Kill the password
« Reply #7 on: February 16, 2015, 02:54:29 am »
I never understood why Windows never had a feature where you could password protect a specified Word or Excel file.

Something sinister about that, when it's your own damned property.

You can password protect individual files.