Follow Slashdot stories on Twitter

 



Forgot your password?
typodupeerror

Submission + - In a Post-Password Era, Getting Rid of Passwords is the Problem (securityledger.com)

chicksdaddy writes: Large, tech savvy corporations recognize that the static password is dead. Still, they can't seem to stop using and relying on them. That's the conclusion of a panel discussion at the Akamai EDGE (https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fedge.akamai.com) event in Las Vegas last week, where executives at some of the U.S.’s leading corporations, agreed that the much maligned password won’t be abandoned any time soon, even as data breaches and follow-on attacks like automated “credential stuffing” make passwords more susceptible than ever to abuse, The Security Ledger reports. (https://ancillary-proxy.atarimworker.io?url=https%3A%2F%2Fsecurityledger.com%2F2017%2F10%2Fin-post-password-era-passwords-are-the-problem%2F)

“We reached the end of needing passwords maybe seven years ago, but we still use them,” said Steve Winterfeld, Director of Cybersecurity, at clothing retailer Nordstrom. “They’re still the primary layer of defense.” “It’s hard to kill them,” noted Shalini Mayor, who is a Senior Director at Visa Inc. “The question is what to replace them with.”

This, even though the cost of using passwords is high and getting higher, as sophisticated attacks attempt to compromise legitimate accounts using so-called “credential stuffing” techniques, which use automated password guessing attacks against web-based applications.

Large retailers and other vendors often perceive what Patrick Sullivan, the Director of Security Technology and Strategy at Akamai likened to a “disruption in the force” well before major breaches are disclosed as stolen credentials from those hacks are used to try to break into their own system. However, the sheer number of breaches make spotting the source of a particular leaked credential all but impossible.

Stronger and more reliable alternatives to passwords already exist, but the obstacles to using them are often prohibitive. Shalani said Visa is “looking at” biometric technologies like Apple’s TouchID as a tool for making payments securely. Such technologies – from fingerprint scans to facial and retinal scans – promise more secure and reliable factors than alphanumeric passwords, the executives agreed. But customers often resist the technologies or find them error prone or too difficult to use.

Comment A bit biased, but... Google's SRE (Score 1) 338

Google's Site Reliability Engineering was my favourite book of 2016.

Even without diving too deep into technical aspects (with the Load Balancing chapter being a good exception) there's plenty of good information around running large scale teams and systems. The concept of SRE is one of a kind and the details shared in the book help to understand how DevOps is not SRE and vice versa.

Last but not least such transparency is welcome and more big players should follow the example.

Comment Not really a suggestion, just sharing, really... (Score 1) 481

My first experience was with two servers only, so the obvious choice was to name them Beavis and Butthead. Then the network grew and we decided to go with planets (keeping good ol' Beavis and Butthead). After a while (a few years) the network grew again, and by that time, each location decided how to name their own servers. Oh.. beavis and butthead are still breathing!

Sony DRM and the New Digital Hole 184

expro writes "If the root kit scandal was not enough for Sony, Time Magazine reports that it is a delay in 'the release of copy-protection software required for the PS3's game and high-definition movie discs' giving Microsoft a serious advantage in the market place. Is there something Sony should be learning here about preoccupation copy control? With high definition writable media appearing already, will the price drop soon enough to help me overcome the real obstacle to backing up my exsisting commercial DVDs, cost of single media large enough to hold them that is playable in a player? Will the resulting new digital hole in copying existing DVD schemes to higher-density media replace the analog hole of VCRs in copying movies?"

Slashdot Top Deals

Documentation is like sex: when it is good, it is very, very good; and when it is bad, it is better than nothing. -- Dick Brandon

Working...