{"id":5475,"date":"2018-04-16T04:01:04","date_gmt":"2018-04-16T08:01:04","guid":{"rendered":"http:\/\/lifeinsurance-orleans.ca\/Life-Insurance-Blog\/?guid=dd07401b1be2addd42cb6a453016be5c"},"modified":"2018-04-16T04:01:04","modified_gmt":"2018-04-16T08:01:04","slug":"death-of-the-password-new-web-standard-trades-passcodes-for-biometrics","status":"publish","type":"post","link":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/2018\/04\/16\/death-of-the-password-new-web-standard-trades-passcodes-for-biometrics\/","title":{"rendered":"Death of the password? New web standard trades passcodes for biometrics"},"content":{"rendered":"<p>The death of the password could be upon us.<\/p>\n<p>A new security standard recently endorsed by the World Wide Web Consortium has experts excited about the prospect of making logins &#8220;unphishable&#8221; and ending the vulnerabilities that currently exist because so many users have poor &#8220;password hygiene&#8221; and reuse the same one across countless websites.<\/p>\n<p>The Web Authentication (WebAuthn) standard developed collaboratively by members of the FIDO Alliance &#8212; which includes the likes of Amazon, Facebook, Google, Intel, Lenovo, Microsoft, PayPal, Samsung and Visa &#8212; allows web surfers to use biometrics such as fingerprints or facial scans instead of inputting a password. Plugging a compatible USB device into a computer can also be used to bypass password screens on participating websites.<\/p>\n<p>&#8220;I don&#8217;t think the password will be killed tomorrow, or even within the next three to six months, or even year,&#8221; says Joni Brennan, president of the non-profit Digital ID and Authentication Council of Canada.<\/p>\n<p>&#8220;But there&#8217;s a shift and a journey that needs to happen and to finally move past having so many passwords and ideally not having passwords at some point &#8212; this I think is a really key step.&#8221;<\/p>\n<p>Mozilla&#8217;s Firefox browser has already implemented the technology while Google and Microsoft have also committed to updating their browsers.<\/p>\n<p>Users who adopt the new standard will basically be upgrading to a level of security used for protecting state secrets, says Vancouver native John Bradley, standards architect for the security hardware company Yubico, a board member of the FIDO Alliance.<\/p>\n<p>&#8220;Essentially you&#8217;re moving people from being able to do remote attacks to phish you to actually having to break into your house and steal your phone &#8230; and extract your pin from you at gunpoint. It significantly raises the bar,&#8221; says Bradley, who predicts some popular websites may start offering the new type of login within a couple of months.<\/p>\n<p>He says security experts call the login method &#8220;unphishable&#8221; because there&#8217;s no indication yet that hackers could compromise it.<\/p>\n<p>&#8220;So people would have to move onto other social-engineering schemes,&#8221; he explains.<\/p>\n<p>&#8220;But there isn&#8217;t something you could tell someone over the phone if (a scammer) called you up&#8230; there isn&#8217;t anything the user can actually disclose to somebody else (to reveal their login), so it makes it very difficult for the attackers. I&#8217;m sure they&#8217;ll come up with some other scheme to keep security people in business, but this would cut off what&#8217;s becoming a major pain in the neck for people.&#8221;<\/p>\n<p>Bradley notes that users who choose to use biometrics as an unlocking mechanism needn&#8217;t worry about their fingerprints being handed over to websites they visit. Biometrics are not uploaded during the login process and are not stored on the user&#8217;s device.<\/p>\n<p>&#8220;All the biometrics are local to the device, so you&#8217;re not sending your fingerprint to the website &#8212; that would be a bad thing from a privacy perspective,&#8221; he says.<\/p>\n<p>Brennan expects some people might be nervous about using their biometrics routinely for logging in online and fear they&#8217;ll be misused. She admits it took her a while to warm to Apple&#8217;s Touch ID fingerprint technology on its devices.<\/p>\n<p>&#8220;Over time I saw there was a convenience there and I was able to learn what was happening,&#8221; she says.<\/p>\n<p>&#8220;That was a personal decision.&#8221;<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The death of the password could be upon us. A new security standard recently endorsed by the World Wide Web Consortium has experts excited about the prospect of making logins &ldquo;unphishable&rdquo; and ending the vulnerabilities that currently exist because so many users have poor &ldquo;password hygiene&rdquo; and reuse the same one across countless websites. The [&hellip;]<\/p>\n","protected":false},"author":578,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[],"tags":[],"jetpack_featured_media_url":"","_links":{"self":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/5475"}],"collection":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/users\/578"}],"replies":[{"embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/comments?post=5475"}],"version-history":[{"count":1,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/5475\/revisions"}],"predecessor-version":[{"id":5477,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/posts\/5475\/revisions\/5477"}],"wp:attachment":[{"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/media?parent=5475"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/categories?post=5475"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/blog.lifeinsurance-orleans.ca\/index.php\/wp-json\/wp\/v2\/tags?post=5475"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}