Last password standing

Last password standing

LastPass?reported a security incident on their blog?this week. How bad was it, really?

Let's start with the headlines:

LastPass?in their own words is a 'pioneer in cloud security technology. LastPass provides award-winning password and identity management solutions that are convenient, effortless, and easy to manage.'

This is the problem for all the companies claiming that their name is a synonym for security. The marketing departments have to instill the confidence in the minds of their customers that nothing, absolutely nothing can be more secure. Yet, their security people are daily praying 'please, not to be me, today'. They know how one mistake can lead to a security breach.

They have to be right every time. The hacker has to be right only once.

Was it the first security incident there? No, it wasn't. There have been 6 other (publicly disclosed)?incidents in the past. It is a tough business.

But this post is not?about Lastpass as a company.

This latest incident is a symptom of what's wrong with the computer industry: We are still using passwords!

The password is a cruel joke by developers imposed on the rest of humanity. It is the reflection of their laziness to come up with technology which is easy to use and secure at the same time.

One study?promoting the use of software?like Lastpass, suggested that people have about 100 passwords. I don't think it is an accurate number, as it was done by one of the makers of the password management software. But even if we go with 50% or even 25%, you still have this pile of nonsense you have to remember.

That's where the developers are trying to outdo each other. It’s no longer enough to have 6-character passwords. It has to be 8 and has to have lower and upper case and numbers and special characters.

Why stop at 8 when we can have a 10 or 12-character password and change it every 30 days? Also, you can't ever repeat it. Then others come up with the 'clever' technique to create a memorable password - take the name of your favorite pet, spell it backwards, replace o with 0, e with 3, n with _ and 1 with ! and add the last four digits from a prime number with 8 digits. It is that simple.

When you - as a stupid person - ask “Why do we have to use such complex passwords? The answer is - So it can resist the brute force attack, you dummy!”

Ok, then explain to me why my bank card has only a?4-digit PIN?to access my bank account!?!?!

Banks found out that 4 digits is the minimum number for security and maximum number for what most of their clientele can reliably remember.

Rather than building a system which can resist such attacks, developers make you suffer all. And companies like LastPass can justify its existence.

Of course the irony is that while you are required to create, memorize and use these monstrosities, the hackers go around all this masterful security and get improperly stored complex passwords directly. Like they did when they?harvested 1.2 billion usernames and passwords?around the Internet.

Yes, passwords had its time in history and that's where they belong. It is time to move on. There are vendors and companies who are building better systems, where they take time to think hard to make the systems secure and more user friendly at the same time.

I mentioned the demise of?Blackberry devices?the other day. Notably, the Blackberry was one of the first devices which you could unlock without a password. Today, your Apple devices can be used just looking at them or by using your fingerprint. Meanwhile, there are companies like?Plurilock?which provide real-time, continuous credential monitoring using your own movement patterns.

I hope that complex, secure passwords will be one pattern which will cease to exist. We have better things to do than memorizing passwords.

Steve Sponseller

Patent Strategist helping tech companies design patent strategies that create a competitive advantage, attract investors, and increase valuation | Author of Cracking the Patent Code | Tech Leader Talk podcast host

2 年

Think back on all of the technological breakthroughs and new systems in the past 10+ years - some huge innovations. But, password "protection" seems antiquated. Can't we get some innovation in this area too - it's important!

要查看或添加评论,请登录

Vaclav Vincalek的更多文章

  • AI Sand Castle?Trap

    AI Sand Castle?Trap

    This post will start as a very boring talk about science, but try to get through the first few lines, we will get into…

    12 条评论
  • Goodnight, Skype

    Goodnight, Skype

    And that wraps up the Skype journey. May 5th, 2025 will be the last time you’ll be able to use Skype.

    1 条评论
  • The House of?Alexa

    The House of?Alexa

    The wait is over. Amazon introduced Alexa+.

    1 条评论
  • Big Bada Boom, Christmas 2032?

    Big Bada Boom, Christmas 2032?

    There is a chance that Earth will get hit by an asteroid on Dec. 22, 2032.

    2 条评论
  • Robots. The next wave is coming

    Robots. The next wave is coming

    My dear reader, by now, you might be tired of reading another write up about AI. The promises of the imminent arrival…

    4 条评论
  • When the AI rubber hits the?road

    When the AI rubber hits the?road

    Large Language Models (LLMs) have stormed the front pages of mass media, thanks to OpenAI and its now famous ChatGPT…

    10 条评论
  • DeepSeek hysteria

    DeepSeek hysteria

    One of the advantages of writing a weekly newsletter is that you don’t have to react immediately to any breaking news…

    7 条评论
  • The pitfalls of AI?search

    The pitfalls of AI?search

    Before we resume our regular programming, I have to issue an apology to you, my dear reader. I have been misled and in…

    2 条评论
  • AI. In search of value, in search of?price

    AI. In search of value, in search of?price

    Now that we are on our way to spending billions of dollars on AI, the question of making at least some of the money…

  • The Face-AI-book

    The Face-AI-book

    I wanted to write something this week about the continuous moral decline of Facebook. But then I found something…

    1 条评论

社区洞察

其他会员也浏览了