Alert icon
We're changing our privacy policy. This stuff matters.  Learn more  Dismiss

2010 Google Faculty Summit: Defeating the Password Anti-Pattern with Open Standards

Loading...

Sign in or sign up now!
Alert icon
Upgrade to the latest Flash Player for improved playback performance. Upgrade now or more info.
2,264
Loading...
Alert icon
Sign in or sign up now!
Alert icon
There is no Interactive Transcript.

Uploaded by on Aug 3, 2010

Google Faculty Summit 2010
July 29, 2010

ABSTRACT

Presented by Dirk Balfanz.

Passwords can leak through a variety of channels: users tend to re-use passwords across web sites, get phished, attacked by malware, etc. Most would agree that password-based authentication is not very secure. So why do we still live in an online world dominated by passwords? In my talk I will point out some of the challenges we face when moving away from password-based authentication. I will explain what roles OpenID and OAuth play in this move, security issues we faced in the past with these protocols, and where we're headed in the world of "Internet Identity."

Category:

Science & Technology

Tags:

License:

Standard YouTube License

  • likes, 0 dislikes

Link to this comment:

Share to:
see all

All Comments (4)

Sign In or Sign Up now to post a comment!
  • help i go this phone from this lady and the phone was fine. until i put the password lock screen and i tried my pattern but wouldnt work. now it says that ive tried to many times and is asking for my google account, but the problem is that i never put my google account in, now my phone is on a lock and i cant access anything from it. what do i do

  • @R1e2v3oOf I can only shed a little light. Yes you can be a service provider. There are open source implementations, however, google (and most other big sites) only want to be a provider and not a consumer (allow you to use some other site as your provider), so it is almost useless right now to be your own provider.

    You are right, you are not anonymous to the provider you choose.

  • Does anyone know if Google will be an openid consumer. If not, then Google is NOT embracing openid.

  • Honestly I don't know much about this ...

    24:57 Different personas ... but you can't be anonymous at your service provider if you're using biometric authentication or hardware ids and so forth, can you?

    Could I be a service provider?

    It might be hard to solve the passwort anti-pattern Problem AND the pfishing problem at the same time.

Loading...

Alert icon
0 / 00Unsaved Playlist Return to active list
    1. Your queue is empty. Add videos to your queue using this button:
      or sign in to load a different list.
    Loading...Loading...Saving...
    • Clear all videos from this list
    • Learn more