Google Faculty Summit 2010
July 29, 2010
ABSTRACT
Presented by Dirk Balfanz.
Passwords can leak through a variety of channels: users tend to re-use passwords across web sites, get phished, attacked by malware, etc. Most would agree that password-based authentication is not very secure. So why do we still live in an online world dominated by passwords? In my talk I will point out some of the challenges we face when moving away from password-based authentication. I will explain what roles OpenID and OAuth play in this move, security issues we faced in the past with these protocols, and where we're headed in the world of "Internet Identity."
help i go this phone from this lady and the phone was fine. until i put the password lock screen and i tried my pattern but wouldnt work. now it says that ive tried to many times and is asking for my google account, but the problem is that i never put my google account in, now my phone is on a lock and i cant access anything from it. what do i do
hannahsbibfan100 11 months ago
@R1e2v3oOf I can only shed a little light. Yes you can be a service provider. There are open source implementations, however, google (and most other big sites) only want to be a provider and not a consumer (allow you to use some other site as your provider), so it is almost useless right now to be your own provider.
You are right, you are not anonymous to the provider you choose.
justspewing 1 year ago 2
Does anyone know if Google will be an openid consumer. If not, then Google is NOT embracing openid.
justspewing 1 year ago
Honestly I don't know much about this ...
24:57 Different personas ... but you can't be anonymous at your service provider if you're using biometric authentication or hardware ids and so forth, can you?
Could I be a service provider?
It might be hard to solve the passwort anti-pattern Problem AND the pfishing problem at the same time.
R1e2v3oOf 1 year ago