• chevron_right

      Google announces new algorithm that makes FIDO encryption safe from quantum computers

      news.movim.eu / ArsTechnica · Friday, 18 August, 2023 - 20:01

    Google announces new algorithm that makes FIDO encryption safe from quantum computers

    Enlarge (credit: Getty Images)

    The FIDO2 industry standard adopted five years ago provides the most secure known way to log in to websites because it doesn’t rely on passwords and has the most secure form of  built-in two-factor authentication. Like many existing security schemes today, though, FIDO faces an ominous if distant threat from quantum computing, which one day will cause the currently rock-solid cryptography the standard uses to completely crumble.

    Over the past decade, mathematicians and engineers have scrambled to head off this cryptopocalypse with the advent of PQC—short for post-quantum cryptography—a class of encryption that uses algorithms resistant to quantum-computing attacks. This week, researchers from Google announced the release of the first implementation of quantum-resistant encryption for use in the type of security keys that are the basic building blocks of FIDO2.

    The best known implementation of FIDO2 is the passwordless form of authentication: passkeys. So far, there are no known ways passkeys can be defeated in credential phishing attacks. Dozens of sites and services now allow users to log in using passkeys, which use cryptographic keys stored in security keys, smartphones, and other devices.

    Read 7 remaining paragraphs | Comments

    • chevron_right

      This week’s Reddit breach shows company’s security is (still) woefully inadequate

      news.movim.eu / ArsTechnica · Friday, 10 February, 2023 - 22:01

    This week’s Reddit breach shows company’s security is (still) woefully inadequate

    Enlarge (credit: Getty Images)

    Popular discussion website Reddit proved this week that its security still isn’t up to snuff when it disclosed yet another security breach that was the result of an attack that successfully phished an employee’s login credentials.

    In a post published Thursday, Reddit Chief Technical Officer Chris "KeyserSosa" Slowe said that after the breach of the employee account, the attacker accessed source code, internal documents, internal dashboards, business systems, and contact details for hundreds of Reddit employees. An investigation into the breach over the past few days, Slowe said, hasn’t turned up any evidence that the company’s primary production systems or that user password data was accessed.

    “On late (PST) February 5, 2023, we became aware of a sophisticated phishing campaign that targeted Reddit employees,” Slowe wrote. “As in most phishing campaigns, the attacker sent out plausible-sounding prompts pointing employees to a website that cloned the behavior of our intranet gateway, in an attempt to steal credentials and second-factor tokens.”

    Read 14 remaining paragraphs | Comments

    • chevron_right

      Passkeys—Microsoft, Apple, and Google’s password killer—are finally here

      news.movim.eu / ArsTechnica · Tuesday, 25 October, 2022 - 13:25 · 1 minute

    Passkeys—Microsoft, Apple, and Google’s password killer—are finally here

    Enlarge (credit: Gertty Images)

    For years, Big Tech has insisted that the death of the password is right around the corner. For years, those assurances have been little more than empty promises. The password alternatives—such as pushes, OAUTH single-sign ons, and trusted platform modules—introduced as many usability and security problems as they solved. But now, we’re finally on the cusp of a password alternative that’s actually going to work.

    The new alternative is known as passkeys. Generically, passkeys refer to various schemes for storing authenticating information in hardware, a concept that has existed for more than a decade. What’s different now is that Microsoft, Apple, Google, and a consortium of other companies have unified around a single passkey standard shepherded by the FIDO Alliance. Not only are passkeys easier for most people to use than passwords; they are also completely resistant to credential phishing, credential stuffing, and similar account takeover attacks.

    On Monday, PayPal said US-based users would soon have the option of logging in using FIDO-based passkeys, joining Kayak, eBay, Best Buy, CardPointers, and WordPress as online services that will offer the password alternative. In recent months, Microsoft, Apple, and Google have all updated their operating systems and apps to enable passkeys. Passkey support is still spotty. Passkeys stored on iOS or macOS will work on Windows, for instance, but the reverse isn’t yet available. In the coming months, all of that should be ironed out, though.

    Read 15 remaining paragraphs | Comments

    • chevron_right

      Google enclenche son plan anti-mot de passe

      news.movim.eu / Numerama · Thursday, 13 October, 2022 - 10:00

    mot de passe

    Google commence à mettre en place les bases techniques dans Android et Chrome qui vont lui permettre d'appliquer sa stratégie pour sortir des mots de passe. D'autres, comme Apple et Microsoft, suivent le même chemin. [Lire la suite]

    Abonnez-vous aux newsletters Numerama pour recevoir l’essentiel de l’actualité https://www.numerama.com/newsletter/

    • chevron_right

      Apple, Google et Microsoft s’allient pour tuer vos mots de passe plus vite

      news.movim.eu / Numerama · Thursday, 5 May, 2022 - 14:30

    Pour accélérer l'émergence d'un monde sans mot de passe, Apple, Google et Microsoft décident d'agir de concert. De nouvelles fonctionnalités pour améliorer l'interopérabilité et la convivialité des dispositifs d'authentification vont arriver. [Lire la suite]

    Abonnez-vous aux newsletters Numerama pour recevoir l’essentiel de l’actualité https://www.numerama.com/newsletter/