Data Storage Today

CIO Today Network Sites:   Top Tech News  |   CIO Today   |   Mobile Tech Today   |   Data Storage Today
News & Information for Data Storage Professionals
Commvault Simpana® 10
Protect, manage, access, and
realize the untapped value of data.

www.commvault.com
Tuesday, May 21st 
Stingray Traffic Manager on Amazon Web Services
Home
Data Centers
Storage Solutions
Storage Networks
Data Storage Issues
Data Security
Enterprise I.T.
DST Press Releases
 
Free Newsletters
Top CIO News
 
Mobile Tech Today
 

Advertisement

Data Security

In Google's Future, You May Log in with Your Ring

In Google
January 21, 2013 2:05PM

Bookmark and Share
A smartphone or "smartcard-embedded finger ring," wrote the Google authors, could "authorize a new computer via a tap on the computer, even in situations in which your phone might be without cellular connectivity." The Google authors call for the "primary authenticator" to be a piece of hardware, but envision a second authentication might also be involved.

Stingray Traffic Manager on Amazon Web Services - Deliver Fast, Secure, and Available Applications. Looking to combine advanced load balancing with the application delivery features on Amazon Web Services? This process will allow you to run Stingray™ software on Amazon AWS using an Amazon account of your choice. Click here to view the complete range of Riverbed Stingray products on AWS.

Just as we Google people now, will we ring ourselves into our e-mail account in the near future? That's a possibility outlined in a new Google research paper, which proposes such options as a ring that taps on a computer Relevant Products/Services to logon.

The paper, by Google Vice President of Security Eric Grosse and Engineer Mayank Upadhyay, is scheduled for publication this month in IEEE Security & Privacy Magazine. It argues for post-password computing because, according to the authors, "passwords and simple bearer tokens such as cookies are no longer sufficient to keep users safe."

It's hard to argue with that conclusion. While individual account hackings do not normally make news, most users have such experiences as someone breaking into their e-mail account, or receiving a notice about a security breach from their credit card company. And the news is regularly populated with reports of companies whose confidential user information has been stolen, with the pilfered accounts often numbering in the thousands or millions.

'Tap to Logon'

To address this situation, Google proposes a variety of physical logon devices, such as utilizing the small Yubico cryptographic card. It can be inserted into a USB port, and a modified Google Chrome browser can accept such a login without a separate software Relevant Products/Services download. The Yubico card first needs to be registered, after which it's good to go.

While external, keychain-held physical devices that function as a second factor are not uncommon in some corporate environments, they are not widely used by consumers or many businesses, at least in part because of the convenience factor and the need for IT support. Google is attempting to circumvent both obstacles by suggesting that a ring or the ubiquitous smartphone could have Yubico-like capabilities built-in, along with a "tap to logon" capability -- not unlike the "tap to buy" capability of near field communication (NFC)-equipped smartphones.

In a recent story here, "Will Near Field Communication Change the World?", author Ira Brodsky outlined the change wave being driven by NFC, the security advantages, and a coming world where tap-to-do is a common activity. He called NFC a "wireless Relevant Products/Services game changer" that can only operate in close physical proximity to the receiver.

Independent Protocol

A smartphone or "smartcard-embedded finger ring," wrote the Google authors, could "authorize a new computer via a tap on the computer, even in situations in which your phone might be without cellular connectivity." The authors envision that a second factor of authentication, including an on-screen one, might also be involved to ensure against a break-in if the physical device is stolen or lost, but they call for the "primary authenticator" to be a piece of hardware.

To support this vision, Google says it has developed a device- and vendor-independent protocol that uses a Web browser to support device-based authentication.

Google already offers two-step authentication to its users, with a one-time password sent to your smartphone to be entered along with your regular login. Other sites, such as Dropbox or Blizzard, also offer two-factor authentication schemes, but the weakness is that second-factor codes could be susceptible to fake Web sites and phishing attempts. Another possible possible approach is reflected in a recent rumor that the next Apple iPhone will provide a different kind of physical authentication -- a built-in fingerprint sensor.

Based on your interest in this article, here's something that may be of interest to you also:

Recommended Reading: Search & Destroy: Why You Can't Trust Google Inc. Synopsis: This is the other side of the Google story. In Search & Destroy, Google expert Scott Cleland, shows that the world's most powerful company is not who it pretends to be. Google pretends to be a harmless lamb, but chose a full-size model of a Tyrannosaurus Rex as its mascot. Beware the T-Rex in sheep's clothing.

Tell Us What You Think
Comment:

Name:

Advertisement



 Data Security
1. China Hackers Resume U.S. Attacks
2. Financial Times Latest Hacking Target
3. Hackers Find Smartphones Useful
4. Investors Funding Cyberwarfare
5. Cyber-Experts Impressed with Heist


advertisement


 Most Popular Articles
1. Half of Companies To Mandate BYOD by 2017, Gartner Says
2. Best of Interop Award Winners Announced
3. Novell Filr Offers IT-Friendly Dropbox Alternative
4. BitTorrent Offers Alpha of P2P File-Syncing App
5. 75% of Breaches Financially Motivated, 20% Are Espionage

Have an informed opinion on this story?
Send a Letter to the Editor.
We want to know what you think.
Send us your Feedback.

 Related Topics  Latest News & Special Reports

  China Hackers Resume U.S. Attacks
  Cyberattacks Could Help Syrian Raids
  Financial Times Latest Hacking Target
  HP and SAP Team on HANA Database
  Cloud Computing Gains Another Rival

 Technology Marketplace

BYOD & MDM
Build a business case for a BYOD program.
 
CRM Systems
Free Download: Understanding the Voice of the Customer
 
Cloud & Virtualization
Brocade technologies help enable the full benefits of virtualization.
Riverbed Stingray Traffic Manager on Amazon Web Services
 
Contact Centers
Unlock the potential in your people with Microsoft Dynamics
 
Customer Data
Free Download: Understanding the Voice of the Customer
 
Customer Service
Unlock the potential in your people with Microsoft Dynamics
 
Data Security
Simpana® 10 software: an exponential leap forward
 
Data Storage
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software
Simpana® 10 software: an exponential leap forward
 
Mobile Apps
Build great mobile apps that drive engagement.
 
Network Security
Brocade makes it easier to deploy, manage, and scale networks.
 
Enterprise Software Spotlight

Should Enterprises Skip Over Windows 8?
Because of the interface changes and compatibility issues, most businesses will not adopt Windows 8 as their standard, but must be prepared to meet employee BYOD demand for it, Forrester Research says.

HP and SAP Team To Advance HANA Database Technology
The two tech leaders are working on a system that SAP says could fundamentally change the database market. HANA is SAP's technology that keeps data in-memory, for super fast processing.

Revlon Saving Millions with Microsoft Dynamics
The cosmetics giant is reporting millions of dollars in savings thanks to consolidating its enterprise resource planning by using Microsoft Dynamics ERP. Revlon CIO David Giambruno recently shared his story.

Advertisement
Navigation
Data Storage Today
Home/Top News | Data Centers | Storage Solutions | Storage Networks | Data Storage Issues | Data Security | Enterprise I.T.
DST Press Releases
Also visit these Enterprise Technology Sites
Top Tech News | CIO Today | Mobile Tech Today | Data Storage Today

Services:
FreeNewsFeed | Free Newsletters | XML/RSS Feed

About CIO Today Network | How To Contact Us | Article Reprints | Services for PR Pros (In partnership with NewsFactor) | Top Tech Wire | How To Advertise

Privacy Policy | Terms of Service
© Copyright 2000-2013 Data Storage Today. All rights reserved. Article rating technology by Blogowogo. Member of Accuserve Ad Network.