Тёмный

Passwords are Dead, Long live Passkeys! - Stephen Rees-Carter - NDC Security 2024 

NDC Conferences
Подписаться 194 тыс.
Просмотров 2,7 тыс.
50% 1

This talk was recorded at NDC Security in Oslo, Norway. #ndcsecurity #ndcconferences #security #developer #softwaredeveloper
Attend the next NDC conference near you:
ndcconferences.com
ndc-security.com/
Subscribe to our RU-vid channel and learn every day:
/‪@NDC‬
Follow our Social Media!
/ ndcconferences
/ ndc_conferences
/ ndc_conferences
Authentication is hard! Passwords are guessable, while SMS and app-based multi-factor authentication can be compromised. Even the promise of hardware tokens comes at a cost, being easy to lose and/or forget. Unfortunately, as developers, we're stuck trying to solve this difficult problem: how to make authentication work without putting our users at risk. Every option appears to have downsides... but there is hope!
Passkeys are a new authentication technology that uses cryptography within the web browser to securely identify and authenticate users, automatically syncing across devices, to entirely eliminate the need for passwords. It's like magic! We'll learn what they are, how they work, and why they are (virtually) unhackable. Your users will love a simplified login flow, and you'll stop worrying about account takeovers.

Наука

Опубликовано:

 

25 мар 2024

Поделиться:

Ссылка:

Скачать:

Готовим ссылку...

Добавить в:

Мой плейлист
Посмотреть позже
Комментарии : 11   
@computer9764
@computer9764 3 месяца назад
You forgot the critical reason that SMS-based multi-auth is argued against, which is that it, quite frequently, is used as the only factor.
@AldoInza
@AldoInza 3 месяца назад
And SMS can be hijacked by employees of the phone companies, and lots of employees in the phone companies have that ability,.
@urvhalt
@urvhalt 3 месяца назад
So, we can tag thoose keys with names that tell what they are for, and store them all behind one bad password?
@urvhalt
@urvhalt 3 месяца назад
... but 2fa for that password of course. Yes, more convenient comapred to a hardcopy with a list of complex passwords.
@lindhe
@lindhe 3 месяца назад
It's possible to memorize one good password. The problem is that it's not possible to memorize 1000 unique strong passwords, and that's why we need a system for it.
@putnam120
@putnam120 3 месяца назад
Yeah gonna pass on trusting Microsoft with credentials given recent events
@lindhe
@lindhe 3 месяца назад
So sync it with 1Password or something instead?
@EpKjelltzer
@EpKjelltzer 3 месяца назад
Even BitWarden already supports creating, storing, and syncing passkeys. No need to trust big tech with this.
@pepeshopping
@pepeshopping 3 месяца назад
Flying half a world away for that? Riiiiiigt, because a bunch of 0s and 1s are hard to log, read, steal. If a human made it, another human can break it! I RESPECT a lot more the people that understand that computer security, LIKE physical security, is an illusion! If somebody really wants in, they will!
@lindhe
@lindhe 3 месяца назад
Yes, they are infact hard to log and steal.
@capability-snob
@capability-snob 3 месяца назад
Current operating systems and browsers are not great at keeping your secrets, it's true. This is a solvable problem, though.
Далее
Уловки Такси: не ведись!
0:43
Просмотров 285 тыс.
Let’s kill the password - Timothy Jacobs
36:14
Passkeys And Disaster Planning
14:03
Просмотров 9 тыс.
5 Design Patterns That Are ACTUALLY Used By Developers
9:27
When Cybercriminals with Good OpSec Attack
49:01
Просмотров 179 тыс.
HTTPS, SSL, TLS & Certificate Authority Explained
43:29
Здесь упор в процессор
18:02
Просмотров 346 тыс.
Собери ПК и Получи 10,000₽
1:00
Просмотров 2,7 млн