death to passwords

88

Upload: cristiano-betta

Post on 02-Jul-2015

1.795 views

Category:

Technology


1 download

DESCRIPTION

Talk given at DroidCon NL

TRANSCRIPT

Page 1: Death to Passwords
Page 2: Death to Passwords

Death to Passwords

Page 3: Death to Passwords

Death to Passwords

Cristiano Betta Developer Advocate

Page 4: Death to Passwords

Death to Passwords

Cristiano Betta Developer Advocate

Page 5: Death to Passwords

Death to Passwords

Cristiano Betta Developer Advocate @cbetta | @braintree_dev

Page 6: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

WHERE I LIVE

Page 7: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

WHERE I USED TO LIVE

Page 8: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 9: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

That’s me

Page 10: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 11: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 12: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 13: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

>Death to Passwords_

Page 14: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 15: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 16: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

>The 3 key problems_

Page 17: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

The top 1000 most used passwords of 2012

wiki.skullsecurity.org/Passwords

Page 18: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

The top 1000 most leaked passwords of 2012

wiki.skullsecurity.org/Passwords

Page 19: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

4.7% OF ALL LEAKED PASSWORDS ARE

Page 20: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

4.7% OF ALL LEAKED PASSWORDS ARE PASSWORD

Page 21: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 22: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

8.5% OF ALL LEAKED PASSWORDS ARE

Page 23: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

8.5% OF ALL LEAKED PASSWORDS ARE PASSWORD or 123456

Page 24: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

4.7% OF ALL LEAKED PASSWORDS ARE

Page 25: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

4.7% OF ALL LEAKED PASSWORDS ARE PASSWORD or 123456 or 12345678

Page 26: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

... and it doesn’t even stop there 14% have a password from the top 10 40% have a password from the top 100 79% have a password from the top 500 91% have a password from the top 1000

Page 27: Death to Passwords

Braintree_Dev. @cbetta | @braintree_devabstrusegoose.com/296

Page 28: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

A brief analysis of the situation in 2013cbsn.ws/1siTPGH

Page 29: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

1. 123456 2. password 3. 12345678 4. qwerty 5. abc123 6. 123456789 7. 111111 8. 1234567 9. iloveyou 10. adobe123

11. 123123 12. admin 13. 1234567890 14. letmein 15. photoshop 16. 1234 17. monkey 18. shadow 19. sunshine 20. 12345

Page 30: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

1. 123456 up 1 2. password down 1 3. 12345678 4. qwerty up 1 5. abc123 down 1 6. 123456789 new 7. 111111 up 2 8. 1234567 up 5 9. iloveyou up 2 10. adobe123 new

11. 123123 up 5 12. admin new 13. 1234567890 new 14. letmein down 7 15. photoshop new 16. 1234 new 17. monkey down 11 18. shadow 19. sunshine down 5 20. 12345 new

Page 31: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

11. 123123 up 5 12. admin new 13. 1234567890 new 14. letmein down 7 15. photoshop new 16. 1234 new 17. monkey down 11 18. shadow 19. sunshine down 5 20. 12345 new

1. 123456 up 1 2. password down 1 3. 12345678 4. qwerty up 1 5. abc123 down 1 6. 123456789 new 7. 111111 up 2 8. 1234567 up 5 9. iloveyou up 2 10. adobe123 new

Page 32: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

11. 123123 up 5 12. admin new 13. 1234567890 new 14. letmein down 7 15. photoshop new 16. 1234 new 17. monkey down 11 18. shadow 19. sunshine down 5 20. 12345 new

1. 123456 up 1 2. password down 1 3. 12345678 4. qwerty up 1 5. abc123 down 1 6. 123456789 new 7. 111111 up 2 8. 1234567 up 5 9. iloveyou up 2 10. adobe123 new

Page 33: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

11. 123123 up 5 12. admin new 13. 1234567890 new 14. letmein down 7 15. photoshop new 16. 1234 new 17. monkey down 11 18. shadow 19. sunshine down 5 20. 12345 new

1. 123456 up 1 2. password down 1 3. 12345678 4. qwerty up 1 5. abc123 down 1 6. 123456789 new 7. 111111 up 2 8. 1234567 up 5 9. iloveyou up 2 10. adobe123 new

Page 34: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 35: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 36: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 37: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 38: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 39: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 40: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

“FAVOR SECURITY TOO MUCH OVER THE EXPERIENCE AND YOU’LL MAKE THE WEBSITE A PAIN TO USE.”smashingmagazine.com /2012/10/26/password-masking-hurt-signup-form

Page 41: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

vs

Page 42: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 43: Death to Passwords

Braintree_Dev. @SeraAndroid / @PayPalDev

People forget passwords…

45% admit to leaving a website instead of re-setting their password or answering security questions

- Blue Inc. 2011

Page 44: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Let’s admit it... Passwords really suck!

Page 45: Death to Passwords

Braintree_Dev. @SeraAndroid / @PayPalDev

People hate to register

Out of 657 surveyed users 66% think that social sign-in is a desirable alternative.

- Blue Inc. 2011

Page 46: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Let’s admit it...Passwords really, really suck!

Page 47: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

“Braintree Says Goodbye to Passwords With One Touch Payments for PayPal and Venmo, and Hello to Bitcoin”

braintreepayments.com /blog/goodbye-passwords-one-touch-hello-bitcoin

Page 48: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Merchant app

PayPal app

Merchant app

Page 49: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Merchant app

PayPal app

Merchant app

Page 50: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Merchant app

PayPal app

Merchant app

Page 51: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Merchant app

PayPal app

Merchant app

Page 52: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

> Continue? (Y/n) _

Page 53: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Multi-Factor Authenticationen.wikipedia.org /wiki/Multi-factor_authentication

Page 54: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

KNOWLEDGE FACTOR

Page 55: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

INHERENCE FACTOR

Page 56: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

POSSESSION FACTOR

Page 57: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

2-Factor Authenticationtwofactorauth.org

Page 58: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

twofactorauth.org

Page 59: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Passwordless Authenticationmedium.com /@ninjudd/passwords-are-obsolete-9ed56d483eb

Page 60: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 61: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 62: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 63: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 64: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 65: Death to Passwords

fidoalliance.org

Page 66: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 67: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 68: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 69: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 70: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 71: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

> Exit? (Y/n) _

Page 72: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Authorization & Authenticationstackoverflow.com /questions/6367865/is-there-a-difference-between-authentication-and-authorization

Page 73: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Google Facebook Twitter

Page 74: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 75: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 76: Death to Passwords
Page 77: Death to Passwords
Page 78: Death to Passwords
Page 79: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 80: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome

Page 81: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck

Page 82: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck• We need something you have, know and/or are

Page 83: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck• We need something you have, know and/or are

• Wearable tech opens up a new world of possibilities

Page 84: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck• We need something you have, know and/or are

• Wearable tech opens up a new world of possibilities

• Don’t re-invent the wheel

Page 85: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck• We need something you have, know and/or are

• Wearable tech opens up a new world of possibilities

• Don’t re-invent the wheel• FIDO

Page 86: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

• Passwords are awesome• But people+passwords suck• We need something you have, know and/or are

• Wearable tech opens up a new world of possibilities

• Don’t re-invent the wheel• FIDO• Third party auth

Page 87: Death to Passwords

Braintree_Dev. @cbetta | @braintree_dev

Page 88: Death to Passwords

THANK YOUCristiano Betta

Developer Advocate

@cbetta | @[email protected]