Perimeter
9/16/2011
05:26 PM
Rob Enderle
Rob Enderle
Commentary
50%
50%

Intel Demonstrates Potential Password-Killers

Intel presented two possible ways it plans to make passwords obsolete

I've never been a fan of passwords. For some time we have known that trivial passwords can be remembered but are easily compromised, and folks who write down complex passwords make them easy to find and copy. In fact, way back in the 1980s while I was working security audits in IBM, we’d regularly argue that passwords were largely an ineffective way to secure anything that was truly sensitive -- and that was long before the Internet.

Well, Intel might have come up with something that is on the cusp of eliminating passwords and making those of us who buy the next generation of PCs and tablets far more secure.

We all carry cell phones, and an increasing number of us carry smartphones, so why don't we use a cell phone as a second factor to validate we are who we say we are? At its recent developer conference, this was actually a compelling demonstration by Intel and could be done with an app on a smartphone, a unique text message generating a one-time key, or even a clickable (on the cell phone) message that validated the person who was logging in also had the cell phone tied with the account.

With that one move, the user's password could be the number one or "password," and it would be far more secure than the cryptic mess we advise users to have today. But Intel didn't stop there: It showcased a BIOS-based technology that would allow a Web page to bypass the buffer and send an image directly to the graphics system on a registered PC. The demonstration entailed the use of a randomized virtual keypad where a PIN number would be entered. Anyone cloning the screen would only see a black box, and while he might see the cursor, he would have no idea what the cursor was pointing at and couldn’t repeat the PIN. This pretty much eliminates buffer attacks as a way to get access to this class of identification information.

Now if the PIN was also single-use and sent to the cell phone, the level of security that could be provided to the user would likely exceed significantly what most high security systems provide today and be consumer-friendly.

We’ve been trying -- largely unsuccessfully -- to kill off passwords for decades. Intel is one of the few firms with enough power to actually make this happen, and the technologies it showcased were compelling. Given how entrenched passwords are, I doubt we’ll see them go away before 2025, but Intel might make them redundant in two years. And that's good enough for me.

Rob Enderle is president and founder of The Enderle Group. Special to Dark Reading

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading Tech Digest, Dec. 19, 2014
Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-4632
Published: 2015-01-31
VMware vSphere Data Protection (VDP) 5.1, 5.5 before 5.5.9, and 5.8 before 5.8.1 does not properly verify X.509 certificates from vCenter Server SSL servers, which allows man-in-the-middle attackers to spoof servers, and bypass intended backup and restore access restrictions, via a crafted certifica...

CVE-2014-7287
Published: 2015-01-31
The key-management component in Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allows remote attackers to trigger unintended content in outbound e-mail messages via a crafted key UID value in an inbound e-mail message, as demonstrated by the outbound Subject header.

CVE-2014-7288
Published: 2015-01-31
Symantec PGP Universal Server and Encryption Management Server before 3.3.2 MP7 allow remote authenticated administrators to execute arbitrary shell commands via a crafted command line in a database-backup restore action.

CVE-2014-8266
Published: 2015-01-31
Multiple cross-site scripting (XSS) vulnerabilities in the note-creation page in QPR Portal 2014.1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) title or (2) body field.

CVE-2014-8267
Published: 2015-01-31
Cross-site scripting (XSS) vulnerability in QPR Portal 2014.1.1 and earlier allows remote attackers to inject arbitrary web script or HTML via the RID parameter.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
If you’re a security professional, you’ve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.