Affichage des articles dont le libellé est passwords. Afficher tous les articles
Affichage des articles dont le libellé est passwords. Afficher tous les articles

lundi 6 juillet 2015

If you hate passwords as much as we do, you’ll love Google ATAP’s latest projects



project-abacus-you-are-your-password-phandroid


It’s another wonderful day of Google I/O and the developer conference is proving that there’s still more interesting developments outside of Android M. During a Google ATAP session, Regina Duggan took the stage to talk about what the special projects unit as been working on.


Project Abacus


One of the more interesting projects is something called Project Abacus. They’ve actually been conducting user trials and gathering data since last year. Everyone knows passwords suck (Duggan actually said this on stage) and Project Abacus looks to eliminate the hassle of typing out or remembering long passwords because simply put: humans aren’t good at this.


Because your smartphone knows more about you than you think, Project Abacus combines a variety of sensor data — how you walk, location patterns, how you talk, how you type — to verify that you are you. In other words, your device is the key to your authentication and it doesn’t even need fingerprint scanning hardware to pull it off.


project-abacus-password-types-phandroid


Project Abacus works passively in the background to continually authenticate you before a website or app or anything else asks you for your password. Based on a trust score, it can verify your identity and you’ll be logged in without having to type a single thing. Higher trust scores could be required from something like a banking app, while low ones for something like logging into a game. Should your device fall into the wrong hands, the trust score will drop and the user will be asked to input a password like the olden days.


Of course, the question on everyone’s mind is how secure Abacus is when compared to other methods of authentication. ATAP says that by combining all this sensor data, Abacus is more than 10 times more secure than traditional methods. We’ve seen enough movies to know that anyone can pop out your eyeball or cut off your fingers — wouldn’t it be great if you phone knew you were you?


Project Vault


project-vault-announcement-phandroid


Another interesting project to come out of Google ATAP’s session is something they’re calling Project Vault. ATAP says Vault is tiny, security dedicated computer squeezed into a micro SD card. It uses a suite of encryption primitives to act as a digital mobile safe for your most sensitive data, anything from chat conversations to files and everything in between.


Using a driver-free interface, Project Vault partitions a portion of an SD card to store data and works out of the box on a variety of platforms outside of Android (like full fledged Windows PCs). ATAP says that Vault more or less aimed at the enterprise market for now and like most things to come out of Google I/O, still in its early stages but will soon have an open source SDK for developers.





Plex has been hacked, so be sure to change your passwords



plex logo banner 1


Quick PSA this morning, folks: Plex, the multimedia server that lets you stream your digital content to most internet connected devices, had its servers compromised. The company fell victim to an attack that fell on their blog and forums server, which — if your Plex account is linked to it — exposes your account’s passwords (which is stored in a hashed and salted algorithm that’s tough to crack).


That’s comforting, but the company will still require you to change your password, and you’ll want to do it as soon as possible. Apparently they will only ask you to change your password if you’ve ever linked your Plex.tv account with your forum account, butt we’d change passwords even if you don’t fall under that category. Also consider changing your password for other services if you happen to use the same one (which you shouldn’t be doing, by the way).


Plex was clear to note that other sensitive customer information — such as your payment and billing information — exists on an entirely different server and hasn’t been compromised in any way. We sure hope so.


[Update]: Well, things are about to get interesting. We’ve uncovered a message from the malicious hacker left on the server. It was since removed by Plex, but a cached version of Plex’s website still shows the goods.


The culprit apparently wants ransom. It’s simple: someone forks over 9.5 bitcoins (about ,400) or all the data the hacker stole will be released for anyone to see. If it doesn’t happen by July 3rd, they’ll ask for another 5 bitcoins. And if no one comes through? They say they’ll simply release the data anyway, and alleges that “there will be no more Plex.tv.”


We’re not sure how strong that claims is as Plex’s forums and blog systems are supposedly on an entirely different server than the one they use for payments and infrastructure, so we’ll have to wait and see what happens either way.


The no-gooder also suggests they’ll remove individual data from the database as long as they pay, though we’d strongly advise against doing that. In the meantime, just be sure to change those passwords like Plex recommends and hope for the best.


[via Lifehacker]