Upgrade to Pro — share decks privately, control downloads, hide ads and more …

User Identity - NSConference 2013

User Identity - NSConference 2013

A public talk given at NSConference in Leicester on Wednesday, 06 March 2013. You can find the video of the talk at https://www.youtube.com/watch?v=osdDy7X0n78

An iOS implementation of residence based authentication is available at https://github.com/verylargebox/VLBUserIdentity

A video of the above implementation also available at http://www.youtube.com/watch?v=_9Zu-AHhXyo

Markos Charatzas

March 06, 2013
Tweet

More Decks by Markos Charatzas

Other Decks in Technology

Transcript

  1. User Identity 1. the use of a password. 2. the

    lie. 3. forced upon. 4. the joke. 5. the proposal. Wednesday, 6 March 13
  2. password policy “a set of rules designed to enhance computer

    security by encouraging users to employ strong passwords and use them properly.” 1 1. http://en.wikipedia.org/wiki/Password_policy Wednesday, 6 March 13
  3. fixed size of 5 numbers (no reuse) cursed those born

    in single digit days, single digit months Wednesday, 6 March 13
  4. consonant, vowel, consonant, consonant, vowel, consonant, number, number “An Environ

    password”1 1. http://en.wikipedia.org/wiki/Password_policy Wednesday, 6 March 13
  5. “Furthermore, for extra security reasons, a password change is obligatory

    by the system every two months.”1 just in time you memorised it 1. http://goo.gl/szQPs National Bank of Greece Wednesday, 6 March 13
  6. “What is your oldest cousin's first and last name?” so

    good, they made a website1 1. http://goodsecurityquestions.com/examples.htm Wednesday, 6 March 13
  7. Common password practice1 • never share a computer account •

    never use the same password for more than one account • never tell a password to anyone, including people who claim to be from customer service or security • never write down a password • never communicate a password by telephone, e-mail or instant messaging • being careful to log off before leaving a computer unattended • changing passwords whenever there is suspicion they may have been compromised • operating system password and application passwords are different • password should be alpha-numeric 1. http://en.wikipedia.org/wiki/Password_policy Wednesday, 6 March 13
  8. “the greatest lie about security” dear user, using a password

    keeps you secure, honestly. Wednesday, 6 March 13
  9. please state your name and by the way, I need

    you to think of a password Wednesday, 6 March 13
  10. so why do I need a password again? you are

    using it wrong Wednesday, 6 March 13