Skip to main content
Top

2023 | OriginalPaper | Chapter

5. Who Goes There?

Author : Carey Parker

Published in: Firewalls Don't Stop Dragons

Publisher: Apress

Activate our intelligent search to find suitable subject content or patents.

search-config
loading …

Abstract

We can’t go much further in this book without discussing passwords. I hate passwords. I hate them with a passion. And I know I’m not alone. But despite some promising new technology, I’m here to tell you that password-based authentication is still your most secure option for proving your identity today, if you use them correctly. By the time you finish this chapter, you’ll understand why.

Dont have a licence yet? Then find out more about our products and how to get one now:

Springer Professional "Wirtschaft+Technik"

Online-Abonnement

Mit Springer Professional "Wirtschaft+Technik" erhalten Sie Zugriff auf:

  • über 102.000 Bücher
  • über 537 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Maschinenbau + Werkstoffe
  • Versicherung + Risiko

Jetzt Wissensvorsprung sichern!

Springer Professional "Technik"

Online-Abonnement

Mit Springer Professional "Technik" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 390 Zeitschriften

aus folgenden Fachgebieten:

  • Automobil + Motoren
  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Elektrotechnik + Elektronik
  • Energie + Nachhaltigkeit
  • Maschinenbau + Werkstoffe




 

Jetzt Wissensvorsprung sichern!

Springer Professional "Wirtschaft"

Online-Abonnement

Mit Springer Professional "Wirtschaft" erhalten Sie Zugriff auf:

  • über 67.000 Bücher
  • über 340 Zeitschriften

aus folgenden Fachgebieten:

  • Bauwesen + Immobilien
  • Business IT + Informatik
  • Finance + Banking
  • Management + Führung
  • Marketing + Vertrieb
  • Versicherung + Risiko




Jetzt Wissensvorsprung sichern!

Footnotes
3
You can keep track of support for passkeys on your devices and major websites here: https://passkeys.dev/
 
4
This is from an annual report from SplashData (https://www.splashdata.com). Note that this is the list of all hacked passwords… that is, of all the passwords the bad guys were able to guess, these are the most popular.
 
5
Special thanks to Steve Gibson’s excellent website for these figures: https://www.grc.com/haystack.htm
 
6
If you want a truly unique and fun way to “roll” your dice, check out the official Firewalls Don’t Stop Dragons challenge coin! https://d20key.com/#/coin
 
7
Security people sometimes cheekily refer to these as “something you forget, something you lose, or something you cease to be.”
 
8
SIM = subscriber identity module. It’s what ties your account to your phone number and the smartphone itself.
 
9
Most people attribute this to a 2004 policy written for the National Institute of Standards and Technology by a guy named Bill Burr. He got it from a whitepaper from the 1980s! He’s since apologized for this, and NIST has removed this from their security recommendations.
 
10
If you’re interested in this level of privacy, I will have some recommendations at the end of the book.
 
11
For some really stupid reason, we have not settled on a simple login standard for websites. And apparently, one common issue with Bitwarden is that it doesn’t always recognize when you’re logging into a website for the first time. In those cases, you can explicitly add your website credentials using the plugin menu on your browser.
 
Metadata
Title
Who Goes There?
Author
Carey Parker
Copyright Year
2023
Publisher
Apress
DOI
https://doi.org/10.1007/978-1-4842-9036-1_5

Premium Partner