Stronger Identity Protection via Mobile Devices
Date: July 2013
Publication: Passwords13 Las Vegas
Source: Currently no known Internet copy of paper.
Abstract or Summary:
In this talk we will show how a mobile phone can promote password security by relieving users from the need to type in long and complex passwords.
The need for stronger passwords and multi-factor authentication in today's digital environment is widely recognized. There are even special hardware devices offered on the market to facilitate stronger authentication: "password typing" tokens, tokens designed to act as a second authentication factor, etc. Such solutions are often limited, e.g., they can "type" only one password, limited to certain systems, or require significant backend integration effort from software developers.
In this talk we will re-visit the idea of using mobile phones in a multi-factor authentication. Unlike previous approaches, we won't limit ourselves with sending codes over SMS or OTP generation on the device. Instead, we will turn an Android phone into a "password typing" device that acts similarly to YubiKey but is not constrained to a single password. We will also show how on-device password managers can be integrated with this feature to provide a very convenient and familiar UX.
PasswordResearch.com Note: Video of presentation: https://www.youtube.com/watch?v=FRVkHlEKSv0
Do you have additional information to contribute regarding this research paper? If so, please email firstname.lastname@example.org with the details.