Click here to Skip to main content
15,886,258 members

The Insider News

   

The Insider News is for breaking IT and Software development news. Post your news, your alerts and your inside scoops. This is an IT news-only forum - all off-topic, non-news posts will be removed. If you wish to ask a programming question please post it here.

Get The Daily Insider direct to your mailbox every day. Subscribe now!

 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 2:55
professionalZurdoDev6-May-20 2:55 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 3:26
mveRichard Deeming6-May-20 3:26 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:32
professionalZurdoDev6-May-20 3:32 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 3:49
mveRichard Deeming6-May-20 3:49 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:54
professionalZurdoDev6-May-20 3:54 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 10:15
kalberts6-May-20 10:15 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming6-May-20 23:21
mveRichard Deeming6-May-20 23:21 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts6-May-20 23:49
kalberts6-May-20 23:49 
There are other aspects to it as well, e.g. your dependency on an internet connection to the keystore. You may have keys for resources that do not necessarily have the same acessibility as you keystore, or rather the other way around: Your keystore access may be more limited. Say that you are running a lot of servers within a local network, requiring login. Then an excavator rips the fiber cable connecting you to the external internet. You can no longer authenticate yourself to local services.

If all your passwords can be accessed by specifying a single password - that to the keystore - then it really doesn't make much difference that after the keystore is opened you can select any key to get in anywhere. Only one key is needed for arbitrary access: That to the keystore. You get an illusion of security much higher than reality.

The fundamental problem is that we pass keys around for login. For thirty years we have had solutions like Kerberos[^], where no passwors need to be sent across the network. For some reason, it never caught on, as it really could deserve.

(Every time I mention Kerberos to someone who actually recognizes the name, I get an explanation of its failure to be accepted based on some nitty-gritty little detail that keeps if from being 100% perfect. So instead of getting someting that would be 99% perfect, we use something that is extremely far from any perfection, and we have to remedy the most serious problems with such tools as keystores. From a system architeture point of view, I find it disgusting Smile | :) )
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Richard Deeming7-May-20 0:27
mveRichard Deeming7-May-20 0:27 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
kalberts7-May-20 0:53
kalberts7-May-20 0:53 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
F-ES Sitecore6-May-20 2:33
professionalF-ES Sitecore6-May-20 2:33 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
ZurdoDev6-May-20 3:33
professionalZurdoDev6-May-20 3:33 
GeneralRe: We beg, implore and beseech thee. Stop reusing the same damn password everywhere Pin
Daniel Pfeffer6-May-20 4:31
professionalDaniel Pfeffer6-May-20 4:31 
NewsFree Windows 10, Linux, macOS open-source graphics editor: Inkscape 1.0 is out Pin
Kent Sharkey5-May-20 11:30
staffKent Sharkey5-May-20 11:30 
GeneralRe: Free Windows 10, Linux, macOS open-source graphics editor: Inkscape 1.0 is out Pin
Rob Grainger6-May-20 23:08
Rob Grainger6-May-20 23:08 
NewsNASA confirms work on a Tom Cruise movie to be shot aboard the International Space Station Pin
Kent Sharkey5-May-20 11:30
staffKent Sharkey5-May-20 11:30 
GeneralRe: NASA confirms work on a Tom Cruise movie to be shot aboard the International Space Station Pin
markrlondon6-May-20 17:02
markrlondon6-May-20 17:02 
NewsCut-and-paste enters era of augmented reality Pin
Kent Sharkey5-May-20 9:15
staffKent Sharkey5-May-20 9:15 
NewsStanford researchers demonstrate a new method to transmit electricity wirelessly Pin
Kent Sharkey5-May-20 8:00
staffKent Sharkey5-May-20 8:00 
NewsGoDaddy reports data breach involving SSH access on hosting accounts Pin
Kent Sharkey5-May-20 8:00
staffKent Sharkey5-May-20 8:00 
NewsSoftware flaws often first reported on social media networks, researchers find Pin
Kent Sharkey4-May-20 11:30
staffKent Sharkey4-May-20 11:30 
GeneralRe: Software flaws often first reported on social media networks, researchers find Pin
Nelek4-May-20 22:43
protectorNelek4-May-20 22:43 
NewsMillions of remote desktop accounts attacked every week Pin
Kent Sharkey4-May-20 11:30
staffKent Sharkey4-May-20 11:30 
NewsControversial sale of .org web domain blocked Pin
Kent Sharkey4-May-20 11:30
staffKent Sharkey4-May-20 11:30 
NewsJetBrains Academy for learning code launches for free during COVID-19 pandemic Pin
Kent Sharkey4-May-20 9:00
staffKent Sharkey4-May-20 9:00 

General General    News News    Suggestion Suggestion    Question Question    Bug Bug    Answer Answer    Joke Joke    Praise Praise    Rant Rant    Admin Admin   

Use Ctrl+Left/Right to switch messages, Ctrl+Up/Down to switch threads, Ctrl+Shift+Left/Right to switch pages.