Tag Archives: authentication

Meta pays the price for storing hundreds of millions of passwords in plaintext

Getty Images reader comments 90 Officials in Ireland have fined Meta $101 million for storing hundreds of millions of user passwords in plaintext and making them broadly available to company employees. Meta disclosed the lapse in early 2019. The company said that apps for connecting to various Meta-owned social networks had logged user passwords in… Read More »

NIST proposes barring some of the most nonsensical password rules

Getty Images reader comments 156 The National Institute of Standards and Technology (NIST), the federal body that sets technology standards for governmental agencies, standards organizations, and private companies, has proposed barring some of the most vexing and nonsensical password requirements. Chief among them: mandatory resets, required or restricted use of certain characters, and the use… Read More »

SSH protects the world’s most sensitive networks. It just got a lot weaker

Enlarge / Terrapin is coming for your data. Aurich Lawson | Getty Images reader comments 65 Sometime around the start of 1995, an unknown person planted a password sniffer on the network backbone of Finland’s Helsinki University of Technology (now known as Aalto University). Once in place, this piece of dedicated hardware surreptitiously inhaled thousands… Read More »

Passkeys may not be for you, but they are safe and easy—here’s why

Aurich Lawson | Getty Images reader comments 121 with My recent feature on passkeys attracted significant interest, and a number of the 1,100-plus comments raised questions about how the passkey system actually works and if it can be trusted. In response, I’ve put together this list of frequently asked questions to dispel a few myths… Read More »

Google passkeys are a no-brainer. You’ve turned them on, right?

Aurich Lawson | Getty Images reader comments 389 with By now, you’ve likely heard that passwordless Google accounts have finally arrived. The replacement for passwords is known as “passkeys.” There are many misconceptions about passkeys, both in terms of their usability and the security and privacy benefits they offer compared with current authentication methods. That’s… Read More »

Passkeys—Microsoft, Apple, and Google’s password killer—are finally here

Gertty Images reader comments 159 with 93 posters participating, including story author Share this story For years, Big Tech has insisted that the death of the password is right around the corner. For years, those assurances have been little more than empty promises. The password alternatives—such as pushes, OAUTH single-sign ons, and trusted platform modules—introduced… Read More »

How Apple, Google, and Microsoft will kill passwords and phishing in one stroke

Getty Images reader comments 186 with 108 posters participating, including story author Share this story For more than a decade, we’ve been promised that a world without passwords is just around the corner, and yet year after year, this security nirvana proves out of reach. Now, for the first time, a workable form of passwordless… Read More »