Universal password authentication systems - more R&D is necessary

Global web authentication

You are right !
It is exciting times...but there is no further R&D needed. We have been doing exactly this for the past year.
With a secure strong authentication at the front end to accompany the password we have the means to log you into all your accounts. We have broken the authentication flows of all the major providers with Perl and Java tools and now we can authenticate the account is there, check the existing password and reset it.
There is no rocket science in this...just the will to win.
We provide only password management services to the enterprise on a commercial basis but we are equipped to roll the web version out globally tomorrow via a trusted service provider and a recognised second factor vendor.

Anything else you would like to share with us ?
 
Last edited:
From Article said:
Morris’ primary concern is that should a user’s single login or authentication be compromised, the hacker would have access to everything, from banking details, to e-mail and online retail accounts.

This is my problem with a universal passwrod as well. It's a nice concept but I wonder if I would trust it.

FastPass said:
You are right !
It is exciting times...but there is no further R&D needed. We have been doing exactly this for the past year.
With a secure strong authentication at the front end to accompany the password we have the means to log you into all your accounts. We have broken the authentication flows of all the major providers with Perl and Java tools and now we can authenticate the account is there, check the existing password and reset it.
There is no rocket science in this...just the will to win.
We provide only password management services to the enterprise on a commercial basis but we are equipped to roll the web version out globally tomorrow via a trusted service provider and a recognised second factor vendor.

Anything else you would like to share with us ?

Huh? It's must still be too early in the morning for me, cause I couldn't make heads or tails of this.
 
Paranoia

If you ordinarily access the web from the same machine then a secure token can accompany the login process.
This is true for laptops, desktops, PDAs and Smartphones...certs can be placed on all these. Use a USB authenticator in a net cafe if you habitually access your most secure accounts from there...but then best practices says this is not so smart !
Personally, I don't see the problem...you just read the wrong press and are as susceptible to structured social engineering to acquire your details as you are to falling foul of technology.
 
Top
Sign up to the MyBroadband newsletter
X