Google’s updated security roadmap details increased friction, reliance on hardware

Google's updated security roadmap details increased friction, reliance on hardware

A lot has changed in the security realm since 2008 — remember Alicia Keys’ recent attempt to convince us her Twitter account was hacked, when we all know she still uses an iPhone even as BlackBerry’s Creative Director? Pranks aside, the consumer world alone has been overrun with mass data hackings — everyone from Evernote to Microsoft to Sony to RSA has felt the wrath. To combat all of this, Google is revamping its five-year security plan, which calls for a complex authentication code replacing the conventional password in due time; in other words, Google is going to make it harder to access your accounts when initially setting up a device, but hopes you’ll deal. Eric Sachs, group product manager for identity at Google, put it as such: “We will change sign-in to a once-per-device action and make it higher friction, not lower friction, for all users. We don’t mind making it painful for users to sign into their device if they only have to do it once.”

The documents also suggest that two-step verification may soon become less of an option, and more of a mandate. Sachs straight-up confesses that Google didn’t predict the current level of smartphone adoption back in 2008, but now realizes that utilizing mobile hardware and apps as friction points for logging in makes a lot more sense. A huge swath of Google users are already carrying around a product that could be used as a verification token, so the obvious solution is to make use of that. We’re also told that learnings from Android will be carried over to Chrome, and further into the world of web apps. No specific ETAs are given, but trust us — half a decade goes by quickly when you’re having fun.

Filed under: ,

Comments

Via: ZDNet

Source: Google

Microsoft Accounts Receive Two-Step Verification To Help Keep Secure

Microsoft Accounts Receive Two Step Verification To Help Keep SecureThe online world has become a little less safe considering how many companies have their services hacked, which results in the user having to change a perfectly good password in fear their account will be accessed by an unauthorized user. Microsoft is taking steps to keep your security when using their services the highest priority, which is why they’re rolling out a new two-step verification process for all of its accounts.

The new verification process will start rolling out an upgrade to Microsoft accounts over the next few days that will allow its users to enable an optional two-step authentication service to help improve the security of their account. The result will help better protect a person’s Microsoft account through the use of a verification process. Microsoft account owners will also be able to use app passwords for some of its services, such as the Xbox 360, for those services, which at the moment, don’t support two-step authentication. (more…)

By Ubergizmo. Related articles: Dropbox Can Be Used To Find Your Stolen Computer, Adobe Launching Primetime To Tackle TV Everywhere,

    

The Super Easy Way Twitter Could Make All This Account Hacking Stop

Twitter accounts are getting hacked left and right. Today it was Burger King. Before that, it was the Westboro Baptist Church (Admittedly, they deserved it). And before that, it was us and Mat Honan. Hacks will always happen, but this is dumb because Twitter could make this all go away. Forever. All we need is two-factor authentication and it’s insane we haven’t gotten it yet. More »

Google’s Making Moves to Kill the Password

Passwords are long and complicated and hard to remember. And that’s only if they’re good passwords. No matter how you slice it, passwords are annoying and on top of that, they’re not even all that secure. Google knows that all too well, and it’s pushing for the next big thing. A ring maybe. Like for your finger. More »