On TechRepublic: 10 dying IT skills
BNET Business Network:
BNET
TechRepublic
ZDNet

May 24th, 2005

Microsoft security guru wants you to jot down your passwords?

Posted by George Ou @ 10:28 am

Categories: Security

Tags:

When I first read this article from Munir Kotadia about Microsoft’s sr. program manager Jesper Johansson advising users to write down their passwords, I thought my eyes were deceiving me.  In fact, I’m surprised that Johansson is even permitted to represent Microsoft, given the fact that Bill Gates has declared the death of the password in favor of Smartcard cryptographic tokens or OTP (One Time Pad) token technology such as RSA’s SecurID.  The NIST gives Smartcards and OTP the highest ratings for secure authentication.  What Johansson is saying about password security seems to be flying in the face of what the Microsoft campus at Redmond is actually doing with Smartcards to consolidate physical building access and computer authentication into a single physical token.  I personally can’t wait for the demise of the password and the adoption of a universal strong token-based authentication standard that could grant access to everything from your car to your bank account to your corporate network.

Johansson not only evangelized the practice of writing down a complicated single-use and single-factor password for "better security", but went further to criticize two-factor authentication by saying that some people were taping pin numbers to their RSA SecurID tokens.  The truth of the matter is, a password can be copied or memorized by an unauthorized person without any indication and therefore constitutes a secret breach of security that can go on indefinitely and lead to many more secret breaches.  On the other hand, the theft of a Smartcard or OTP token, at worst (if the thief can also steal the pin and/or user password), will only grant very temporary access until the token is discovered missing and is revoked.  Any usage of the token after the time of theft would alert IT to unauthorized access and also indicate the theft of the user’s password forcing an immediate revocation of the token and an immediate password change.  There is no way to know if and when a password has been copied or memorized by someone else; whereas you will always know a when a token has been stolen since its legitimate owner will call the helpdesk the minute he can’t get to his email.  If anything, this makes the case for simple multi-use passwords and physical tokens since users will not need to write down a simple password.  A hacker with a stolen token will not be able to guess even a simple four-character alpha-numeric password in a reasonable amount of time since it would take an average of over 800,000 manual guesses to break into the system and the token would have long since been revoked.

As an IT consultant who travels from company to company, working on the most sensitive network and server infrastructures, I can’t tell you how many times I’ve been handed a master list of passwords of all the servers, routers, switches, and firewalls simply because that is the only way I can work on the systems.  It’s almost inevitable that multiple administrators and consultants will know all of the most sensitive passwords that will most likely never be changed due to the disruption that would occur.  Tokens, on the other hand, can be granted permissions and revoked on the fly without any sharing of secret keys, and they can seamlessly grant secure access to multiple systems within multiple companies.  Passwords have long been obsolete and no fancy policy is ever going to make them any more secure.  It doesn’t matter if the password is encrypted or not since at some point, you’ll have to decrypt it to use it and all it takes is a key logger to defeat the most complex password in the world.  Smartcards and RSA tokens have no such problem since there is no way to copy them without physically stealing them and triggering an alert.  It’s shocking that someone this high up in rank at Microsoft has such a poor grasp of authentication theory and is taking such a great leap backwards while the rest of his company moves forward. 

George Ou is Technical Director of ZDNet. See his full profile and disclosure of his industry affiliations.

  • Talkback
  • Most Recent of 28 Talkback(s)
frankly the only problem I see is the privacy issue
when all the websites which require registration to download any piece of crap will force me to auth using my smart card, basically everything I do will be nicely and tightly logged somewhere. nice to know, in case of alzeheimer (please correct my spelling, thanks)... (Read the rest)
Posted by: ranjix@... Posted on: 06/10/05 You are currently: a Guest | | Terms of Use
Er... What?  xxyl | 05/24/05
Did you read what I said?  george_ou | 05/24/05
Yes, there are other issues.  wresnick | 05/25/05
My point is, passwords are obsolete period  george_ou | 05/25/05
I don't know if I really like this  SantiagoCrespo | 06/07/05
frankly the only problem I see is the privacy issue  ranjix@... | 06/10/05
Yes, and...  xxyl | 06/03/05
Not quite  wresnick | 05/25/05
I have to disagree, George  Real World | 05/24/05
Tokens cost $30 a piece  george_ou | 05/24/05
$30 each, plus  Real World | 05/24/05
Forget to mention  Real World | 05/24/05
You have outdated information  george_ou | 05/24/05
We'll have to agree to disagree  Real World | 05/25/05
Smartcards are easier than you think  george_ou | 05/24/05
Quick and Dirty Two-factor  salmonslayer | 05/24/05
What happens when one of these passwords are intercepted?  george_ou | 05/24/05
That's not important  wresnick | 05/25/05
Who said anything about memorization?  george_ou | 05/25/05
mjb, just because you do it doesn't make it right  ranjix@... | 06/10/05
Setting up a smartcard system is trivial to do!  B.O.F.H. | 05/24/05
Differant slant  mtrotz | 05/25/05
Absolutely  wresnick | 05/25/05
The subject applies to both cases  george_ou | 05/25/05
George...  ordaj@... | 05/25/05
Three points ...  George Mitchell | 05/27/05
Passwords are full of tradeoffs  george_ou | 05/27/05
Write down your password?  papatator | 06/07/05

What do you think?

SponsoredWhite Papers, Webcasts, and Downloads

Click Here
advertisement

Recent Entries

Top Rated

    Premier Vendor Content Whitepapers, webcasts & resources from our Power Center Sponsors

    Archives

    ZDNet Blogs

    White Papers, Webcasts, and Downloads

    • Smart Tech Expert advice on innovations in healthcare and the green technologies that make it happen. Find out more
    • Smart Business Discussion and advice on management issues that revolve around making your world smarter and more useful. More Smart Advice
    • Smart People The best and worst moves in the management and strategy trenches. Learn More