Stolen Passwords — How to Break Away from This Futile Loop

Today’s topic: ”UK donates 225 million stolen passwords to hack-checking site”

We could think of three different approaches –

(1) teach people to remember a yet stronger password that everyone knows humans are by no means able to recall (proper hashing assumed),

(2) remove the password altogether from the sphere of digital identity

and (3) make the entropy of the password high enough to stand fierce brute force attacks (proper hashing assumed) while reducing the burden on people

(1) is what security professionals including NIST used to propose persistently for a few decades, (2) is what some disastrously misguided people proposed and (3) is what we are proposing

Ref for (1): No need any longer although there are still a pocket of people who stick to it.

Ref for (2): Passwords are to Present-day Citizens What Stones and Clubs are to Ancient Ancestors

Ref for (3): Maximizing Entropy of Secret Credentials while Minimizing Burden on Citizens

Incidentally, we would like to emphasize that it would be only harmful to mix up the discussions on authenticators (password, token, etc.) with that on deployment of authenticators (2FA/MFA, SSO, etc.)

Advocate of 'Identity Assurance by Our Own Volition and Memory', Inventor of Expanded Password System and Founder of Mnemonic Identity Solutions Limited in UK.

Hitoshi Kokumai

Hitoshi Kokumai

Advocate of ‘Identity Assurance by Our Own Volition and Memory’, Inventor of Expanded Password System and Founder of Mnemonic Identity Solutions Limited in UK.

