Pages

Showing posts with label Password. Show all posts
Showing posts with label Password. Show all posts

EyeVerify Knows You by Your Eyes

Image via Flickr user Grégoire Lannoy
EyeVerify says that their technology allows them to identify you by the unique patters of blood vessels within your peepers. The company, which launched last year, believes that their product could succeed where so many other biometric verification methods haven't, and might be the solution to the password problem.

A Live Authentication
"Passwords fail for two reasons," said EyeVerify's CEO and Founder Toby Rush to SecurityWatch. "Because we're terrible at creating passwords, and there's no 'live-ness' test." While a password manager can solve the first problem of weak or repeated passwords, there's no way to determine whether the person entering the password is who they claim to be—"live-ness."

EyeVerify believes it can solve both problems. In terms of strength and accuracy, Rush said that their technology was recently validated by a third-party as being on par with fingerprints – that is, less than one in 10,000 false rejects.

Live-ness is a little more complicated. In The Avengers, for instance, Loki scans the eye of a wealthy plutocrat in order to gain access to a vault. Rush says that could never happen with EyeVerify because it uses streaming video, not still images, to identify the patterns of blood vessels.

"We tell the camera to do different things," Rush explained, such as change the white balance of the image or the frame rate at random. The software also recognizes the different absorption rates of light in the eye versus on a monitor, meaning that the system wouldn't be fooled, "even if you had an exact video of sequence."

We've seen plenty of biometric security systems before, but EyeVerify believes that it can gain wider acceptance because it requires no special hardware. Instead, the software is designed to run on smartphones—both iOS and Android—that have at least a 2MP camera. "We're leveraging the devices they already have," said Rush.

Giving a Voice
The company has already begun partnering with companies, including password managers and banks, but Rush sees possibilities far beyond mere secondary authentication for web services. "It's a genetic bio-marker clearly visible in the whites of their eyes," he said. "It's independent of ethnicity, gender, race, and has no language barriers."

Rush sees applications in healthcare, where patients can prove their identity to access health records, or academic testing and certification so educators know exactly who is in the seat taking an exam. The software could also be deployed to help include the millions of individuals who exist without officials records, such as refugees. "The poor want to have a name, they want to have an identity," said Rush.
Unfortunately, passwords are likely to always be a part of identification and security systems. However, systems like EyeVerify and other biometric identifiers can do more than authenticate; they can clearly determine who is accessing what and where. With more and more high-profile attacks making the headlines, look for this kind of technology rolling out soon.
Image via Flickr user Grégoire Lannoy

Predictable Passwords a Target for Hackers — SplashData Reveals 25 Worst Choices

If you use the word ‘password’ as your e-mail or social media site password, you’re in good company.
According to SplashData, a provider of password management applications, it is the most-used password of the year.
‘123456,’ and ‘12345678’ round out the top three.

“In a year with several high profile password hacking incidents at major sites including Yahoo, LinkedIn, eHarmony, and Last.fm, SplashData’s list of frequently used passwords shows that many people continue to put themselves at risk by using weak, easily guessable passwords,” reads a press release issued by SplashData.

The firm’s list of the ’25 Worst Passwords of the Year’ was assembled using information hackers have posted online as “stolen passwords.”

New to the worst password list this year are: ‘welcome, ‘ ‘jesus,’ ‘ninja,’ ‘mustang,’ and ‘password1.’

Here is a look at the list:
#              Password                Change from 2011
1               password                Unchanged
2               123456                    Unchanged
3               12345678                Unchanged
4               abc123                     Up 1
5               qwerty                     Down 1
6               monkey                   Unchanged
7               letmein                    Up 1
8               dragon                    Up 2
9               111111                      Up 3
10             baseball                  Up 1
11             iloveyou                  Up 2
12             trustno1                  Down 3
13             1234567                  Down 6
14             sunshine                 Up 1
15             master                     Down 1
16             123123                     Up 4
17             welcome                  New
18             shadow                    Up 1
19             ashley                      Down 3
20             football                   Up 5
21             jesus                        New
22             michael                   Up 2
23             ninja                        New
24             mustang                 New
25             password1              New

SplashData chief executive officer Morgan Slain says publishing the list is a way to make people aware of the risk they are taking in using weak passwords.
“Even though each year hacking tools get more sophisticated, thieves still tend to prefer easy targets,” says Slain. “Just a little bit more effort in choosing better passwords will go a long way toward making you safer online.”
SplashData offers the following tips for choosing more secure passwords:
  • Use passwords of eight characters or more with mixed types of characters. One way to create longer, more secure passwords that are easy to remember is to use short words with spaces or other characters separating them. For example, “eat cake at 8!” or “car_park_city?”
  • Avoid using the same username/password combination for multiple websites. Especially risky is using the same password for entertainment sites that you do for online email, social networking, and financial services. Use different passwords for each new website or service you sign up for.
  • Having trouble remembering all those different passwords? Try using a password manager application that organizes and protects passwords and can automatically log you into websites. There are numerous applications available, but choose one with a strong track record of reliability and security like SplashID Safe, which has a 10 year history and over 1 million users. SplashID Safe has versions available for Windows and Mac as well as Smartphones and tablet devices.

Post from: SiteProNews

How Safe Is Your PIN

How Safe Is Your PIN?

Compiled by: BackgroundCheck.org