ZA·007 Talk 2019
Authentication is Broken. Can We Try Fix It?
- Event
- BSides Cape Town
- Region
- South Africa
- Language
- EN
Abstract
This talk seeks to demonstrate how the hardened derivation of hierarchically deterministic asymmetric keys can be used as an authentication mechanism that sites could use to replace the passwords. As anyone who frequents haveibeenpwned would know, password reuse is a major problem that is worsened by inevitable data leakages. Without the use of a password manager a person is prone to reuse a password at least once (or risk forgetting their password if they try to be clever by coming up with a new password for every site). In this proposed authentication mechanism sites would store xpubs instead of passwords. The xpubs would be used to derive public keys when authenticating users.
Sources
- Watch the recording youtube.com
- Archived copy web.archive.org
- Where this entry came from bsidescapetown.co.za
Source of truth:
data/works/authentication-is-broken-2019.yaml