a thoughtful web.
Good ideas and conversation. No ads, no tracking.   Login or Take a Tour!
comment
byonic  ·  3111 days ago  ·  link  ·    ·  parent  ·  post: Google aims to kill passwords by the end of this year

I'm by no means a cryptographer, but I'm worried about the security implications of this. It concerns me that they compared the security of Trust API to fingerprints, which are notoriously insecure. Even if the new api is 10x as secure as a fingerprint, a normal password is, to my understanding, many times stronger than that. It seems to me that we should be seeking to make systems more secure, rather than less.

Convenience is of course always a factor, but to me it's second to security.