RSS

Web authentication on Mobile devices

 

Common sense regarding web security is to never use the same password on multiple sites. That way, when one password gets compromised, not all of them are.

I usually generate passwords for every single web site that requires a login. For some of them, I even generate the username. There is no way I can remember all of them by heart, it is simply impossible. However, I use a combination of Firefox, Truecrypt, and KeyPass to store my passwords in a secure way. The whole hard drive is encrypted with Truecrypt, low-security site passwords are stored in Firefox, and the important ones are stored in KeyPass, which is also encrypted.

The reason for KeyPass is that you can’t rely on Firefox to keep your passwords safe, it’s not meant to do that. It does fine for my Slashdot password though, as long as the hard drive is encrypted.

With the release of the latest round of Smartphones, more and more people are using an iPhone, an Android phone, and Windows mobiles phones too. Now, these phones often come with nice data plans and decent browsers that didn’t exist just a few years ago. Before using Opera Mini and Safari mobile, going to Slashdot on a mobile phone to post a few comments did not feel like an interesting way to waste 10 minutes at all. Now, it is doable in a comfortable way.

Except typing passwords. That is definitely a pain. I don’t want to remember that 16char. password every time I post a retarded comment on Fark. Yet, I don’t really want to save cookies and authenticated sessions either, because the iPhone is not very secure (understatement of the year). I am convinced that a lot of people who use mobile phones will set a lot of their online passwords to something short, simple, and sometimes maybe even numeric only.

What is the solution? Secure mobile devices and certificates? Possibly. Fingerprint protected certificates could be nice as well, leveraged by some kind of “OpenID” infrastructure maybe.

I guess with the latest iPhone firmware, it takes more than clicking emergency call or receiving a call to unlock it, at least.

1 Comment | Tags: , ,

Firefox Awesomebar

 

At first, it was annoying.

Then, I didn’t notice it.

Now, I love it!

I have always hated bookmarks. They’re a pain in the butt to manage, keep up to date, etc. I have 4-5 bookmarks on my Bookmarks toolbar usually, and I never use bookmarks in the actual bookmarks folder.

Now, I just vaguely remember a page’s URL or title, I start typing away, and it’s gotten pretty good at finding it fast.

Another nice thing is it finds things in your bookmarks, so I don’t have to keep them classified or anything. I can just add bookmarks and dump them in the bookmarks root, and bam! I find my stuff easily!

Just give it a week or two after you upgrade before deciding that you hate it. I know hating the Awesomebar is the cool thing right now, but believe me it’s not so bad!

Firefox 3

No Comments | Tags: ,

Cuil is everything but "Cool"

There’s some buzz around “Cuil”. Oh, it has the biggest index of pages!

Oh, they want to beat Google!

Oh, they have some super wise intelligent technology so the results are better!

Wait a minute. Has anyone ever been able to actually FIND something using Cuil? I mean, at first I didn’t even want to try it because the name sounded stupid, but I forced myself to try it in case it was good. I mean, the homepage is pretty clean, which is nice.

So, at one point today I wanted some details about a group policy setting versus how it affects Internet Explorer precisely. So I “Cuiled” this:

Group policy prevent save username Internet explorer

And got THIS:

No results were found for: Group policy prevent save username Internet explorer

If you’ve checked your spelling, you could try using fewer or different keywords to broaden your search.

Still no luck? Send us your feedback: noresults@cuil.com

Ok, so you didn’t find anything, and you want me to go through the trouble of SENDING YOU AN EMAIL? Are you nuts? I want to find stuff, not email you ! What are you going to do, email me the results back?

I tried a few other searches, and I either got no results, or got a ton of results which were mostly spam.

I don’t doubt that they have some “Cuil” technology over there, but it isn’t nearly ready for prime-time. Re-launch in a year and we’ll see.

Did anybody get good results using it? Seriously?

3 Comments | Tags: , , , ,