Sep 19, 2009

Cheap one time passwords

How many passwords do you have to remember? 6, 23 maybe more? With the increasing amount of online services you login everyday plus passwords in $dayjob and others the number of passwords you have to remember has gone up from 1 to 2 (email, machine) to tens (flickr, twitter (possible, multiple accounts), facebook and so on). You do have different password for each service, right? Didn't think so. Some people try to tackle this problem by using different password levels, first level for non crucial data, second level for important data and third level for data you depend on. Each level having different passwords and of course third level being hardest to guess. What if you would only have to remember one password?

Featuring "cheap one time passwords". The idea is simple and you can already use it at some level on most of the services.
  1. Forget your password
  2. Click on the forgot your password link on the service
  3. Use the password you got in your email to login
  4. Change the password to something long and hard (use some random generator and make the password long)
  5. Do what ever you want
voila, one time passwords done cheap.

This leaves your email password on being the only password you really need to secure and remember. Now if service providers could provide a "log in using one time password" functionality they could do step 4 automatically when you login. The email could even hold a direct login link with a timestamp so that the link can only be used for 15minutes or so.

I already use this method on some of the sites I login too irregularly to really remember the password, try it out next time you need to login to your you haved logged in in a while.

No comments:

Post a Comment