4
Jul

Asterix Love

   Posted by: wkossen   in Security, Uncategorized

Mood: interested

a false sense of securityLately there has been a lot of discussion about this poor little character, the asterix: *. One example of this is this site. This character has been a very frequent site on every login screen you might encounter. It hides your real password (unless you actually had ******* as a password…) The question is whether this is good or bad practice. In this little post I’ll give you my opinion on it.

The original argumentation was to hide the password from peeking eyes. Look over someone’s shoulder and you know… then, you might look at what someone is typing on the keyboard and know as well. Especially if someone is typing slow. The added value is limited. In fact, security by obscurity isn’t real security. As it turns out, not seeing what you are typing increases the likelyhood of making mistakes. This is frustrating, but also costly. Unlocking accounts, retrieving passwords by e-mail etc. is timeconsuming and therefor pricy. Now we have two sides of the scales, which one is heavier?

In fact, that may not at all be the question. You could argue that the asterix’s make people feel good. They’re not only nice to look at, but also give a (false) sense of security, something people like (and not just after 9/11). The feel-good-factor hasn’t been taken into account in all the discussions I’ve read on the internet. Even if the added value in terms of real security is limited, what about making people feel safe (even if they aren’t. You want safety? Shut down that computer Now!).

Another factor that hasn’t been discussed is the simple fact that if we were to change this habit, it would take a very long time to reach an asterix-free world. There would be a mixed environment for years which might confuse people so much they call on the helpdesk anyway. No savings here. Is it really that bad? Or should people learn to type without looking and improve their skills that way?

Even further, one could (and I do) argue that the password itself isn’t a very good idea. There are better ways of securing stuff from unwanted access. Multifactor authentication, biometrics (although there are strong arguments against that one as well. maybe worth another post one day), smartcards, PKI, etc…. If we’re going to change at all, let’s not just do the superficial and aesthetics…

As you see, I don’t have the answer. do you? I hope you will comment on this post and give me your views on this little subject.

4c685b3de1f98bc3665afa55cc11559d Asterix Love

Related posts…

4c685b3de1f98bc3665afa55cc11559d Asterix Love


bookmark Asterix Love

If you enjoyed this post, make sure you subscribe to my RSS feed!

Tags:

This entry was posted on Saturday, July 4th, 2009 at 13:23 and is filed under Security, Uncategorized. You can follow any responses to this entry through the RSS 2.0 feed.

Word count: 439

You can leave a response, or trackback from your own site.

This website uses IntenseDebate comments, but they are not currently loaded because either your browser doesn't support JavaScript, or they didn't load fast enough.

2 comments so far

 1 

Hello,

i saw that you are a membre of Adgitize, too. I hope you will reach payout soon. I have for you one or perhaps more useful tips, but definitely one which

gives you a boost in ad view points -> in the end you will earn some more cents day by day.

Just read my guide How to maximize your earnings in Adgitize

Adgitize Payment Proof June 2009

ReplyReply
July 13th, 2009 at 12:58
 2 

Willem,

Read my opinion at http://0308783450.nl/2009/07/22/sterretjes-in-wac... about this subject.

ReplyReply
July 22nd, 2009 at 11:54

Leave a reply

You must be logged in to post a comment.

Bad Behavior has blocked 160 access attempts in the last 7 days.

Copyright © 2008 Willem Kossen

you're welcome to reuse under certain conditions. It is licensed: Attribution-Non-Commercial-Share Alike 3.0 Netherlands

Internet Blogs - BlogCatalog Blog Directory


Page Rank

look here:

Blog Directory Blog Directory
Theme Tweaker by Unreal