News: 1652257153

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Yahoo Japan strives for universal passwordless authentication

(2022/05/11)


Yahoo Japan has revealed that it plans to go passwordless, and that 30 million of its 50 million monthly active users have already stopped using passwords in favor of a combination of FIDO and TXT messages.

A [1]case study penned by staff from Yahoo Japan and Google's developer team, explains that the company started work on passwordless initiatives in 2015 but now plans to go all-in because half of its users employ the same password on six or more sites.

The web giant also sees phishing as a significant threat, and has found that a third of customer inquiries relate to lost credentials.

[2]

“From a security perspective, eliminating passwords from the user authentication process reduces the damage from list-based attacks, and from a usability perspective, providing an authentication method that does not rely on remembering passwords prevents situations where a user is unable to login because they forgot their password,” the case study states.

[3]

[4]

Yahoo Japan's replacement is either authentication by one-time codes sent by SMS, or the Fast Identity Online (FIDO) standard.

When using SMS, the company is fond of using techniques that allow Apple’s iOS and Google’s Chrome browser to read and enter incoming one-time passwords so that users have nothing to do to arrange authentication.

[5]

Users are encouraged to use authenticator apps that work with FIDO and WebAuthn, with one-time codes generated on the device used to access Yahoo Japan.

[6]Japan seeks to decentralize datacenters

[7]Another big Toshiba shareholder calls for major change

[8]Yahoo ! Japan ! offers ! free ! comment ! -moderation ! -as ! -a ! -service ! API !

[9]Japanese messaging giant Line admits it mishandled user data, promises to do better

“The greatest difficulty for offering passwordless accounts is not the addition of authentication methods, but popularizing the use of authenticators,” the case study states. User experience is therefore paramount.

Yahoo Japan has therefore used tricky moments to promote adoption – when users sign up for services like e-commerce that have high fraud potential, or reset forgotten passwords, they receive suggestions to adopt authentication methods that are more secure and easier to use.

Users are encouraged to use the same authentication method on all their devices, but Yahoo ! Japan recognizes that’s not easy or possible for all, and so will tolerate mixed methods. The company also envisages operating multiple methods for the foreseeable future.

The company’s efforts have worked, in two dimensions.

[10]

“The percentage of inquiries involving forgotten login IDs or passwords has decreased by 25 percent compared to the period when the number of such inquiries was at its highest,” the case study explains. Yahoo Japan has also seen a decline in unauthorized access as its number of passwordless accounts rises. ®

Get our [11]Tech Resources



[1] https://web.dev/yahoo-japan-identity-case-study/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YnuJTyk--XBRsXbRxYNtnwAAAMA&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnuJTyk--XBRsXbRxYNtnwAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnuJTyk--XBRsXbRxYNtnwAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnuJTyk--XBRsXbRxYNtnwAAAMA&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[6] https://www.theregister.com/2022/04/13/japan_data_center_decentralisation_plan/

[7] https://www.theregister.com/2022/04/07/toshiba_corporate_governance_embarassment/

[8] https://www.theregister.com/2021/05/19/yahoo_japan_ai_comment_moderation/

[9] https://www.theregister.com/2021/10/19/line_data_governance_report/

[10] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnuJTyk--XBRsXbRxYNtnwAAAMA&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[11] https://whitepapers.theregister.com/



The calm before the storm

Pete 2

> eliminating passwords from the user authentication process reduces the damage from list-based attacks, and from a usability perspective, providing an authentication method that does not rely on remembering passwords

Well, yes. But only because there is an inevitable lag between someone introducing a new security feature and the baddies exposing its weaknesses. Although it seems to me that FIDO / SMS based authentication does little except make users even more dependent on technology and extends the length of the chain of events. So rather than having people contain their passwords in their own memory (brain) and then use their own fingers to enter it, there are now several electronic systems that the authentication data has to pass through, first. All of which have to be working, secure and kept up-to-date.

None of which are under the control of the user (which admittedly, might be a good thing!)

And that is presuming you don't lose your phone, go somewhere that cannot receive the messages, allow your battery to go flat or break it. ISTM all this does is trade one set of potential problems (hacks, forgotten passwords) for a different set.

SMS...

GlenP

SMS is all very well if you have a mobile signal .

I've had to resort to running upstairs, waving my phone out of the window and hoping the SMS message came through and I could get back down to type the code in the 15 minutes the particular site permitted. I got there on the third attempt having wasted the best part of an hour. WiFi calling helps but is by no means universal across operators and phones and still assumes you have a connection available.

I'm quite happy with using authenticators as an addition to passwords, not as an alternative - the clue is in the 2 of 2FA.

Doctor Syntax

"the company is fond of using techniques that allow Apple’s iOS and Google’s Chrome browser to read and enter incoming one-time passwords so that users have nothing to do to arrange authentication.....The percentage of inquiries involving forgotten login IDs or passwords has decreased by 25 percent "

So the thieves don't have to bother getting the password reset nowadays - hte phone is its own security.

https://www.theguardian.com/technology/2022/may/08/crypto-muggings-thieves-in-london-target-digital-investors-by-taking-phones

Anything is good if it's made of chocolate.