| Sumario: | The article emphasizes the need to critically revisit authentication as a whole and the password's role therein to understand the current situation in computer security. Topics discussed include the simplistic models of user and attacker behaviors that have led researchers to emphasize on the wrong threats, authentication as a classification problem amenable to machine learning, and the continued use of passwords to reduce harm at acceptable cost. Also mentioned are the history of passwords, two outdated models that underlie much of the current password literature, and the need to protect user accounts and sensitive data.
|