Andrew Bonwick
Vice President of Product Development at Relm Insurance
Madhav Sheth
CEO of Ai+ Smartphone
Stephen Rose
CEO Render Networks
I was at the c0c0n conference between 7th & 8th October 2011 held at Cochin and attended some very good interesting works and presentations, such as “Wi-Fi Malware for Fun and Profit” by Vivek Ramachandran which is real good exploit in windows7, which I have attended in Banglore(September-2011) itself to understand and another one “When I Grow Up I want to be a Cyber Terrorist” by Michael Kemp and more.
However, I have attend one more presentation on “Password Less Authentication, Authorization & Payments” by Srikar Sagi from PayPal – and I was first intrigued by the very title itself that, how is authentication possible without a password (thought some mind freak – no pun intended).
I somehow liked it after deeper understanding of costs involved in account takeovers, development costs and fraud investigation costs (poor guy has explained me well and convinced me).I observed that the Design proposed by him is dividing the authentication process itself into two halves i.e. the authentication journey starts on the IP Network by entering a simple USERID and a PIN to server and receives a small challenge on the web page which you need to enter into a mobile application.
Server reads the message and loads the temporary auth database against the user based on the mobile phone number, decrypts the packet using the server’s private key and compares the hashes.I was surprised that the truth is I’m authenticated using my own secrets (IMSI, ICC-ID, APPID, PIN) with arbitrary codes and but no passwords, no password complexities, no need to carry tokens (hardware or software).


