Feeds

Google tries putting an NFC ring on it: Bonking will keep you SAFE

Or sticking it in, to put it another way

Secure remote control for conventional and virtual desktops

Google has started testing NFC keyrings from one-time-pad makers Yubico, with a view to offering them to ordinary punters next summer as a secure way of accessing the Google cloud.

The keyrings feature a USB interface and an embedded NFC tag, either of which can supply a one-time password securing connection. The technique is clever, and if the Wall Street Journal is accurate then Google's support could quickly make it ubiquitous.

The tag in question

When is a keyboard not a keyboard? When it's a key.

The key generates a string of one-time passwords, using a secret seed shared with the service to which it's intended to connect. But unlike similar tokens which display the generated password on an LCD screen for the user to type in, the Yubico device connects as a USB keyboard and enters the password itself.

Which is fine if you're using a computer with a spare USB port, but less convenient on a mobile phone – which is where NFC comes in. Hold the keyring beside an NFC phone and it provides a URL, containing the one-time password, to the handset's browser.

And that's the critical point about Yubico - it doesn't require any software on the phone or computer; it just provides the secure password without the user having to type it in.

That confirms to the cloud service that the user has possession of the key ring, and a normal password comprises the second stage of the two-stage making the connection a good deal more secure with the minimum of additional effort.

That might still prove too much effort for users who generally expect their browsers to keep track of their passwords anyway, which is presumably what Google is testing for, but with more services moving into the cloud the ability to know who's accessing them is only going to become more critical over time. ®

Secure remote control for conventional and virtual desktops

More from The Register

next story
Ellison: Sparc M7 is Oracle's most important silicon EVER
'Acceleration engines' key to performance, security, Larry says
Linux? Bah! Red Hat has its eye on the CLOUD – and it wants to own it
CEO says it will be 'undisputed leader' in enterprise cloud tech
Oracle SHELLSHOCKER - data titan lists unpatchables
Database kingpin lists 32 products that can't be patched (yet) as GNU fixes second vuln
Ello? ello? ello?: Facebook challenger in DDoS KNOCKOUT
Gets back up again after half an hour though
Hey, what's a STORAGE company doing working on Internet-of-Cars?
Boo - it's not a terabyte car, it's just predictive maintenance and that
prev story

Whitepapers

A strategic approach to identity relationship management
ForgeRock commissioned Forrester to evaluate companies’ IAM practices and requirements when it comes to customer-facing scenarios versus employee-facing ones.
Storage capacity and performance optimization at Mizuno USA
Mizuno USA turn to Tegile storage technology to solve both their SAN and backup issues.
High Performance for All
While HPC is not new, it has traditionally been seen as a specialist area – is it now geared up to meet more mainstream requirements?
Beginner's guide to SSL certificates
De-mystify the technology involved and give you the information you need to make the best decision when considering your online security options.
Security for virtualized datacentres
Legacy security solutions are inefficient due to the architectural differences between physical and virtual environments.