Pico: No More Passwords!
Author(s): Frank Stajano

Date: 3 2011
Publication: Proceedings of the 19th international conference on Security Protocols (SP'11)
Page(s): 49 - 81
Publisher: Springer
Source 1: http://www.cl.cam.ac.uk/~fms27/papers/2011-Stajano-pico.pdf
Source 2: http://regmedia.co.uk/2011/04/04/pdf.pdf
Source 3: http://dx.doi.org/10.1007/978-3-642-25867-1_6 - Subscription or payment required

From a usability viewpoint, passwords and PINs have reached the end of their useful life. Even though they are convenient for implementers, for users they are increasingly unmanageable. The demands placed on users (passwords that are unguessable, all different, regularly changed and never written down) are no longer reasonable now that each person has to manage dozens of passwords. Yet we can’t abandon passwords until we come up with an alternative method of user authentication that is both usable and secure.

We present an alternative design based on a hardware token called Pico that relieves the user from having to remember passwords and PINs. Unlike most alternatives, Pico doesn’t merely address the case of web passwords: it also applies to all the other contexts in which users must at present remember passwords, passphrases and PINs. Besides relieving the user from memorization efforts, the Pico solution scales to thousands of credentials, provides “continuous authentication” and is resistant to brute force guessing, dictionary attacks, phishing and keylogging.

PasswordResearch.com Note: Project page: http://mypico.org/ A video related to this research that was presented at Passwords15 London is available here https://www.youtube.com/watch?v=8Nbt0FY19Hg and another video from Passwords11 is available: https://www.youtube.com/watch?v=F5OKRr7YFfM

