Skip to main content

Google wants to kill the password, and came up with an ingenius way to do it

google atap plan to kill passwords maxresdefault
Image used with permission by copyright holder
Google’s Advanced Technologies and Projects (ATAP) unveiled a bundle at the group’s I/O keynote this morning, but two of the most interesting presentations dealt with passwords, or “relics,” as division head Regina Dugan called them. “Passwords suck,” she explained, for a variety of reasons. According to ATAP’s data, 70 percent of users forget their passwords, and don’t often do a very good job creating hard-to-crack phrases besides — “Humans are a bad source of entropy,” Dugan said. In an effort to develop more reliable security, ATAP developed Project Abacus, an analytical system based on machine learning, and Project Vault, a cryptographic MicroSD card.

The scale of Project Abacus was so vast that ATAP sought outside help — Dugan said the department recruited 25 researchers from 16 institutions to participate in development. With the added brainpower and the help of hundreds of volunteers, they managed to create a new method of authentication that Dugan said is not only 10 times more secure than the best fingerprint sensor available, but also entirely based in software — it requires no special operating system or hardware.

Project Abacus works, she explained, by continually generating a “trust score” from data the hardware on which it’s running collects — the apps you most frequently use, for example, or your location. To demonstrate, two researchers on stage passed a smartphone running Abacus software back and forth. The front-facing camera collected facial data and algorithms calculated trustworthiness in real time. When the second researcher used an app at a time of day the first researcher typically didn’t, the “score,” represented on a line graph, decreased.

Dugan was coy about workings and prospects of Project Abacus, but stressed the code was simple enough to be packaged in a software update.

Project Vault, on the other hand, is physical. But that doesn’t make it any less impressive. It’s capable of creating a secure communications channel on any device with a MicroSD slot.

google-io-2015-atap0076
Image used with permission by copyright holder

That may sound like magic, but Project Vault actually a “security-dedicated computer [in] a MicroSD card with a driver-free interface and encryption and secure communication,” explained development lead Peiter “Mudge” Zatko. He wasn’t kidding about the computer part — Project Vault packs an antenna, 4GB of storage, and an ARM processor on a thumb-sized card. Zatko says modern hardware informed the team’s choice of form factor. “You already have secure elements in your phones and computers, like SIM cards and Trusted Platform Modules for OEMs,” he said. “What about a secure element that protects the things important to you?”

In abstract, Project Vault accomplishes this all rather simply: plug it into a phone or computer and communications with nearby Vault users — video, audio, photos, and text — are encrypted. That’s accomplished with immutable logging, a record of all attempts by nefarious third parties to access the cars, and with a real-time operating system (RTOS) with a wealth of cryptographic tools, including a random number generator and hashing, at its disposal.

Communication worked seamlessly in the on-stage demo. Two smartphones with Project Vault cards were able to send and receive instant messages directly in real time.

ATAP’s producing Vault modules for enterprise right now, but it’s releasing the software under an open source license. “We’re doing this to be fully transparent because we want developers to be able to see how it works, understand it, and trust it,” Zatko explained. The team plans to deploy 500 prototypes internally and release development hardware at some point in the near future.

“It shouldn’t matter how many doors or windows your house has as long as it has a vault in it,” Zatko said.

Editors' Recommendations

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Fitbit recalls Ionic smartwatch after several burn reports
best walmart deals on apple watch garmin and fitbit ionic smartwatch adidas edition ice gray silver

Fitbit Ionic smartwatch users need to stop using their devices right now. The company has recalled its Ionic wearable after over 150 reports of the watch’s lithium-ion battery overheating, and 78 reports of burn injuries to the users. It will offer a refund of $299 to the Fitbit Ionic smartwatch users who return the device.

Fitbit has received at least 115 reports in the United States and over 50 reports internationally about the Ionic smartwatch's battery overheating. It is recalling the device as there are two reports of third-degree burns and four reports of second-degree burns out of the 78 total burn injuries report.

Read more
Razer Anzu smart glasses deal knocks $140 off the price tag
The Razer Anzu smart glasses placed on top of an open book.

While smartwatch deals have slowly claimed their place in the mainstream, smart glasses haven't turned out to be as popular. Gaming-focused brand Razer, however, is trying to renew interest in smart glasses with the Razer Anzu, which you can currently purchase from Best Buy at $140 off. If you'd like to give them a try, they're available for just $60, less than half their original price of $200.

There have been failures like the Google Glass and Snap Spectacles, and hopeful attempts like Oppo's Air Glass and Apple's secretive project, but the Razer Anzu smart glasses take a different spin on the wearable device by designing them for indoors. While they come with polarized sunglass lenses, their clear lenses are more useful with their blue light filter, which protects your eyes from screen glare to prevent discomfort even after hours of playing video games or working from home. The smart glasses, which also have a built-in omnidirectional microphone and speakers, may also be more comfortable to wear for an extended period of time compared to headsets and headphones. You'll enjoy smooth, stutter-free sound with the Razer Anzu's low latency audio with a 60ms Bluetooth connection.

Read more
The best Samsung Galaxy Watch 4 screen protectors
Person holding skateboard while wearing the Samsung Galaxy Watch 4.

A new, sleek design and digital bezel help the Galaxy Watch 4 stand out in the crowd and set it apart from the traditional style of the Galaxy Watch 4 Classic. Whether you've picked up a 40mm model with a 1.2-inch Super AMOLED screen or opted for more screen real estate with the 44mm model, that stand-out design needs protecting from scratches and knocks. That means it's time for our picks of the best Samsung Galaxy Watch 4 screen protectors, with something to suit all budgets.

These screen protectors will all fit the 40mm or 44mm models of the Galaxy Watch 4. If you've got a Samsung Galaxy Watch 4 Classic, these won't fit.
Spigen Glas.tR EZ Fit Screen Protector

Read more