Skip to main content

Google wants to kill the password, and came up with an ingenius way to do it

google atap plan to kill passwords maxresdefault
Google’s Advanced Technologies and Projects (ATAP) unveiled a bundle at the group’s I/O keynote this morning, but two of the most interesting presentations dealt with passwords, or “relics,” as division head Regina Dugan called them. “Passwords suck,” she explained, for a variety of reasons. According to ATAP’s data, 70 percent of users forget their passwords, and don’t often do a very good job creating hard-to-crack phrases besides — “Humans are a bad source of entropy,” Dugan said. In an effort to develop more reliable security, ATAP developed Project Abacus, an analytical system based on machine learning, and Project Vault, a cryptographic MicroSD card.

The scale of Project Abacus was so vast that ATAP sought outside help — Dugan said the department recruited 25 researchers from 16 institutions to participate in development. With the added brainpower and the help of hundreds of volunteers, they managed to create a new method of authentication that Dugan said is not only 10 times more secure than the best fingerprint sensor available, but also entirely based in software — it requires no special operating system or hardware.

Recommended Videos

Project Abacus works, she explained, by continually generating a “trust score” from data the hardware on which it’s running collects — the apps you most frequently use, for example, or your location. To demonstrate, two researchers on stage passed a smartphone running Abacus software back and forth. The front-facing camera collected facial data and algorithms calculated trustworthiness in real time. When the second researcher used an app at a time of day the first researcher typically didn’t, the “score,” represented on a line graph, decreased.

Dugan was coy about workings and prospects of Project Abacus, but stressed the code was simple enough to be packaged in a software update.

Project Vault, on the other hand, is physical. But that doesn’t make it any less impressive. It’s capable of creating a secure communications channel on any device with a MicroSD slot.

google-io-2015-atap0076

That may sound like magic, but Project Vault actually a “security-dedicated computer [in] a MicroSD card with a driver-free interface and encryption and secure communication,” explained development lead Peiter “Mudge” Zatko. He wasn’t kidding about the computer part — Project Vault packs an antenna, 4GB of storage, and an ARM processor on a thumb-sized card. Zatko says modern hardware informed the team’s choice of form factor. “You already have secure elements in your phones and computers, like SIM cards and Trusted Platform Modules for OEMs,” he said. “What about a secure element that protects the things important to you?”

In abstract, Project Vault accomplishes this all rather simply: plug it into a phone or computer and communications with nearby Vault users — video, audio, photos, and text — are encrypted. That’s accomplished with immutable logging, a record of all attempts by nefarious third parties to access the cars, and with a real-time operating system (RTOS) with a wealth of cryptographic tools, including a random number generator and hashing, at its disposal.

Communication worked seamlessly in the on-stage demo. Two smartphones with Project Vault cards were able to send and receive instant messages directly in real time.

ATAP’s producing Vault modules for enterprise right now, but it’s releasing the software under an open source license. “We’re doing this to be fully transparent because we want developers to be able to see how it works, understand it, and trust it,” Zatko explained. The team plans to deploy 500 prototypes internally and release development hardware at some point in the near future.

“It shouldn’t matter how many doors or windows your house has as long as it has a vault in it,” Zatko said.

Kyle Wiggers
Former Digital Trends Contributor
Kyle Wiggers is a writer, Web designer, and podcaster with an acute interest in all things tech. When not reviewing gadgets…
Samsung Galaxy Watch 4 vs. Fitbit Sense
The Samsung Galaxy Watch 4 smartwatch, worn on a person's wrist.

The Galaxy Watch 4 is Samsung's take on a modern, hi-tech wearable that doesn't imitate an old-school analog wristwatch. It eschews the classic design of its predecessors for a sleeker, more streamlined look, while also providing some excellent hardware and features. These include a Super AMOLED touchscreen, 16GB of internal storage, generous battery life, and some great health-tracking software.

It's certainly one of the best smartwatches out there, but in a market saturated by Apple Watches and various Android equivalents, it certainly isn't without competitors. One of these is the Fitbit Sense, which in 2020 emerged to offer a premium version of the core Fitbit experience, replete with an ECG sensor, a choice of virtual assistants, and a wealth of fitness features.

Read more
This $4,000 titanium beauty is the ultimate square G-Shock
The G-Shock MRG-B5000B.

Do you want the very best Casio offers in manufacturing, design, and technology from your new G-Shock, all wrapped up in that highly recognizable square case? In other words, the ultimate version of a truly classic G-Shock watch? If so, the new MRG-B5000B is exactly the model you will want, provided cost is no object. We’ve been wearing it.
What makes MR-G so special?
Although Casio is best known for tough watches that won’t break the bank, Casio also has decades of watchmaking experience, and it showcases its talents most effectively in its highly exclusive MR-G family of watches. These models, its most luxurious, are assembled by hand on Casio’s Premium Production Line located in the Yamagata factory in Japan, where only the company’s most experienced, specially certified technicians work on the top MT-G and MR-G models.

The square G-Shock is one of the most popular models, having been around since the G-Shock brand first started in the early 1980s, and bringing it to the luxury MR-G range is going to see a lot of people reaching for their wallets. What makes it so special? It’s the first time the classic, beloved square G-Shock has been given the MR-G treatment, with most other MR-G models over the past few years featuring an analog dial. There's a huge section of an already large fan base waiting for this.

Read more
Fitbit recalls Ionic smartwatch after several burn reports
best walmart deals on apple watch garmin and fitbit ionic smartwatch adidas edition ice gray silver

Fitbit Ionic smartwatch users need to stop using their devices right now. The company has recalled its Ionic wearable after over 150 reports of the watch’s lithium-ion battery overheating, and 78 reports of burn injuries to the users. It will offer a refund of $299 to the Fitbit Ionic smartwatch users who return the device.

Fitbit has received at least 115 reports in the United States and over 50 reports internationally about the Ionic smartwatch's battery overheating. It is recalling the device as there are two reports of third-degree burns and four reports of second-degree burns out of the 78 total burn injuries report.

Read more