Cool new security doo dad
I’ve become aware of an interesting new authentication doo hicky from Sweden, of all places. The YubiKey is a USB dongle that extends the concept of the security token many clients are already familiar with. Generally, you would have a security token if you use internet banking (and if you don’t have one, ring your bank immediately and get one!)
The YubiKey goes a great big leap foward; It generates one time passwords just like existing tokens, but the passwords it generates are much much longer, making them vastly more secure. That would normally be a problem, as typing in a 20 or 30 character password every time would turn most users off.
Yubikey solves this too, by being a USB Keyboard. You just plug it into your computer, browse to the websites login page, click on the password box, then press the button on the Yubikey; It then types in this super secure one time password for you.
I think I’ll write to Suncorp (who I bank with) and ask them if they are looking into offer a Yubikey solution.