REAL

“Egy jelszó mind fölött”, avagy ki vagyok én? Van-e, véd-e igazán a nem jelszavas autentikáció? = One Password to Rule Them All: Or, Who Am I? Does Passwordless Authentication Really Exist, and Does It Truly Protect?

Pfeiffer, Szilárd and Balsai, Péter (2026) “Egy jelszó mind fölött”, avagy ki vagyok én? Van-e, véd-e igazán a nem jelszavas autentikáció? = One Password to Rule Them All: Or, Who Am I? Does Passwordless Authentication Really Exist, and Does It Truly Protect? In: A tudomány, az oktatás és a közgyűjteményi kiszolgálás új informatikai szinergiái : NETWORKSHOP 2026 : 35. Országos Informatikai Konferencia : 2026. március 31-április 2. Debreceni Egyetem, Debrecen. Hungarnet Egyesület, Budapest, pp. 191-200. ISBN 9786156792297

[img]
Preview
Text
nws_2026_inpress_pfeiffer.pdf - Published Version
Available under License Creative Commons Attribution.

Download (778kB) | Preview

Abstract

A vezető techcégek kommunikációjában ma megszokott kijelentés, hogy a jelszó elavult módszer. Egyetértenek abban, hogy birtokalapú és/vagy biometrikus megoldásokkal kell alkalmazni. A „jelszómentesség” sokszor csak illúzió, a termékeladást segítő marketing- üzenet. Felvetjük, hogy a jelszavak teljes mellőzése hamis dogma, hiszen a biokulcsok és hardvertokenek gyakran megjegyezhető kódokra (PIN, recovery code) támaszkodnak. A CIA-háromszög, a Parkeri hatszög és a Kerckhoffs-elvek használatával mutatjuk be a részletek ismertetése nélkül, hogy a biometria és a birtokalapú megoldások számos biztonsági elvet sértenek/sérthetnek. Azt is bemutatjuk, hogy a jelszó nyújtotta entrópia modern aszimmetrikus protokollokkal (pl.: OPAQUE) ötvözve magasabb szintű kriptográfiai biztonságot nyújtanak az alapvető elvek betartása mellett. Érintjük a szabad, nyílt forráskódú szoftverek szerepét a technológiai szuverenitás és az auditálhatóság megőrzésében. A valódi kérdés tehát nem az, hogy alkalmazzuk-e a jelszavakat, hanem az, hogy mennyire közvetlen módon alkalmazzuk őket. Kitérünk arra a tapasztalatunkra, hogy az azonosítás és jogosultságvizsgálat a való világból kerül át a digitális térbe, és egyre inkább a digitális térbeli azonosítás határozza meg kilétünket. Így a nemzetállamok jogi és magánszemély-azonosítási monopóliuma a nagy techcégek és partnereik kezébe csúszik át. | In the messaging of leading tech companies, it is now a commonplace claim that the password is an obsolete method. They agree that it should be used with possession-based and/ or biometric solutions. „Passwordlessness” is often only an illusion – a marketing message that helps sell products. We argue that abandoning passwords entirely is a false dogma, since biometric keys and hardware tokens frequently rely on memorable codes (PIN, recovery code). Using the CIA triad, the Parkerian hexad, and Kerckhoffs’s principles, we show – without detailing the specifics – that biometric and possession-based solutions violate, or may violate, a number of security principles. We also present that the entropy provided by a password, combined with modern asymmetric protocols (e.g., OPAQUE), delivers a higher level of cryptographic security while respecting the fundamental principles. We touch on the role of free and open-source software in preserving technological sovereignty and auditability. The real question, therefore, is not whether we use passwords, but how directly we use them. We also reflect on our experience that identification and authorization are moving from the physical world into the digital space, and that digital-space identification increasingly determines who we are. As a result, the nation-states’ monopoly on legal and individual identification is slipping into the hands of the large tech companies and their partners.

Item Type: Book Section
Uncontrolled Keywords: NWS 2026, autentikáció, jelszó, jelszómentesség, biometria, technológiai szuverenitás, opaque protokoll, digitális identitás, CIA-háromszög, Parkeri hatszög, Kerckhoffs-elv, authentication, password, passwordless, biometrics, technological sovereignty, opaque protocol, digital identity, CIA triad, Parkerian hexad, Kerckhoffs’s principle, Networkshop 2026
Subjects: Q Science / természettudomány > QA Mathematics / matematika > QA75 Electronic computers. Computer science / számítástechnika, számítógéptudomány
SWORD Depositor: MTMT SWORD
Depositing User: MTMT SWORD
Date Deposited: 01 Aug 2026 06:31
Last Modified: 02 Aug 2026 14:51
URI: https://real.mtak.hu/id/eprint/243592

Actions (login required)

Edit Item Edit Item