Login Revolution.
Smart authentication with Qypher, using only QR.

Change Daymode and Nightmode
En

Why Qypher matters, right now.

A column series about the news surrounding passwords, and about the everyday mechanism we call "login."
We'll avoid technical jargon where we can, and add to it a little at a time.
Part 1

📰Another "password leak" headline. It's not someone else's problem.

Reports of "tens of thousands of personal records leaked" now appear almost every year. Much of the blame lies with the password itself.

News that personal data has leaked from a large service is, unfortunately, no longer rare. The causes cited again and again are "reused passwords," "passwords that are too simple," and "passwords stolen through phishing."

This isn't solely due to users being careless. The password itself, as a mechanism, demands that a human keep a secret that is "long, complex, different for every service — and still memorable." With the number of services we use only growing, doing this perfectly is close to impossible. When a password leaks from one service, the damage cascades into every other service where that same password was reused — and that is why so many breaches end up doing so much damage.

Qypher has no "password" to leak in the first place

Logging in with Qypher involves no password — no string of characters a person has to memorize. All you use is a single Qypher card with a QR code printed on it. Accidents unique to passwords — "a memorized secret gets stolen," "a reused secret leaks" — simply cannot happen within this design.

Of course, this doesn't mean "with Qypher, nothing can ever go wrong." If you lose your Qypher card, reissuing a new one immediately disables the old one from that moment on. What matters is the design itself — one where no human has to carry around a secret that would cause trouble if it leaked. We'll go deeper into this way of thinking about security later, in article four.

Part 2

🔗How is it different from "Sign in with Google"? Qypher as another option

Social login is genuinely convenient. Rather than replacing it, Qypher aims to be another option that serves a different purpose.

Social login options like "Sign in with Google" or "Sign in with Apple" are a convenient mechanism used across many sites. Being able to log in right away with an account you already have is a real advantage.

Qypher isn't trying to compete with this mechanism — it aims for a different position altogether. Social login ties you to an account on a specific major platform. Qypher, on the other hand, is an independent authentication mechanism that also works for people who aren't a member of any particular platform, or who simply feel "I'd rather not hand all my identifying information to one company."

What Qypher values

  • Neutrality: It works as a standalone login method, without depending on any one company's account.
  • Versatility: A single Qypher card can be used across multiple, unrelated services that support Qypher.
  • Transparency: You can check and choose, each time, exactly what data gets passed to the site you're logging into.

This isn't about which one is "better." We believe that having more options to choose from — depending on the situation and the values that matter to you — is a good thing, both for users and for site operators.

Part 3

👨‍👩‍👧Protecting children from online risks. Qypher's guardian authentication

Age verification and guardian authentication aren't just restrictions — they're a mechanism to protect children and families.

Now that using the internet is simply a part of daily life, incidents where children accidentally access age-restricted services, or end up making unintended, high-value purchases, are increasingly being raised as a social issue.

Qypher's age verification and guardian authentication

Qypher verifies age based on a registered date of birth, and for users under a certain age, it's designed to require guardian authentication or consent. This means a site never has to "build its own identity- and guardian-verification mechanism from scratch," which makes it far easier for consideration for children's safety to spread across more services.

For guardians too, it becomes easier to keep track of which services their child is logging into, reducing the risk of a child wandering, without anyone noticing, into a place unsuited to their age.

One shared mechanism, leading to peace of mind for society as a whole

If age verification and guardian authentication can exist as a shared mechanism, rather than being built separately by every single service, consideration for protecting children can spread across the entire industry far more smoothly. What Qypher aims to be is the foundation for that kind of virtuous cycle.

Part 4

🛡️Just how "hard to break" is Qypher's design?

Here's a look, with technical jargon kept to a minimum, at the thinking behind how Qypher stays strong against outside attacks.

Just being told "it's safe" may not be enough to put your mind at ease. Here, we'll explain, as plainly as possible, the way of thinking behind how Qypher stays robust.

No "secret" worth stealing exists in the first place

As we mentioned in article one, logging into Qypher involves no password that a person memorizes. Because there's no "secret" for an attacker to target in the first place, common attack methods — stealing a password, guessing one, exploiting a reused one — simply don't apply.

Even in a worst case, nothing is stored in a usable form

Qypher's database never stores authentication-related information in a form that can be reversed back to the original. What's kept is only data that has gone through a one-way transformation — one that can't be computed back to its original value. Personal information such as names and addresses is likewise stored in encrypted form. So even if part of the data were to end up in the wrong hands, it couldn't be extracted in a form that's directly usable.

Generation left to machines — not something you can guess

The information used for login isn't generated from predictable factors like the date and time — it's produced by a cryptographically secure random number generator. Because it isn't a string a human thought up, there's no pattern to guess your way to it.

Qypher's security doesn't rest on "keeping the mechanism secret" — it's supported by a design that, as shown here, holds up even when made public. If you're interested in the technical details, please also take a look at our page for engineers, "How it's secure."

Get your free Qypher card
See Qypher basics
Consider adding it to your site
Sign in
Qypher Sitemap
Qypher Home
Why Qypher
For users
For site owners
How it's secure
Column
Usage
How to use Qypher
How to implement Qypher
Usage fees
Plan list
Registration information
Member registration
Sign in
Personal information
Operating company
Company information
Terms of Use
Privacy policy
Notation based on the Act on Specified Commercial Transactions
Support
Support Form
AbuseIPDB Contributor Badge
↼ Back to top