How the “new, safer and simpler log-in” works at the USPTO?

click to enlarge

I’ve received many questions from people who have tried to use the “new, safer and simpler log-in” for PAIR and EFS-Web.  (See the big blue footer that now appears whenever you try to use PAIR.)  Here’s what one very experienced USPTO customer asked me:

Last week I set up two-factor authentication with MyUSPTO, following the USPTO’s instructions.  Recently the big blue banner started appearing and I figured I had better start using the newer, safer and simpler log-in.  So today I needed to e-file form SB39 in one of my cases.  This is my time to try out the newer, safer and simpler log-in, right?  I logged in at the USPTO web site using my MyUSPTO user ID and password.  So far, so good.  Over on the right side, it says “File patents with EFS Web”.  So now that I have logged in, I click there and I reach the “unregistered e-filers” page.  There are some links but none of them will get me to the “registered” EFS-Web.  Finally I give up on MyUSPTO and I click on the old-fashioned link on the upper left and I click on “eFile (registered)” and that got me to the familiar old Entrust Java Applet page.  I e-filed my form SB39.

When that was done I went back to the MyUSPTO home page again hoping to figure out how I might have gotten to the “registered” EFS-Web page.  What did I miss?

Being smart about TOTP (time-based one-time password)

A long time ago the way to log in was with a user ID and password.  Then people started using two-factor authentication (2FA or “something you have, and something you know”).  USPTO’s particularly poor choice for 2FA was the Entrust Java Applet.  After a while some organizations started using a text message on a cell phone as the second factor.  This turns out to be a really poor choice as well because it is very easy to hack.

The smart way to do this nowadays is TOTP (time-based one-time password).  For most people the way you do this is to install an authenticator app onto your smart phone, and you scan a QR code.  The app displays a six-digit code that changes every thirty or sixty seconds.  The code is the second factor.

Things you need to do today if you are a USPTO patent practitioner

You’ve received the scary emails from USPTO, and the scary pop-up messages in PAIR, saying that “you will need to use a newer, safer, and simpler log-in … beginning in October 2018”.

There are some things that you really need to do now (if you have not already done so) if you are a USPTO patent practitioner.  Each human being in your office needs to get a MyUSPTO user ID and password (if he or she has not already done so).  Each human being in your office needs to set up TOTP with that user ID (if he or she has not already done so).  And you need to attend some upcoming webinars in which USPTO will try to explain all of this very clearly.

Oppedahl Patent Law Firm LLC listservs are working again

I am delighted to be able to report that the Oppedahl Patent Law Firm LLC listservs are working again.  Just now I successfully migrated the listservs from a previous hosting provider to a new hosting provider.

Industrial Designs and more test cars

click to enlarge

It’s test car time of year again for Summit County, Colorado.  Here are ten of the approximately sixty camouflaged cars swarming around the streets and highways and the mountains of Colorado this week.  They are testing next year’s car models to see how they perform in the thin air at an elevation of 9000 feet (2700 meters) or higher.

It’s not only that camouflage wrap is laid onto the cars.  There are also fake body panels and bumps and contours taped into place under the camouflage wrap.

This is all to protect the industrial designs — postponing for as long as possible the day when a competitor will get to see exactly what next year’s models look like.

One month remaining to sign up for PCT seminar in Silicon Valley

One month remains, folks, to sign up for my PCT seminar that will take place in Silicon Valley, California, on October 16-18, 2018.

Oppedahl Patent Law Firm Listservs are broken

Update:  The listservs are working again.

I’ve learned that our listservs (email discussion groups) are broken.

Our listservs are hosted by a hosting company in Boulder, Colorado.  The hosting company of course provides services to others besides us.  I did some troubleshooting, and I see that the IP address from which the listserv emails get sent has gotten blacklisted by one of the spam blacklisting services.

The blacklisting service has good intentions, of course.  The service tries to notice patterns of email sending so that spammers can be identified and blocked.

I’d guess that some new customer of the hosting company started sending spam.

Now the hosting company will have to figure out which new customer is sending the spam, and shut them down.  And then the hosting company will have to ask the blacklisting service to re-evaluate the email traffic for the IP address.   And eventually the IP address will be removed from the blacklist.  And then our listservs will start working again.
