Back in 2004, Bill Gates said people would rely less and less on passwords, because they just don’t meet the challenge. And really, passwords, the world’s most common way of authentication, have been becoming obsolete over the past decade or so. Judging from numerous security incidents we can say that passwords aren’t doing their job nearly as effectively as they should.
In order to maintain appropriate security standards that regulate the protection of companies’ assets and employees, enterprises should focus on implementing more secure authentication methods.
The biggest caveat with passwords is that they simply cannot ensure a proper level of sensitive data security anymore. No matter how strange it may appear, many employees write down the passwords for their work accounts on sticky notes and attach them to their monitor screens or keep them in the drawers. Workers send passwords in plaintext via email and chat tools. 25% of workers said they shared passwords when asked by a college.
There are numerous examples demonstrating that passwords are easy to steal. In 2017, the Imgur image hosting and sharing service fell victim to a massive password compromise due to weak security protocols. As a result, 1.7 million account credentials were leaked.
This year, researchers have unveiled details on critical vulnerabilities dubbed Meltdown and Spectre that affect nearly all popular processing units and may cause large-scale credential leaks. Besides, security analysts have discovered the Zyklon malware that exploits loopholes in Microsoft applications to steal passwords.
Another problem with passwords is that users do not like to remember a huge number of alphanumeric characters and symbols. Different web services typically have different requirements in this regard, which, frankly speaking, makes the mission pretty much impossible. So, users reuse passwords or utilize simple passwords. Doing so increases the risk of being compromised.
Major organizations continue to use passwords at this point. However, quite a few alternative authentication methods have surfaced recently that may supersede passwords in the near future. Let’s take a look at these alternatives.
Security tokens
Software and hardware tokens guarantee a decent degree of security because they presuppose the availability of a certain extra element during authentication. Tokens aren’t connected to the Internet and instead generate one-time passwords based on what’s called the seed record synchronized with the central server. A lot of modern tokens don’t even require the user to enter any passwords manually as they use the NFC (near-field communication) technology.
In spite of the obvious benefits, implementing token-based authentication is a tedious process for businesses. First of all, it’s quite expensive, given that every employee needs to have a token of their own. Furthermore, carrying tokens at all times is a mandatory requirement for the employees to be able to authenticate in the enterprise system. Token, a company headquartered in New York, tries to solve this problem with its token ring.
Biometrics
Biometrics involves things like fingerprints and face recognition for authentication. This method became extremely popular after Apple integrated the Touch ID and Face ID features in their devices. One of the fundamental advantages of biometrics over the other authentication techniques is that it’s based on identifying what the user, essentially, is.
Biometrics delivers a better user experience, allowing users to authenticate much faster and more conveniently. Many tech giants are offering biometrics-based authentication solutions nowadays. Microsoft’s Windows Hello for desktop computers provides features for fingerprints and face recognition. The corporation intends to make Windows Hello compatible with a much wider range of devices in the future.
Biometrics has a few shortcomings, though. Many present-day biometric systems have issues with recognition accuracy and are quite expensive. Biometrics is susceptible to compromise, too. A study conducted by Japanese researchers demonstrated that some biometric data could be forged using high-resolution photos.
It’s also worth mentioning that the infrastructure behind biometrics has become decentralized over the past few years. It means there is no centralized database of biometric information that cybercriminals could steal. Therefore, the whole authentication workflow essentially boils down to exchanging the private and public key, so an adversary who gets hold of this key will also steal the victim’s identity without having to forge biometric data.
With all of these risk factors in place, no wonder that the National Institute of Standards and Technology doesn’t recommend using biometrics as the only authentication method in an enterprise.
Phone authentication (two-step authentication)
This category includes several authentication methods that are rapidly becoming many companies’ solutions of choice. Let’s have a look at three of these techniques relying on the use of mobile phones.
Applications that support push notifications
When a user queries a server, they instantly receive a message that contains an identity verification question or simply information about a successful login event. The main benefit of this method is its user-friendliness because there is no need to use one-time passwords or carry any devices all the time. This method only requires that the user responds to the push notification sent directly to their mobile device.
Mobile tokens
These ones resemble hardware tokens as far as their implementation is concerned. However, instead of relying on an extra device, this method uses a smartphone to generate a one-time password. This calculation routine involves such parameters as the smartphone’s clock and the algorithm built into a special app running on the device.
This technique has its cons as well, though. The fact that one-time passwords reside on a device connected to the Internet makes them potentially vulnerable to theft by cybercrooks.
SMS authentication
This method comes down to sending an SMS message containing a one-time password to the user’s device. This scheme was originally used alongside regular passwords, but since passwords can be reset via SMS, their value became questionable. As a result, many applications started using SMS as an alternative to passwords.
The most obvious advantage of this method is that the user doesn’t need to install any additional app onto their device. One of the most serious drawbacks is the relatively low reliability, because passwords sent via SMS may be compromised in several ways. The malefactor might pass himself off as the device owner, tamper with the mobile network, or infect the device with malware.
Conclusion
It’s within the realms of possibility that passwords will sink into oblivion quite soon. The tech giants have been busy creating alternative authentication methods lately, and the users are looking for a dependable substitute for passwords. Taking the pros and cons of every alternative technique into consideration, companies, and users can make an informed decision on the most suitable one. Perhaps a flawless authentication mechanism will be invented in the future, but in the meanwhile, our choice is restricted to the methods described above.