Is A Passwordless Future A More Secure Future?

Following the news that the UK has introduced the worlds-first law banning weak passwords, minimum security standards must now be enforced by manufacturers of all internet connected devices. The Telecommunications (Security) Act mandates stricter cybersecurity measures for smart devices to protect consumers.

Manufacturers are now required to eliminate default passwords, establish a security issue reporting point of contact for consumers and disclose the minimum duration for which the device will receive important security updates.

While this legislation is a step in the right direction, it begs the questions, what can we do to better secure our first line of defence? 

The Perils of Poor Password Hygiene 

Password negligence has far-reaching implications, especially for businesses. With over 23 million people using simplistic passwords like ‘123456’, the stakes are alarmingly high. Such lax security can unravel an organisation, leading to data breaches, ransom demands, and irreparable damage to customer trust. In fact, just a single weak password can open the floodgates to wide-ranging cyberattacks. For instance, recent attacks on major organisations like Okta and 23AndMe were facilitated by stolen login details, demonstrating the widespread impact and ongoing threat posed by weak password practices.

From phishing exploits to brute-force attacks, the techniques used by cybercriminals are evolving. With advancements in AI, hackers now harness machine learning algorithms to predict and crack passwords more swiftly than ever, exploiting every chink in our digital armour.

This escalation in attack capability necessitates the adoption of passwords that are not only longer, but also more complex.

The Possibility Of A Passwordless Future

The role of traditional passwords amidst the advent of biometric authentication is a subject of lively debate among security experts. While some advocate for completely abandoning passwords in favour of biometric solutions—such as fingerprints or FaceID—and modern alternatives like Google Passkey for their convenience and enhanced security, others support the continued use of password managers or a combination of methods. Despite advances in authentication technology, traditional passwords remain prevalent across various platforms.

Biometric authentication, while secure, has a significant drawback: once compromised, biometric data cannot be changed. This vulnerability can lead to irreversible identity theft. In contrast, traditional passwords can be frequently updated to prevent unauthorised access following a security breach.

Furthermore, many individuals and industries still depend on passwords to access critical services, such as email and personal accounts. However, there is a noticeable shift toward passwordless authentication, especially in sectors with rigorous security needs like banking and corporate communications. This shift includes the adoption of hardware tokens, multi-factor authentication using alternate devices, and one-time verification pins, offering secure access without traditional passwords.

Remove Reliance On Passwords 

Executives need to enact and enforce good cybersecurity practices. The best way to do that is to reduce the reliance you have on passwords alone. This means organisations need to adopt other authentication methods to reduce the chances of becoming overwhelmed. For example, by combining multiple account protection solutions such as two-factor authentication with biometrics, you will lower the chances of a successful attack while at the same time, helping to improve the overall security posture in your organisation. 

Businesses could also consider using Single Sign-On (SSO), which allows a user to authenticate themselves on multiple, separate platforms via a single ID. This solution negates the need for several different passwords. There is an element of risk, but by combining SSO with multi-factor authentication you can add a second layer of protection. 

Essential Password Hygiene

To strengthen password security, I would recommend the following best practices:

1.    Complexity and Length:  Create passwords with a mix of numbers, letters, and symbols, aiming for 12-16 characters to enhance security. Ensure the password is unique to you and avoid using easily guessed personal details like birthdays or anniversaries.

2.    Unique Passwords for Different Accounts: Avoid reusing passwords across multiple platforms. Use memorable phrases or sentences, like 'meryhadalittlelamb', or a more secure variant with special characters '#M3ryHad@L1ttleL4m8'. There are solutions available that prevent the reuse of corporate passwords on external sites and protecting against phishing and malware.

3.    Use a password manager:  Sometimes having a password is a mandatory requirement, so you cannot rely on other authentication methods alone. Conduct an evaluation to decide if a password manager would be appropriate for your organisation. Password managers have several benefits. They allow your employees to securely store credentials, generate unique passwords and they can auto-complete fields on websites. This removes the reliance on remembering hundreds of passwords or writing them down for anyone to see.  

4.    Implement security tools to prevent credential harvesting:  Always enable MFA to add an additional layer of security. This ensures that even if a password is compromised, unauthorised access is still blocked. Employ encryption protocols to safeguard sensitive data during transmission.

Regularly update and patch software to mitigate vulnerabilities that could be exploited by cyberattacks. Additionally, educate users on recognising phishing attempts.

By proactively integrating these security measures, you fortify your defences against credential harvesting and enhance the overall security posture of your online presence.

5.    Implement an account monitoring solution:  You can only protect what you can see, so it’s important that you have visibility of all accounts that have been compromised by an attack. Otherwise, how are you going to make improvements to stop an attack from happening again? This is why you need to review the default account settings and turn on features like locking an account after certain attempts. You don’t want an attacker to have unlimited time or an unlimited number of login attempts, allowing them to force their way into your organisation. 

By adhering to these guidelines, individuals and organisations can significantly enhance their digital security posture.

The Takeaway 

In the current cyber environment, an attack is inevitable. However, preventing an attack is possible with the right combination of technologies and security protocols. Put simply, action must be taken now to keep your accounts safe.

Given that poor password hygiene and the resulting impact can damage an organisation’s reputation beyond repair, companies need to treat this situation with the level of seriousness it demands. 

Muhammad Yahya Patel is a Security Engineer and member of the Office of the CTO at Check Point. 

Image: Unsplash

You Might Also Read: 

How Poor Password Hygiene Could Unravel Your Business:

___________________________________________________________________________________________

If you like this website and use the comprehensive 6,500-plus service supplier Directory, you can get unrestricted access, including the exclusive in-depth Directors Report series, by signing up for a Premium Subscription.

  • Individual £5 per month or £50 per year. Sign Up
  • Multi-User, Corporate & Library Accounts Available on Request

Cyber Security Intelligence: Captured Organised & Accessible


 

« Using AI To Defend Against AI-Enhanced BEC Scams
LockBit Resurrection »

CyberSecurity Jobsite
Perimeter 81

Directory of Suppliers

The PC Support Group

The PC Support Group

A partnership with The PC Support Group delivers improved productivity, reduced costs and protects your business through exceptional IT, telecoms and cybersecurity services.

Clayden Law

Clayden Law

Clayden Law advise global businesses that buy and sell technology products and services. We are experts in information technology, data privacy and cybersecurity law.

TÜV SÜD Academy UK

TÜV SÜD Academy UK

TÜV SÜD offers expert-led cybersecurity training to help organisations safeguard their operations and data.

LockLizard

LockLizard

Locklizard provides PDF DRM software that protects PDF documents from unauthorized access and misuse. Share and sell documents securely - prevent document leakage, sharing and piracy.

CYRIN

CYRIN

CYRIN® Cyber Range. Real Tools, Real Attacks, Real Scenarios. See why leading educational institutions and companies in the U.S. have begun to adopt the CYRIN® system.

Lloyd's

Lloyd's

As an insurance market, Lloyd’s can provide access to more than 65 expert cyber risk insurers in one place.

IABG

IABG

IABG offer independent, product-neutral consulting as well as technical and scientific services for the use of safety-relevant systems and technologies.

SAI360

SAI360

SAI360 (formerly SAI Global) provide products and services for enterprise risk management including Governance, Risk & Compliance and Digital Risk solutions.

Altron

Altron

Altron provides locally relevant innovative and integrated ICT solutions to business, government and consumers.

Farsight Security

Farsight Security

Farsight Security provides the world’s largest real-time actionable threat intelligence on how the Internet is changing.

Conviso

Conviso

Conviso is a consulting company specialized in Application Security and Security Research.

German Israeli Partnership Accelerator (GIPA)

German Israeli Partnership Accelerator (GIPA)

GIPA is based on two pillars: it is an incubator aimed at young academics and a program to transfer cybersecurity expertise to corporate partners.

Corsha

Corsha

Corsha is on a mission to simplify API security and allow enterprises to embrace modernization, complex deployments, and hybrid environments with confidence.

Carve Systems

Carve Systems

Carve Systems was founded to bring enterprise level information security, training, and risk management services to organizations of any size and industry.

Netizen

Netizen

Netizen is an award-winning company that develops and leverages innovative solutions to enable a more secure cyberspace for clients in government and commercial markets.

Avetta

Avetta

Avetta One is the industry’s largest Supply Chain Risk Management (SCRM) platform. It enables clients to manage supply chain risks and suppliers to prove the value of their business.

Laneden

Laneden

Laneden specialise in helping organisations identify security concerns and quantify the risks you may have across your assets, using Penetration Testing, Threat Simulation and Compliance Testing.

ITC Federal

ITC Federal

ITC Federal delivers IT cybersecurity assessment services to support agencies in meeting their security strategies and federal security compliance goals.

Velum Labs

Velum Labs

Velum Labs is a cyber intelligence company that provides simple and non-intrusive, cloud and cyber intelligence solutions; built from a market-leading understanding of cyber-attack methodology.

IndoSec

IndoSec

IndoSec is an annual cybersecurity summit that powers an in-person gathering of cybersecurity leaders from Indonesia’s major corporations, leading businesses and key government entities.

Black Duck Software

Black Duck Software

Black Duck (formerly the Synopsys Software Integrity Group) is the market leader in application security testing (AST).