{"id":4717,"date":"2020-01-09T15:24:49","date_gmt":"2020-01-09T15:24:49","guid":{"rendered":"https:\/\/www.sagenet.com\/?post_type=insights&#038;p=4717"},"modified":"2020-01-09T15:58:22","modified_gmt":"2020-01-09T15:58:22","slug":"improving-cybersecurity-with-passwordless-authentication","status":"publish","type":"insights","link":"https:\/\/www.sagenet.com\/insights\/improving-cybersecurity-with-passwordless-authentication\/","title":{"rendered":"Improving Cybersecurity with Passwordless Authentication"},"content":{"rendered":"<div class=\"lead\"><span class=\"text-accent\">By Neil Christie<\/span><\/div>\n<div>\n<p>It\u2019s time to acknowledge that conventional cybersecurity practices are built upon a fundamental flaw \u2014 the password. Although companies around the world spend more than $100 billion a year on increasingly sophisticated security measures, industry analysts say poor password practices are the root cause of roughly 80 percent of all data breaches.<\/p>\n<p>It\u2019s time to ditch the password. SageNet is helping customers eliminate this weak link in the security chain with \u201cpasswordless\u201d authentication solutions that can substantially reduce the risk of phishing attacks, credential stuffing, account takeovers and other threats.<\/p>\n<p>The main problem with password security is that it places too much burden on end-users. You wouldn\u2019t ask your sales team or your marketing staff to configure firewalls, install an encryption solution or apply security patches. Yet, we think nothing of asking employees to assume responsibility for the critical first line of network defense.<\/p>\n<p>For years, security experts have stressed the importance of having employees create complex and unique passwords. That\u2019s simply not an effective strategy. The average business user today has nearly 200 unique passwords \u2014 a number that strains the limits of human memory and encourages a range of risky password practices. It\u2019s no wonder that \u201c123456\u201d and \u201cpassword\u201d consistently rank among the most commonly used passwords.<\/p>\n<p><strong>Password Repositories Targeted<\/strong><\/p>\n<p>However, even highly complex passwords with long combinations of letters, numbers and symbols are vulnerable. Companies often keep all employee passwords in a centralized vault or repository for easier management. Very often, passwords are stored in plain text. Hackers have targeted these central stores in several notorious breaches resulting in the theft of hundreds of millions of passwords.<\/p>\n<p>The easy availability of stolen credentials on dark web marketplaces have sparked a significant increase in credential stuffing attacks, which is essentially weaponized password reuse on a mass scale. It\u2019s a type of brute-force attack in which hackers use large numbers of stolen credentials to make multiple login attempts on multiple accounts simultaneously.<\/p>\n<p>These types of attacks have increased the urgency to reduce dependence on passwords. Gartner predicts that 60 percent of large and global enterprises and 90 percent of midsize enterprises will implement passwordless methods by 2022 \u2014 up from just 5 percent in 2018.<\/p>\n<p>There are a range of approaches for implementing passwordless authentication. All involve the use of some unique identifier such a biometric signature or a hardware token to establish proof of identity. They essentially use the same approach as digital certificates \u2014 a cryptographic key pair with a private and a public key.<\/p>\n<p><strong>An Easy and Secure Alternative<\/strong><\/p>\n<p>We recently partnered with <a href=\"https:\/\/www.hypr.com\/\" target=\"_blank\" rel=\"noopener noreferrer\">HYPR<\/a>, a New York-based provider of passwordless security solutions that shift authentication from a password database to the end-user\u2019s smartphone. Comcast, Mastercard and Samsung are among significant investors in HYPR, and Mastercard and Aetna are among notable customers.<\/p>\n<p>The HYPR solution is available as a mobile app or as a software development kit for rapid deployment across customer- and employee-facing applications. It enables secure desktop authentication for both Windows and Mac platforms, and it works with existing identity and access management (IAM) infrastructures.<\/p>\n<p>The solution is compliant with the Fast IDentity Online (FIDO) Universal Authentication Framework. FIDO standards enable easy and secure logins to websites and applications via device-based biometrics and security keys. FIDO\u2019s simpler login experiences are backed by strong cryptographic security that is superior to passwords, protecting users from phishing, password theft and replay attacks.<\/p>\n<p>While passwords won\u2019t be entirely replaced anytime soon, organizations need to take a hard look at their authentication tools and processes and move away from password-only data protection. With most data breaches linked to misused or stolen user credentials, it is clear that passwords no longer provide sufficient defense. Passwordless solutions can deliver more sophisticated and effective security while relieving end-users from much of their burden.<\/p>\n<p><a href=\"https:\/\/www.hypr.com\/\" target=\"_blank\" rel=\"noopener noreferrer\"><span class=\"text-secondary\">For more information on HYPR, visit them online.\u00a0<\/span><\/a><\/p>\n<\/div>\n","protected":false},"excerpt":{"rendered":"<p>One of the weakest links in online security is the password, with poor password practices accounting for nearly 80% of all data breaches. Minimize your risk. Ditch passwords altogether. <\/p>\n","protected":false},"author":59,"featured_media":4718,"template":"","tags":[],"insight_category":[],"class_list":["post-4717","insights","type-insights","status-publish","has-post-thumbnail","hentry","practice-area-sagesecure","practice-area-cybersecurity-consulting-services","practice-area-assessments-2","industry-area-healthcare","industry-area-hospitality","industry-area-public-safety","industry-area-finance","industry-area-restaurant","industry-area-c-store"],"acf":[],"ase":null,"_links":{"self":[{"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/insights\/4717","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/insights"}],"about":[{"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/types\/insights"}],"author":[{"embeddable":true,"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/users\/59"}],"version-history":[{"count":0,"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/insights\/4717\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/media\/4718"}],"wp:attachment":[{"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/media?parent=4717"}],"wp:term":[{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/tags?post=4717"},{"taxonomy":"insight_category","embeddable":true,"href":"https:\/\/www.sagenet.com\/wp-json\/wp\/v2\/insight_category?post=4717"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}