FB pixel

HYPR argues for decentralized biometric credentials in enterprise white paper

Categories Access Control  |  Biometrics News
 

HYPR has published a white paper co-authored with Alan Goode of Goode Intelligence to help enterprises distinguish between passwordless systems that improve security from those intended for convenience. The “True Passwordless Security” report details how most companies that have adopted biometrics have not eliminated user passwords, and have been left vulnerable to credential stuffing and reuse attacks, according to the announcement.

Password breaches and credential stuffing attacks are at an all-time high, HYPR says, and reliance on centralized passwords makes companies vulnerable to a range of attack types, including phishing, social engineering credential theft, account takeover, payment fraud, prepaid product cash-out scams, loyalty fraud, and large-scale data breaches.

“Credential stuffing attacks are on the rise. Akamai’s report found over 8 billion malicious login attempts in mid 2018. That’s a massive problem worth focusing on and with so many enterprises moving away from passwords, it’s important for us to ensure the industry takes the right approach in adopting true password-less security,” said George Avetisov, CEO of HYPR Corp.

Password elimination has received significant attention from analysts and vendors, and recent surveys have indicated public attitudes may have reached a tipping point, but the report suggests that some early efforts to reduce their use have fallen short.

“This is a really important study as many organizations that think they are going password-less are in fact still using their legacy centralized password solutions. The user experience may have a feeling of being password-less but in fact they are just leveraging what is on the phone to unlock the credential (usually a password) that gets verified exactly the same way as the existing password system. It’s like putting on a new door for an old house,” said Alan Goode, CEO & Chief Analyst of Goode Intelligence.

To remedy the situation, the report defines criteria for a password-less architecture, identifies security risks associated with centralized credential storage, and argues for decentralized authentication as a convenient way to deliver true password-less security at scale.

The report is available for free download from HYPR’s website.

HYPR expanded its operations to the UK and EU earlier this year.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Canada regulator backs privacy-preserving age assurance

The Office of the Privacy Commissioner of Canada (OPC) has published a policy note and guidance documents pertaining to age…

 

FCC seeks comment on KYC revision for commercial phone calls

The U.S. Federal Communications Commission (FCC) has proposed stronger KYC requirements for voice service providers to prevent scams and illegal…

 

Deepfake detection upgrade for Sumsub highlights continuous self-improvement

Sumsub has launched an upgrade to its deepfake detection product with instant online self-learning updates to address rapidly evolving fraud…

 

Metalenz debuts under-display camera for payment-grade face authentication

Unlocking a smartphone with your face used to require a camera placed in a notch or a punch hole in…

 

UK regulators pan patchwork policy for law enforcement facial recognition

The UK’s two Biometrics Commissioners shared cautionary observations about the use of facial recognition in law enforcement over the weekend…

 

IDV spending to hit $29B by 2030 as DPI projects scale: Juniper Research

Spending on digital identity verification (IDV) technology is projected to reach a 55 percent growth rate between now and 2030,…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events