FB pixel

Hypr passwordless report uncovers pervasive insecure authentication practices

Hypr passwordless report uncovers pervasive insecure authentication practices
 

Passwordless security is still a relatively new approach to user authentication in the workplace despite a decade of identity standards work by the FIDO Alliance and W3C to democratize these capacities. In the third-annual State of Passwordless Security Report published by Hypr there are several key findings that uncover just how pervasive insecure authentication practices are among organizations.

While passwordless adoption is on the rise, so are phishing attacks. For example, 97 percent of organizations that use passwordless authentication for employees (n=271) are using phishable methods, and 28 percent of organizations (n=1000) experienced push notification phishing attacks, which more than doubled the number in the prior years’ report.

Perhaps worse is that organizations indicate, on average, that four different systems of authentication are used by employees daily and the majority rely on passwords, password managers, and phishable multi-factor authentication (MFA) methods. And nearly all organization — 97 percent allow at least a portion of their employees to access their company computers with only a username and password. Yet, 87 percent of these same IT and security leaders consider their organization’s existing approach to authentication to be completely or mostly secure.

As the report outlines, this conundrum appears to be rooted in the fact that 65 percent of those surveyed were unable to identify the difference between phishable versus phishing-resistant MFA. Phishing-resistant multi-factor authentication is based on public-key cryptography and uses secure, on-device factors to verify identity. It does not use any type of credential that could be phished or intercepted by attackers including passwords, one-time passcodes (OTP), SMS messages, push notifications, phone calls, and knowledge-based security questions.

It is clear from the survey results and findings that more education is needed around phishing-resistant MFA but that alone will not solve the primary issue in the workplace that starts with the operating system and device makers.  The report concludes on a note about Passkeys, which replace passwords with a cryptographic key pair and on-device authentication announced by Apple, Google and Microsoft, however, for the near-term Passkeys still lack the critical administration, configuration, policies, and management capabilities for deployment in the workplace.

Article Topics

 |   |   |   |   | 

Latest Biometrics News

 

Opinions on UK Online Safety Act emphasize importance of enforcement

Online safety legislation is making headlines around the world. But in places where laws have taken effect, are they proving…

 

UK Home Office raises estimate for passport contract to 12 years, £576M

The UK Home Office has opened a third round of market engagement for its next major passport manufacturing and personalization…

 

US lawmakers move to restrict AI chatbots used by kids

A bipartisan pair of House and Senate bills would impose new federal restrictions on AI chatbots, including a ban on…

 

Utah age assurance law for VPN users takes effect this week

Privacy advocates and virtual private network (VPN) providers are up in arms over Utah’s Senate Bill 73 (SB 73), “Online…

 

CLR Labs wins ISO 17025 accreditation for biometrics testing across EU

Cabinet Louis Reynaud (CLR Labs) has been accredited for ISO/IEC 17025, the international standard for testing and calibration laboratories, in…

 

Leidos, Idemia PS advance checkpoint modernization with biometrics, CAT-2 systems

Leidos and Idemia Public Security have formed a strategic partnership to deploy biometric‑enabled eGates and integrated Credential Authentication Technology (CAT-2)…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events