FB pixel

Poll shows broad support for passwordless authentication but risks fly under the radar

Categories Access Control  |  Biometrics News
Poll shows broad support for passwordless authentication but risks fly under the radar
 

Passwordless authentication is a “viable concept” for more than half (54 percent) of cybersecurity experts while 79 percent agree that passwords are evolving or becoming obsolete, according to a new survey interviewing attendees of the 2023 BlackHat USA cybersecurity conference.

Biometrics has become a popular choice for protecting passwords among cybersecurity experts: The majority of respondents (73 percent) said that they use multi-factor authentication (MFA) as an additional authentication method to secure their credentials and identity, with 57 percent saying that they use an authenticator app and 40 percent opting for biometrics.

Passkeys are also gaining traction, with 21 percent of respondents saying they already use them.

The poll was conducted by California-based access management company Delinea.

The survey is hardly representative of the wider business population. Delinea interviewed 100 business hall attendees of the cybersecurity conference, held last week in Las Vegas, U.S., including security team members, executives and IT administrators. But for Delinea’s Chief Security Scientist Joseph Carson the poll shows that “passwordless” is becoming more than a marketing term with easier additional forms of authentication pushing passwords into the background.

“This takes on increased significance when 75 percent of respondents also acknowledged that the fastest way to get access to a network is through social engineering or stolen identities and passwords,” says Carson. “The quicker organizations and end users alike can evolve their identity and access security beyond passwords, the safer we’ll be as a society.”

Not everyone is satisfied with current passwordless solutions, however, with some experts warning of misconfigurations and hidden app vulnerabilities.

Speaking during the BSides meetings, organized on the sidelines of the BlackHat Conference, Aldo Salas, application security lead at Hypr, noted that some passwordless implementations can be poorly configured, cybersecurity trade publication SC Media reports.

“Passwordless is not less secure than passwords,” Salas says. “But there are vulnerabilities, and nobody is talking about them.” Following the WebAuthn specification, for example, does not guarantee the security of access credentials.

Poor coding practices are also a major reason why security flaws can be missed during vulnerability scans and software composition analysis (SCA), according to Yotam Perkal, head of vulnerability research at Rezilion.

Article Topics

 |   |   |   | 

Latest Biometrics News

 

ID4Africa speakers urge legal identity inclusion for refugees, stateless persons

African governments must accelerate efforts to provide legal and digital identity to refugees and stateless populations, according to speakers at…

 

Biometrics lawyer Dan Saeedi talks BIPA on Biometric Update Podcast

Dan Saeedi is a BIPA buster. The renowned Chicago attorney, CIPP/US,a partner and team co-lead of the biometric privacy team…

 

World Bank, African DPAs outline formula for trusted digital identity, DPI

Trust has moved steadily to the center of the conversation around digital public infrastructure and identity at ID4Africa, and the…

 

UK watchdog warns of legal risks as London police deploy LFR at protest

London’s Metropolitan Police will deploy live facial recognition (LFR) technology at a protest for the first time this weekend, prompting…

 

Age assurance debate arrives in Bangladesh

The dominos continue to fall in the game of global online safety legislation targeting social media platforms. Bangladesh is weighing…

 

Et tu, browser? Security experts ring bell over browser fingerprinting

Your web browser wants you to think it’s on your side. It’s your helpful window into the online universe, and…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events