Berliner Boersenzeitung - Passwords under threat as tech giants seek tougher security

EUR -
AED 4.280203
AFN 77.000073
ALL 96.57559
AMD 443.823316
ANG 2.086262
AOA 1068.739166
ARS 1671.282351
AUD 1.755774
AWG 2.097853
AZN 1.98038
BAM 1.956318
BBD 2.346322
BDT 142.527767
BGN 1.954785
BHD 0.439375
BIF 3442.01206
BMD 1.165474
BND 1.5091
BOB 8.050133
BRL 6.360338
BSD 1.164909
BTN 104.741102
BWP 15.477101
BYN 3.349173
BYR 22843.286986
BZD 2.342911
CAD 1.610941
CDF 2601.337209
CHF 0.937187
CLF 0.027427
CLP 1075.962229
CNY 8.240016
CNH 8.238437
COP 4478.461378
CRC 569.050786
CUC 1.165474
CUP 30.885056
CVE 110.295172
CZK 24.239177
DJF 207.444969
DKK 7.468665
DOP 74.559757
DZD 151.547804
EGP 55.36114
ERN 17.482107
ETB 180.69398
FJD 2.630941
FKP 0.873749
GBP 0.874746
GEL 3.140953
GGP 0.873749
GHS 13.251455
GIP 0.873749
GMD 85.079658
GNF 10122.638857
GTQ 8.923479
GYD 243.723536
HKD 9.068365
HNL 30.68213
HRK 7.537128
HTG 152.500409
HUF 382.475294
IDR 19452.9819
ILS 3.756907
IMP 0.873749
INR 105.10185
IQD 1526.097836
IRR 49081.01224
ISK 148.982371
JEP 0.873749
JMD 186.459408
JOD 0.826376
JPY 181.18333
KES 150.637314
KGS 101.920781
KHR 4664.235923
KMF 491.829497
KPW 1048.92586
KRW 1710.636421
KWD 0.357768
KYD 0.970853
KZT 589.13358
LAK 25261.585409
LBP 104320.495171
LKR 359.323672
LRD 205.036969
LSL 19.743447
LTL 3.441342
LVL 0.704984
LYD 6.332678
MAD 10.759551
MDL 19.821167
MGA 5196.37693
MKD 61.591075
MMK 2447.025873
MNT 4134.371135
MOP 9.341635
MRU 46.45531
MUR 53.751762
MVR 17.95086
MWK 2020.035266
MXN 21.197224
MYR 4.795336
MZN 74.485711
NAD 19.743447
NGN 1690.751905
NIO 42.871176
NOK 11.786181
NPR 167.583406
NZD 2.015885
OMR 0.448105
PAB 1.165009
PEN 3.915838
PGK 4.943289
PHP 68.783904
PKR 326.59264
PLN 4.230548
PYG 8012.123043
QAR 4.24628
RON 5.089639
RSD 117.393521
RUB 89.601892
RWF 1694.949126
SAR 4.375093
SBD 9.59254
SCR 15.753107
SDG 701.037435
SEK 10.947267
SGD 1.511124
SHP 0.874407
SLE 27.621604
SLL 24439.401222
SOS 664.576099
SRD 45.02106
STD 24122.955112
STN 24.506389
SVC 10.193657
SYP 12886.454671
SZL 19.728228
THB 37.129082
TJS 10.68857
TMT 4.090813
TND 3.41735
TOP 2.806181
TRY 49.586523
TTD 7.897872
TWD 36.329569
TZS 2855.410928
UAH 48.906159
UGX 4121.074317
USD 1.165474
UYU 45.56266
UZS 13936.752734
VES 296.673618
VND 30723.638259
VUV 141.443193
WST 3.250054
XAF 656.130861
XAG 0.019942
XAU 0.000277
XCD 3.149751
XCG 2.099547
XDR 0.816016
XOF 656.130861
XPF 119.331742
YER 278.023491
ZAR 19.796503
ZMK 10490.655378
ZMW 26.933137
ZWL 375.282096
  • RBGPF

    0.0000

    78.35

    0%

  • CMSC

    -0.0500

    23.43

    -0.21%

  • NGG

    -0.5000

    75.41

    -0.66%

  • CMSD

    -0.0700

    23.25

    -0.3%

  • RIO

    -0.6700

    73.06

    -0.92%

  • RELX

    -0.2200

    40.32

    -0.55%

  • SCS

    -0.0900

    16.14

    -0.56%

  • GSK

    -0.1600

    48.41

    -0.33%

  • VOD

    -0.1630

    12.47

    -1.31%

  • RYCEF

    -0.0500

    14.62

    -0.34%

  • AZN

    0.1500

    90.18

    +0.17%

  • BTI

    -1.0300

    57.01

    -1.81%

  • BCC

    -1.2100

    73.05

    -1.66%

  • BCE

    0.3300

    23.55

    +1.4%

  • BP

    -1.4000

    35.83

    -3.91%

  • JRI

    0.0400

    13.79

    +0.29%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: Chris Delmas - AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

(S.G.Stein--BBZ)