News: 1588811465

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

So you've set up MFA and solved the Elvish riddle, but some still think passwords alone are secure enough

(2020/05/07)


About a third of firms and organisations in Europe, the Middle East and Africa still believe the humble password is a good enough security measure, according to a survey carried out by French firm Thales.

Moreover, two-thirds of the 400 IT professionals quizzed indicated "that their organisations plan to expand use of usernames and passwords in the future".

The findings come as a contrast to [1]yesterday's survey , which showed that the majority of people (as opposed to companies) don't really care about good password hygiene and cheerfully reuse the same one everywhere they digitally go.

Thales, which [2]bought secure mobile phone SIM card biz Gemalto in 2017 , reckoned that over half (57 per cent) of IT pros it polled said that unsecured infrastructure was the most likely attack surface. With that in mind, password-protecting that sort of infrastructure makes more sense than simply leaving it open for any curious or malicious bod to poke around within.

Francois Lasnier, veep of access management solutions at Thales, opined: "Often, in an effort to adapt to the new working habits of users connecting from anywhere, which is increasingly pertinent right now and will become standard moving forward, businesses tend to revert back to old password-based logins for cloud services in despair. This is knowingly increasing their security exposure to credential stuffing and phishing attacks."

Thales, which, among other things, sells access management software, reckoned that its 400 respondents said the amount of staff training on security and access management, increasing spend on access management, and access management becoming a board priority "have all seen an increased focus".

Last year French-owned Thales [3]flogged off hardware security module biz nCipher following its Gemalto acquisition, a sale demanded by competition regulators.

Password security is an ongoing bugbear for security folk. NordVPN found [4]in a survey earlier this year that tens of thousands across the world were using such Fort Knox-style gems as "pakistan", "onedirection" and "superman". ®

Sponsored: [5]Forrester Build a Digital Experience Portfolio



[1] https://www.theregister.co.uk/2020/05/05/logmein_password_survey/

[2] https://www.theregister.co.uk/2017/12/18/gemalto_acquired_by_thales/

[3] https://www.theregister.co.uk/2019/02/22/thales_sells_ncipher_for_gemalto_buyout/

[4] https://www.theregister.co.uk/2020/02/05/one_direction_is_a_rubbish_band_and_password/

[5] https://go.theregister.co.uk/tl/1936/-8554/forrester-build-a-digital-experience-portfolio?td=wptl1936

Just make a really long password

Blackjack

Requirements of sending a text message to confirm is you is really stupid because SMS tech is so unsafe is ridiculous.

... tens of thousands across the world were using such Fort Knox-style gems

macjules

Remind me not to use NordVPN: if they can access their users' passwords.

You can drive a horse to water, but a pencil must be lead.