News: 1646233213

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

The zero-password future can't come soon enough

(2022/03/02)


Passwords, long a weakness in the tapestry of defenses designed to keep enterprises and individuals more secure, continue to be a problem due in large part to the same issue that has haunted them for years: the users themselves.

In a report released today, SpyCloud researchers found that despite the growing sophistication of bad actors and the headlines surround cyberattacks, many users continue to use poor hygiene when it comes to passwords, including using the same or similar passwords for multiple accounts or weak or common passwords.

In addition, more than two-thirds of passwords that have been breached in previous years are still in use, according to the [1]2022 SpyCloud Identity Exposure Report . The company found that 64 percent of consumers repeat passwords for more than one account and 70 percent of passwords that have been compromised are still in use.

[2]

The data in SpyCloud's report dovetails with what other cybersecurity vendors are seeing. Lookout recently [3]published a list of the passwords that are most commonly found on the dark web, with the top four being 123456, 123456789, Qwerty and Password.

[4]

[5]

Passwords have long been an issue in security, particularly as more work and business is being done online. Consumers now can have more than 100 accounts in work and personal lives that need passwords. The rapid shift to remote work brought on by the COVID-19 pandemic has only accelerated that trend. Most people will not only continue to work from home at least part of the time even as the pandemic lifts but have also gotten used to doing more of their personal business online. ®

Such reports as those from SpyCloud and Lookout only add to fuel to the argument being made by some vendors – with [6]Microsoft among the leaders – that passwords should be dropped in favor of a number of other alternatives, such as biometric technology (such as fingerprint or eye scans), security keys, authentication apps or verification codes that are sent to a mobile device or email.

[7]

"At a basic level, everyone understands the logic at least behind picking a complicated, hard-to-guess password when you register for an account," David Endler, co-founder and chief product officer of SpyCloud, told The Register. "However, in practice, especially looking at some of the data in our report, it's clear that bad password habits are still very much prevalent. Part of it is laziness. Another part of it is a sense of the average consumer of, 'Why would someone go to the trouble to target little or me? What's interesting about me?'"

There will always be specific attacks targeted at individuals or companies, but weak passwords also contribute to practices by threat actors like credential stuffing, where cybercriminal use usernames and passwords stolen from one website to try to log into other, often using botnets to fuel the efforts, Endler said. The attackers can then steal credit card data, make fraudulent purchase and use the information in phishing attempts. They can also sell the information.

In all, researchers from SpyCloud – whose products help prevent account takeovers by bad actors – identified 1.7 billion exposed credentials in 2021, a 15 percent year-over-year increase, and 13.8 billion recaptured personally identifiable information (PII) record stolen during breaches last year.

[8]

The issue of passwords is a sticky one. Authenticator apps, security keys or text messages sent to a cell phone are techniques that have been around for years. However, what they're running up against are habits consumers have built up over decades.

"What we're dealing with as a society is there is this built-up muscle memory around creating an account and logging into sites in the enterprise," he said.

[9]Intel's 12th-gen Alder Lake processors will not include Microsoft's Pluton security

[10]New flashpoint: US may ask Chinese tech firms to bin Russia

[11]President Biden calls for ban on social media ads aimed at kids

[12]Second data-wiping malware found in Ukraine, says ESET

Two-factor authentication also has been available on sites for years, but adoption is slow because not all people want to take that second step. However, Endler pushed back at the idea that the campaign for passwordless authentication has stalled.

"These things take time because for decades, this is how we've known to create our accounts, to register our accounts and to log into our accounts and to see change like this does take time," Ender said. "It also does add friction into the online account creation space. I don't know that all sites are enthusiastically embracing this technology because they have to weigh that and counter that with user friction."

There are steps a person can take, including enabling two-factor authentication – which also can be used with biometric technologies – to sites they use and using a password manager to not only store all of their passwords but also to generate unique passwords to those sites. To protect against fraud and protect PII, people should review their credit history and lock down their records at the major credit agencies.

Anything people do will help protect enterprises, particularly at a time when remote work continues to blur the line between work and home life.

"One way to think of it is the enterprise attack surface hasn't changed," he said. "It's just the way we think about it has changed a little bit since we've all been working from home the last two years. At home, we have many more devices right in front of us than we may use to access corporate resources. Those devices don't necessarily have the same benefits of corporate endpoint protection, so we've seen actually more and more malware infections for people working from home."

While using an infected device, they may log into the corporate system, illustrating the overlay between threats to consumers and the enterprise attack surface, particularly when factoring in the various applications people are using that are outside of the organization's protective shield, Endler said, adding that "if someone is using a personal account on one of those systems and is maybe not picking the best password, then it does have a have a ripple effect onto the corporate attack surface."

Eventually the charge into a passwordless future will likely be led by device manufacturers and browser developers, he said. Sites likely will continue to integrate technologies from either devices or browsers, which should help reduce the threats.

"But keep in mind a lot of the accounts that come out in these data breaches were created years ago," Endler said. "We're still years away from that dream because we would have to catch up to the point where people are only registering new accounts using services like Apple's Hide My Email."

Get our [13]Tech Resources



[1] https://spycloud.com/resource/2022-annual-identity-exposure-report/

[2] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2Yh@itbHMi68fG@NF900DxgAAAMQ&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[3] https://www.cnbc.com/2022/02/27/most-common-passwords-hackers-leak-on-the-dark-web-lookout-report.html

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yh@itbHMi68fG@NF900DxgAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[5] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yh@itbHMi68fG@NF900DxgAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[6] https://www.microsoft.com/security/blog/2021/09/15/the-passwordless-future-is-here-for-your-microsoft-account/

[7] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44Yh@itbHMi68fG@NF900DxgAAAMQ&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[8] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/front&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33Yh@itbHMi68fG@NF900DxgAAAMQ&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[9] https://www.theregister.com/2022/03/02/microsoft_pluton_chip/

[10] https://www.theregister.com/2022/03/02/china_us_russia_sanctions_tangle/

[11] https://www.theregister.com/2022/03/02/state_of_the_union_2022_tech_policy/

[12] https://www.theregister.com/2022/03/01/ukraine_wiper_apple_visa_mastercard/

[13] https://whitepapers.theregister.com/



Hubert Cumberdale

Until we reach this magical passwordless future, everyone should use [1]KeePassXC .

[1] https://keepassxc.org/

Paul Crawford

For most accounts simply using the web browser's option is enough. But of course you have the "computer replaced/wiped and I can't login any more!" problem for most folks who lack a proper backup of that.

Pascal Monett

If everyone is using the same tool, then everyone is at risk as soon as some miscreant finds a way into it.

Just sayin'.

RE: risks

Snake

My concern is if you depend upon this single technology, the password manager, to either generate or remember your unique passwords. Even if you allowed your browser to auto-generate a random password, what happens if the manager crashes? Corrupt database? Failed SSD with poor backup regimen (all too common on home users)? Etc, etc, etc.

fidodogbreath

BitWarden is another solid open-source option.

2FA problem

Paul Herber

One problem I've found with 2FA not relying on a password is having the wrong phone number attached to the account. I have a Paypal account like this, all I'm asked for is to respond to the 4-digit code sent to a phone number, which I no longer have access to, it's now a dead number. I can't even get as far as using the password, or any of the secret answers. I've spent an hour on the phone with Paypal support, the one thing they can't change is the phone number. Blah. There's only a few tens of pounds in the account, but it could be so much worse.

Re: 2FA problem

Anonymous Coward

But that's bad 2FA. Or lazy at least.

Even MS, Google and Facebook allow you to generate a set of codes for that moment you've lost your device.

A much bigger- and much less addressed issue - are the man+dog outfits that insist on one login per account which forces you to share it among key staff. Which renders a lot of data security directives null and void before you've started. (If you read them that is).

DarkRookie

Biometrics are immutable,

Security keys are expensive,

Authentication apps are usually made by people I wouldn't trust with codes. Or keeping the app updated.

Verification codes take too long.

If you want to replace the password, replace it with something that can do the same things.

Arthur the cat

Biometrics are immutable

One hopes they're immutable because changing them often tends to involve a hospital visit.

Charlie Clark

Everyone knows that good passwords should only be used once…

As you say, we've yet to come up with anything better that is as universal.

Paul Crawford

Is your no-longer-patched phone authenticator more secure than a paper record of good passwords kept at home (especially if 'modified' in written form)?

If your phone or key fob is lost/stolen how easy is it to replace it and keep all logins still working? Could the bad guys do the same?

Yes, 2FA helps a lot, but not so much if accessing a site from the same device (e.g. phone web and text/app), also some sites like Feacesbook can go jump if they think I'm handing phone numbers over to them!

Adrian 4

Relying on a phone that may be compromised, discharged or out of signal is asinine. I have no confidence in vendors that use it for 2FA. I have the same expectation of security and usabilty in phone-based systems as reused passwords.

Doctor Syntax

Unfortunately if you do want to practice "good password hygiene" it seems that businesses are seeking to make things more difficult. I've just signed up with a different building society which I've wasted half the morning over trying to set up a log-in & now discovered it seems to assume I'll use a mobile app to confirm on-line use. Of all the electronic devices in the house the mobile phone is the one I trust least. For those who don't have their phone surgically attached to their face it's also about the least convenient means to use any service as it's apt to be off/flat/left in the car/somewhere else in the house when it's needed.

I doubt this growing reliance by businesses on assuming their customer have (that cuts out SWMBO anyway) and prefer to use a smartphone is nothing to do with security or customer convenience. It's for their convenience and, I suspect, especially the convenience of their marketing departments.

fidodogbreath

@Paul Crawford: If anyone who has your phone number has ever installed any Faecesbook app, then Faecesbook already has your number -- and all of your other contact info associated with it.

Keeping customers happy....NOT!

Anonymous Coward

Quote: "...text messages sent to a cell phone are techniques that have been around for years..."

Yup....but just to quote NatWest as an example:

(1) Request a text message for authentication on the Nat West web site

(2) The NatWest web site TIMES OUT before the text message arrives!!!

Yup...."around for years"....and the CORPORATE END of the solution DOES NOT WORK!!

Keeping customers happy?? Guess!!!

"the charge into a passwordless future"

Pascal Monett

This charge had better have a solution that is as easy to manage as passwords are.

It's not my fault that the Joe User can't be arsed to manage his passwords properly.

I do, and I do not want my fingerprints, eye scans or tongue surface spread all across corporate databases managed by the summer intern.

If one of my passwords gets compromised, I can change it. I can't change my fingerprints.

So, what's the passwordless solution ? I haven't heard of one yet and, if somebody had an actual solution, I'm sure we'd be hearing about it and seeing it implemented already.

Re: "the charge into a passwordless future"

alain williams

If one of my passwords gets compromised, I can change it. I can't change my fingerprints.

+1

Re: "the charge into a passwordless future"

thejoelr

I went to their website expecting some product and didn't find one surprisingly.

Re: "the charge into a passwordless future"

Martin Gregorie

So, what's the passwordless solution ? I haven't heard of one yet and, if somebody had an actual solution, I'm sure we'd be hearing about it and seeing it implemented already.

Devices like the Yubico dongles seem to work painlessly enough, at least when used for passwordless access to sites like GitLab.

However they they do have drawbacks, such as their price and availability, being small enough to lose easily unless you've attached them to a fob of some sort, and requiring the device you use them with to have a USB socket .

karlkarl

I am going to assume by passwordless they mean that terrible "SMS the user a one time password" crap rather than proper asymmetrical encryption keys like SSH.

Passwordless

vtcodger

I am going to assume by passwordless they mean that terrible "SMS the user a one time password"

Probably. Most likely what they really mean is that they haven't any more idea than anyone else how to balance security versus usability, so they'll go with whatever is popular. And what's popular today is 2FA using SMS with one time codes that are a monumental PITA for many (very likely most) users. But they can pretend that's a user problem, so it's someone else's problem and therefore OK.

Personally, I was paying bills on line 30 years ago. But about 25 years ago, I came to feel that computer security is so difficult that paper was not only safer, but overall probably less effort. It's REALLY hard to straighten things out on-line on the rare occasions when things go wrong. I do keep a couple of minor conventional accounts with passwords and 2FA. If they ever become both secure and easy/convenient to use, I'll consider going fully digital. I do not expect that to happen any time soon.

Yubi keys?

Anonymous Coward

https://www.yubico.com/

Anonymous Coward

I know it's not exactly a web browser or anywhere mainstream, but the Gemini protocol uses a client certificate to define who they are. You can either create a new (self signed) certificate to act as a 'session cookie', or keep hold of it and be identifiable again. The user is in control of its lifetime and could even store it somewhere portable/cloudy.

Any stone in your boot always migrates against the pressure gradient to
exactly the point of most pressure.
-- Milt Barber