News: 1651777572

  ARM Give a man a fire and he's warm for a day, but set fire to him and he's warm for the rest of his life (Terry Pratchett, Jingo)

Microsoft, Apple, Google accelerate push to eliminate passwords

(2022/05/05)


Analysis Microsoft, Apple and Google – all longtime proponents of doing away with passwords for authentication purposes – are throwing their support behind standards developed by the FIDO Alliance and the World Wide Web Consortium (W3C) that could eliminate passphrases completely.

Sometime this year or early in 2023, the three US giants are set to implement these standards so that folks can log into online services and apps using familiar password-less authentication methods, such as the device PIN or fingerprint or face scans they use to unlock their devices, the FIDO – short for Fast Identity Online – Alliance announced Thursday.

We're talking, supposedly, consistent and easy to manage cross-platform authentication for software and websites that doesn't involve recalling passwords.

[1]

Microsoft, Apple and Google are among hundreds of tech companies and service providers that have worked with FIDO and W3C to develop these passphrase-free sign-in standards. The support from such high-profile tech companies and the promise to introduce these newly developed capabilities hopefully will accelerate their adoption, [2]according to Andrew Shikiar, executive director and CMO of the FIDO Alliance.

[3]

[4]

"This new capability stands to usher in a new wave of low-friction FIDO implementations alongside the ongoing and growing utilization of security keys, giving service providers a full range of options for deploying modern, phishing-resistant authentication," Shikiar said.

[5]FIDO Alliance says it has finally killed the password

[6]Would-be password-killer FIDO Alliance aims to boost uptake with new UX guidelines

[7]Cloudflare launches campaign to 'end the madness' of CAPTCHAs

[8]Microsoft promises end-to-end encrypted Teams calls for some, invites you to go passwordless with Azure AD

Passwords have been an ongoing security concern, particularly in the wake of the COVID-19 pandemic and the resulting shift to a constellation of remote services as well as hybrid work schedules. Microsoft believes there are 579 attacks involving passwords every second, or about [9]18 billion a year , and many of them are successful, mainly because people have a tendency to pick poor passwords or reuse them across multiple accounts.

In a report in early March, researchers with cybersecurity vendor SpyCloud found that users were continuing to [10]use the same passwords for multiple accounts as well as weak or common passwords. SpyCloud's [11]report found that 64 percent of users repeat passwords for more than one accounts and 70 percent of passwords that have been compromised in the past are still in use.

The bones of FIDO

FIDO has been pushing for the adoption of password-less methods for ten years through such technologies as USB hardware keys and – with W3C – the WebAuthn security specification. In March the two groups [12]unveiled another version of WebAuthn.

And so now we're told the people behind Office and Azure, iPhones and iCloud, and Chrome and Gmail will implement features newly standardized by FIDO and W3C that should make using non-password sign-in methods easier, including enabling users to automatically access their FIDO sign-in credentials – also known as "passkeys" – on their devices without having to re-enroll every account. Also, individuals should be able to use FIDO authentication on their mobile devices to sign into a website or application on a nearby computer using whatever operating system or browser they're running.

"The complete shift to a passwordless world will begin with consumers making it a natural part of their lives," Alex Simons, corporate vice president for identity program management at Microsoft, said about the latest FIDO and W3C-backed capabilities. "Any viable solution must be safer, easier, and faster than the passwords and legacy multi-factor authentication methods used today."

[13]

Password use isn't getting much better, Craig Lurey, co-founder and CTO of cybersecurity firm Keeper Security, told The Register The reliance of businesses and consumers on passwords is growing faster, due in large part to the shift to remote work and use of cloud services, he said. In addition, Lurey noted that for all its work, FIDO "does not address the need to encrypt the user data in a zero-knowledge and zero-trust environment."

Microsoft has been particularly vocal about doing away with passwords, and in September 2021 said users are able to remove passwords from their Microsoft accounts by instead using the Microsoft Authenticator app, Windows Hello, a security key, or a verification code sent to their mobile phone or email.

Mark Risher, senior director of product management at Google, said the vendors' work with FIDO and W3C "is a testament to the collaborative work being done across the industry to increase protection and eliminate outdated password-based authentication."

Playing the long game

The key for growing adoption of passwordless techniques starts with the device, where Microsoft, Apple and Google are dominant and have already implemented authentication mechanisms, Garret Grajeck, CEO of cybersecurity company YouAttest, told The Register .

"The onus then becomes on the security of these factors on the big three and then the security and implementation of the SSO from these devices to the relying parties – other web, mobile and on-premises applications," Grajeck said. "Given the problems we have with supply chain hacks and other hacks, it is not unforeseeable that more hacks will be occurring in this space."

Single-factor, passwordless login has too many functional, logistical, and security issues to become the norm overnight

Keeper Security's Lurey said it will take a number of steps – from vendors building technologies like multi-factor authentication into their websites and applications and users not only being educated about the technology and trusting it but also relying on their mobile devices – before adoption will accelerate.

"We'll still be using passwords for at least another decade," he said. "Single-factor, passwordless login has too many functional, logistical, and security issues to become the norm overnight."

[14]

John Gunn, CEO of authentication vendor Token, told The Register that "World Password Day is akin to National Running with Scissors Day. Both activities are inherently unsafe, with the latter being significantly safer based on statistical analysis.

"The security of passwords, or the lack of, has advanced only marginally over the 61 years since they were first implemented. It's time for us to collectively ... commit to eliminating passwords entirely." ®

Get our [15]Tech Resources



[1] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=2&c=2YnRJDik--XBRsXbRxYNhaAAAAMc&t=ct%3Dns%26unitnum%3D2%26raptor%3Dcondor%26pos%3Dtop%26test%3D0

[2] https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/

[3] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnRJDik--XBRsXbRxYNhaAAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[4] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnRJDik--XBRsXbRxYNhaAAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[5] https://www.theregister.com/2022/03/21/fido_password_killer/

[6] https://www.theregister.com/2021/06/24/wouldbe_passwordkiller_fido_alliance_aims/

[7] https://www.theregister.com/2021/05/14/cloudflare_cryptographic_attestation_of_personhood_captcha_killer/

[8] https://www.theregister.com/2021/03/03/microsoft_ups_security/

[9] https://www.microsoft.com/security/blog/2021/09/15/the-passwordless-future-is-here-for-your-microsoft-account/

[10] https://www.theregister.com/2022/03/02/passwords-weak-security-link/

[11] https://spycloud.com/resource/2022-annual-identity-exposure-report/

[12] https://www.theregister.com/2022/03/21/fido_password_killer/

[13] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=4&c=44YnRJDik--XBRsXbRxYNhaAAAAMc&t=ct%3Dns%26unitnum%3D4%26raptor%3Dfalcon%26pos%3Dmid%26test%3D0

[14] https://pubads.g.doubleclick.net/gampad/jump?co=1&iu=/6978/reg_security/cso&sz=300x50%7C300x100%7C300x250%7C300x251%7C300x252%7C300x600%7C300x601&tile=3&c=33YnRJDik--XBRsXbRxYNhaAAAAMc&t=ct%3Dns%26unitnum%3D3%26raptor%3Deagle%26pos%3Dmid%26test%3D0

[15] https://whitepapers.theregister.com/



Upgrade!!!!

Chris Gray 1

Am I being too cynical when I suggest that this is also about getting everyone to buy new devices to replace ones that are too old to support this new stuff. And, as I've seen elsewhere, its yet another grab for control and information by those large corporations?

Re: Upgrade!!!!

mark l 2

Yes and will probably only work on their big tech proprietary software, so the small guys and FOSS will get locked out of being able to support it.

Re: Upgrade!!!!

DS999

The "new stuff" this requires is bluetooth and some sort of biometric ID in your phone, so hardly a big leap.

The main roadblock is likely to be Android phones that are no longer getting updates, but that's partly the fault of the buyer for not choosing to buy from someone who supports their devices for a long time.

Re: Upgrade!!!!

jake

I've got all kinds of old kit still doing useful work. None of it will ever be downgraded to this new, about to be forced upon the rubes, "standard".

Thankfully, I see no need to do business with the likes of Microsoft, Apple, Google and their ilk ... Not now, and not into the foreseeable future. The Internet (and my old kit) will still be trucking along quite nicely long after they and their megalomaniacal ideas are dead and buried.

Re: Upgrade!!!!

Chris Gray 1

Would be nice. My phone is 8 years old. (Samsung Galaxy S4) I don't think many folks expect them to be used that long. But, it has a replaceable battery, earphone jack, etc. I like it. I just don't but any new apps on it. Ever.

Re: Upgrade!!!!

Anonymous Coward

Nothing like the big three colluding to discriminate against the disabled. I can't use pin numbers unless it corresponds with my very old army service number. My password manager deals with most logins by using the same default password. Any change that is thrust upon me is subject to the provisions in the Convention and in the Equality Act.

In short, will Alzheimers finish me before Microsoft does?

New ways to choose to fail?

Anonymous Coward

Through all of the discussion of this, I feel like what we have is a case of people pushing before the plan has been hashed out. While I have been hoping TOTP and FIDO would get on by default first party support from the big 3, I feel like this may not address some of the issues the way it is being discussed. I think we needed the big three to implement an authentication layer where alternates could replace all the places where just a password was allowed before. That way aps, devices, and organizations could adopt new methods without re-architecting their whole deployment(which has been the main thing holding everything else back).

Instead we are getting a hard push for what appears to be a swap of one inflexible baked in method for a newer one, which while it has it merits, will be behind the state of the art by the next major release of each of the operating systems.

Worse is Bluetooth. If you want to ensure something never quite works, build it on top of Bluetooth. Connections will be hit an miss, connection setup slower then necessary, and probably have to suffer repeated device pairing. Al least the security can be run over the top, so even if the bluetooth data was in the clear the FIDO drivers on the devices probably will handle security on their own.

Re: New ways to choose to fail?

LateAgain

You notice also that the assumption is that an actual person is there trying to do something.

Not a shared login (loads of those!) or a machine.

Asking a Linux server to pop up a weblogin to authorise something is daft.

Just give me an "app login" FFS

coping with device loss - print out this A4 sheet of random codes and keep it safe

Mark #255

I've recently begun enabling 2FA on a couple of accounts, and, while some bits are quite whizzy (point your phone at the QR code - woo), the recommended steps for ensuring you can still get into your account if your Authenticating Device is lost/stolen/rendered obsolete are somewhere on the "no normal person is going to do this" scale (I do fully accept that I'm not normal).

"Here's a bunch of codes: print them out and keep them safe" seems no more workable than "write the password on the back of an old business card and keep it in the box-o'-passwords"

Re: coping with device loss - print out this A4 sheet of random codes and keep it safe

simkin

It's awful. Our entire industry sucks.

And then your fingerprint scans get stolen.

simkin

Try replacing those.

Lispers are among the best grads of the Sweep-It-Under-Someone-Else's-Carpet
School of Simulated Simplicity. [Was that sufficiently incendiary? :-)]
-- Larry Wall in <1992Jan10.201804.11926@netlabs.com