The Prague Post - Passwords under threat as tech giants seek tougher security

EUR -
AED 4.311308
AFN 77.879699
ALL 96.688625
AMD 447.85425
ANG 2.101831
AOA 1076.505607
ARS 1707.192072
AUD 1.771749
AWG 2.116032
AZN 2.004043
BAM 1.960029
BBD 2.365855
BDT 143.653019
BGN 1.953335
BHD 0.442548
BIF 3472.941475
BMD 1.173943
BND 1.516572
BOB 8.116825
BRL 6.487208
BSD 1.17466
BTN 105.980932
BWP 15.522957
BYN 3.44641
BYR 23009.283073
BZD 2.362488
CAD 1.61659
CDF 2658.980767
CHF 0.932175
CLF 0.027414
CLP 1075.132381
CNY 8.268374
CNH 8.256711
COP 4552.175346
CRC 585.275311
CUC 1.173943
CUP 31.10949
CVE 110.505791
CZK 24.374112
DJF 209.179364
DKK 7.471085
DOP 73.810833
DZD 152.347317
EGP 55.85943
ERN 17.609145
ETB 182.685082
FJD 2.68158
FKP 0.876785
GBP 0.875256
GEL 3.163731
GGP 0.876785
GHS 13.508665
GIP 0.876785
GMD 86.289333
GNF 10269.376903
GTQ 8.996604
GYD 245.759696
HKD 9.134096
HNL 30.939417
HRK 7.539412
HTG 153.845228
HUF 388.315726
IDR 19601.326503
ILS 3.771187
IMP 0.876785
INR 105.831725
IQD 1538.752932
IRR 49434.739984
ISK 148.256896
JEP 0.876785
JMD 187.949541
JOD 0.832281
JPY 182.512335
KES 151.325623
KGS 102.661551
KHR 4704.150133
KMF 491.882164
KPW 1056.541668
KRW 1729.911202
KWD 0.360331
KYD 0.978812
KZT 606.047668
LAK 25437.862305
LBP 105190.301042
LKR 363.434181
LRD 207.916591
LSL 19.695216
LTL 3.466348
LVL 0.710107
LYD 6.366873
MAD 10.76626
MDL 19.809743
MGA 5282.600749
MKD 61.565611
MMK 2465.347298
MNT 4164.683572
MOP 9.414875
MRU 46.891176
MUR 54.048218
MVR 18.137736
MWK 2036.873034
MXN 21.110661
MYR 4.796681
MZN 75.013881
NAD 19.695216
NGN 1711.831956
NIO 43.224185
NOK 11.945563
NPR 169.565872
NZD 2.030951
OMR 0.451385
PAB 1.17468
PEN 3.955018
PGK 5.063032
PHP 68.760173
PKR 329.125553
PLN 4.206828
PYG 7842.087857
QAR 4.283634
RON 5.091398
RSD 117.391899
RUB 93.919441
RWF 1710.190073
SAR 4.403142
SBD 9.54441
SCR 15.974055
SDG 706.125134
SEK 10.912516
SGD 1.513958
SHP 0.880761
SLE 28.295168
SLL 24617.002332
SOS 670.145972
SRD 45.405775
STD 24298.250206
STN 24.553502
SVC 10.278397
SYP 12981.890755
SZL 19.700508
THB 36.915847
TJS 10.847922
TMT 4.108801
TND 3.433408
TOP 2.826573
TRY 50.16658
TTD 7.970401
TWD 36.996574
TZS 2913.082074
UAH 49.613608
UGX 4196.143368
USD 1.173943
UYU 46.0303
UZS 14165.867329
VES 324.27969
VND 30904.049841
VUV 142.484873
WST 3.269096
XAF 657.375417
XAG 0.017908
XAU 0.000271
XCD 3.172639
XCG 2.116968
XDR 0.815819
XOF 657.389447
XPF 119.331742
YER 279.809222
ZAR 19.703518
ZMK 10566.886439
ZMW 26.723686
ZWL 378.009172
  • RBGPF

    -1.7900

    80.22

    -2.23%

  • CMSC

    0.0800

    23.34

    +0.34%

  • SCS

    0.0200

    16.14

    +0.12%

  • RIO

    0.4100

    77.6

    +0.53%

  • BTI

    0.1140

    57.284

    +0.2%

  • AZN

    0.9200

    90.78

    +1.01%

  • BCC

    0.2600

    76.55

    +0.34%

  • NGG

    -0.4800

    76.68

    -0.63%

  • GSK

    -0.1900

    48.52

    -0.39%

  • CMSD

    0.0000

    23.28

    0%

  • RYCEF

    0.6100

    15.38

    +3.97%

  • JRI

    0.0010

    13.431

    +0.01%

  • RELX

    0.2150

    40.775

    +0.53%

  • BP

    -0.8550

    33.615

    -2.54%

  • VOD

    0.0650

    12.875

    +0.5%

  • BCE

    -0.1810

    22.969

    -0.79%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: Chris Delmas - AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

I.Horak--TPP