The Prague Post - Passwords under threat as tech giants seek tougher security

EUR -
AED 4.246644
AFN 74.005922
ALL 96.265326
AMD 436.123466
ANG 2.069937
AOA 1060.360225
ARS 1598.689495
AUD 1.673775
AWG 2.08285
AZN 1.988068
BAM 1.972639
BBD 2.327881
BDT 141.810522
BGN 1.976535
BHD 0.436611
BIF 3427.379034
BMD 1.156336
BND 1.492137
BOB 7.986172
BRL 5.987965
BSD 1.155771
BTN 109.980818
BWP 15.944102
BYN 3.437039
BYR 22664.179845
BZD 2.324442
CAD 1.608272
CDF 2642.226678
CHF 0.921582
CLF 0.027136
CLP 1071.471881
CNY 7.963164
CNH 7.961846
COP 4259.455081
CRC 537.389586
CUC 1.156336
CUP 30.642896
CVE 110.863691
CZK 24.5467
DJF 205.503695
DKK 7.472507
DOP 69.496203
DZD 154.08251
EGP 63.140551
ERN 17.345036
ETB 181.602368
FJD 2.610315
FKP 0.876547
GBP 0.87223
GEL 3.110636
GGP 0.876547
GHS 12.719346
GIP 0.876547
GMD 85.569097
GNF 10146.845711
GTQ 8.843528
GYD 241.875744
HKD 9.063301
HNL 30.754786
HRK 7.528677
HTG 151.694897
HUF 384.268277
IDR 19655.394337
ILS 3.628929
IMP 0.876547
INR 108.251477
IQD 1514.799775
IRR 1521593.247438
ISK 143.397549
JEP 0.876547
JMD 182.85085
JOD 0.819848
JPY 183.470036
KES 150.324057
KGS 101.121607
KHR 4636.906277
KMF 495.487973
KPW 1040.672847
KRW 1743.453202
KWD 0.358024
KYD 0.963121
KZT 550.660545
LAK 25381.569304
LBP 103502.574163
LKR 364.613993
LRD 212.389924
LSL 19.738949
LTL 3.414358
LVL 0.699456
LYD 7.406339
MAD 10.803067
MDL 20.468725
MGA 4831.170578
MKD 61.591507
MMK 2427.7246
MNT 4129.285061
MOP 9.332604
MRU 46.380777
MUR 54.10502
MVR 17.888809
MWK 2008.555118
MXN 20.690083
MYR 4.668704
MZN 73.947626
NAD 19.738948
NGN 1600.403533
NIO 42.471566
NOK 11.181067
NPR 175.969107
NZD 2.013099
OMR 0.444626
PAB 1.155766
PEN 4.042522
PGK 5.07607
PHP 69.688304
PKR 322.845343
PLN 4.28678
PYG 7486.909717
QAR 4.213698
RON 5.097015
RSD 117.393505
RUB 94.009327
RWF 1688.250131
SAR 4.340218
SBD 9.299295
SCR 16.534366
SDG 694.958363
SEK 10.915173
SGD 1.486839
SHP 0.867551
SLE 28.387646
SLL 24247.794113
SOS 660.848203
SRD 43.216918
STD 23933.81449
STN 25.121393
SVC 10.113373
SYP 127.838758
SZL 19.738534
THB 37.748595
TJS 11.078065
TMT 4.058738
TND 3.387824
TOP 2.784178
TRY 51.442948
TTD 7.852061
TWD 36.907956
TZS 2990.065557
UAH 50.776558
UGX 4351.161172
USD 1.156336
UYU 46.890264
UZS 14102.102747
VES 547.268077
VND 30457.882506
VUV 139.157306
WST 3.20221
XAF 661.604585
XAG 0.015529
XAU 0.000247
XCD 3.125055
XCG 2.082981
XDR 0.8221
XOF 659.691044
XPF 119.331742
YER 275.9598
ZAR 19.553517
ZMK 10408.420696
ZMW 22.092587
ZWL 372.339626
  • CMSC

    -0.4028

    21.9

    -1.84%

  • RIO

    4.4700

    93.29

    +4.79%

  • CMSD

    -0.4000

    22.1

    -1.81%

  • JRI

    0.3800

    12.3

    +3.09%

  • RBGPF

    -13.5000

    69

    -19.57%

  • BCE

    0.0100

    25.24

    +0.04%

  • NGG

    0.9100

    84.6

    +1.08%

  • BCC

    0.9000

    75.85

    +1.19%

  • BTI

    0.2100

    58.47

    +0.36%

  • AZN

    3.3400

    197.22

    +1.69%

  • GSK

    0.9600

    55.19

    +1.74%

  • RYCEF

    0.7400

    15.09

    +4.9%

  • VOD

    0.3200

    15.02

    +2.13%

  • RELX

    0.4000

    33.15

    +1.21%

  • BP

    -0.3500

    47

    -0.74%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: Chris Delmas - AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

I.Horak--TPP