Passwordless
The Future of Authentication
Security & Usability for the Digital Transformation
To achieve transformative business objectives, stay competitive and meet user expectations, enterprises are undergoing a digital transformation, also known as modernization. This shift to a decentralized, identity-centric operational model has placed increased importance on ensuring secure access for users. The future of authentication demands both a secure and usable method of authorizing users to both cloud and on-premises systems.
!
The origin of the password arrived in the mid-1960s at the Massachusetts Institute of Technology (MIT) with the development of the Compatible Time-Sharing System (CTSS), according to Computer History and Wired. It allowed hundreds of users to share the computer with a common mainframe. The password was developed as an accounting tool to allow users access to their specific resources for a certain amount of time.
The password as primary authentication and multi-factor authentication (MFA) as secondary authentication became imperative as password theft and data breaches became routine. The 60-year-old single-factor password simply hasn’t stood the test of time. In 2019, an anonymous creator released 2.2 billion usernames and passwords across attacker forums, known as the largest collection of breaches at that time.
In the last two decades, multi-factor authentication (MFA) has matured as a secondary authentication providing an additional layer of security. Advances in secondary factors, including the proliferation of smartphones and the consumerization of biometrics, have led many to question the reliance on passwords altogether.
By 2022, 60% of large and global enterprises, and 90% of midsize enterprises (MSEs), will implement passwordless methods in more than 50% of use cases, which is an increase from fewer than 5% today. — Gartner Market Guide for User Authentication
The Problem With Passwords
- Costly Management: Passwords consume a lot of IT and help desk support time, making them costly to manage. Large organizations have allocated over $1 million annually for password-related support costs.
- User Experience: The number of cloud services a user needs to log into has increased significantly, leading to an average business user logging in with as many as 190 passwords.
- Easy to Compromise: Password threats such as credential stuffing, phishing, and brute-force attacks are rampant. A significant statistic shows that 81% of breaches involve stolen or weak credentials.
What is Passwordless Authentication?
Passwordless authentication establishes a strong assurance of a user's identity without relying on passwords, allowing users to authenticate using biometrics, security keys, or mobile devices. The benefits include better user experience and stronger security posture by eliminating reliance on passwords, thus reducing related threats.
The Challenge: A Nascent Market
Many passwordless vendors only solve for specific use cases, risking security gaps. It is essential to find solutions that support both legacy and cloud applications while providing a consistent user experience. Supporting passwordless technology might involve substantial costs and compliance challenges due to existing regulations.
The Solution: Path to Passwordless
- Identify Use Cases: Reduce reliance on passwords as the only form of user authentication and open up additional factors later for primary authentication.
- Streamline Workflows: With MFA in place, change password policies to reduce user frustration related to password security.
- Increase Trust: Implement adaptive access policies based on the context to ensure that authentications are trusted.
- Provide Passwordless Experience: Utilize biometric authenticators and security keys for logging in.
- Optimize Toolset: Move towards a comprehensive solution eliminating reliance on passwords across all use cases.
What You Can Do Today
Pairing passwordless technology with strong MFA can help provide security coverage across cloud and on-premises systems. Passwordless authentication enhances workforce experience while establishing a zero-trust architecture, critical for securing access in a mobile and cloud-first enterprise.
Building for a Passwordless Future
Duo is committed to building a secure access platform that enables a fully passwordless future through partnerships with technology platforms and support for hardware-based biometric authenticators, thus paving the way to passwordless authentication.