Shadow

Will 2017 Bid Adieu To Password Authentication Systems For Biometrics

Are you a supporter of the campaign to eliminate passwords like FIDO (Fast IDentity Online) Alliance executive director Brett McDowell, Nok Nok Labs CEO Phil Dunkelberger, Palo Alto Networks senior group manager Scott Simkin, and several more big names who believe this might be the year a new generation of authentication technology is compulsorily required.

Will-2017-Bid-Adieu-To-Password-Authentication-System-For-Biometrics

The support team believes the new authentication technology should be largely based on bio metrics. The new standards need to be defined by a massive collaboration of hundreds of companies.

The security problems with passwords are known for past few years and it is well documented too. Its paradigm was never designed for cases of modern society. Also, only technology just not compromise the passwords to hackers, but users too opt for short, simple passwords mostly like “admin,” “12345,” “password,” etc. Users even make mistakes by using same user name and password for several sites to overcome hassle of remembering few dozens of those.

However, it is not to forget passwords are an embedded part of authentication systems and is still used by many popular websites including McDowell, which says it will take much time for password to disappear.

Will-2017-Bid-Adieu-To-Password-Authentication-System-For-Biometrics

Simkin said, “We have decades of legacy systems and behavior to change, and it will take years for the industry to catch up.”

It is also not to forget the cyber criminals have been able to find a way around every advance in security technology. Even though the biometric credentials like voice recognition, iris scans and fingerprints are hard for attackers to hack compared to passwords, but these may not be a magic bullet. If ways can be found to crack these, it will become more difficult to change or update compared to updating passwords.

There have been several reports of biometric spoofing. About a year ago it was learned fingerprint data could be stolen from Android devices. It is important to know fingerprint sensor usually guard by system privilege instead of root. This makes targeting easier.

Japan’s National Institute of Informatics (NII) discovered a high quality digital image of people can help attackers in making a contact lens of the iris to help them pass authentication. Similarly voice recording of a person can also trick the authentication systems.

It is said the attackers may also steal the phone or computer as biometric credential data never leaves the devices.

However, if multi-factor authentication is used, it would be far tough for hackers to get access of data.

Leave a Reply

Your email address will not be published. Required fields are marked *