The China Mail - Passwords under threat as tech giants seek tougher security

USD -
AED 3.672504
AFN 65.503991
ALL 83.072963
AMD 376.980403
ANG 1.790083
AOA 917.000367
ARS 1386.420402
AUD 1.448436
AWG 1.80025
AZN 1.70397
BAM 1.695072
BBD 2.009612
BDT 122.428639
BGN 1.709309
BHD 0.378163
BIF 2970
BMD 1
BND 1.2851
BOB 6.894519
BRL 5.160604
BSD 0.997742
BTN 92.939509
BWP 13.688562
BYN 2.956504
BYR 19600
BZD 2.006665
CAD 1.39475
CDF 2305.000362
CHF 0.79876
CLF 0.023281
CLP 919.250396
CNY 6.88265
CNH 6.886225
COP 3668.42
CRC 464.279833
CUC 1
CUP 26.5
CVE 96.000359
CZK 21.288304
DJF 177.720393
DKK 6.487804
DOP 60.850393
DZD 133.256954
EGP 54.334939
ERN 15
ETB 155.800822
EUR 0.86804
FJD 2.253804
FKP 0.757512
GBP 0.756401
GEL 2.68504
GGP 0.757512
GHS 11.00504
GIP 0.757512
GMD 74.000355
GNF 8780.000355
GTQ 7.632939
GYD 208.828972
HKD 7.83775
HNL 26.504427
HRK 6.539104
HTG 130.952897
HUF 333.930388
IDR 16994.6
ILS 3.130375
IMP 0.757512
INR 92.73995
IQD 1307.141959
IRR 1319175.000352
ISK 125.380386
JEP 0.757512
JMD 157.303566
JOD 0.70904
JPY 159.65404
KES 129.803801
KGS 87.450384
KHR 3990.137323
KMF 427.00035
KPW 899.995741
KRW 1511.260383
KWD 0.30934
KYD 0.831502
KZT 472.805432
LAK 21970.392969
LBP 89502.03926
LKR 314.804623
LRD 183.088277
LSL 16.955078
LTL 2.95274
LVL 0.60489
LYD 6.380628
MAD 9.374033
MDL 17.55613
MGA 4171.343141
MKD 53.495639
MMK 2099.82872
MNT 3572.765779
MOP 8.055104
MRU 39.637211
MUR 46.950378
MVR 15.460378
MWK 1730.071718
MXN 17.891704
MYR 4.031039
MZN 63.950377
NAD 16.954711
NGN 1378.130377
NIO 36.712196
NOK 9.77265
NPR 148.701282
NZD 1.750854
OMR 0.385097
PAB 0.997734
PEN 3.45194
PGK 4.316042
PHP 60.409504
PKR 278.39991
PLN 3.71375
PYG 6454.29687
QAR 3.638018
RON 4.416604
RSD 101.901662
RUB 80.325739
RWF 1457.240049
SAR 3.754558
SBD 8.038772
SCR 14.446904
SDG 601.000339
SEK 9.483104
SGD 1.286704
SHP 0.750259
SLE 24.650371
SLL 20969.510825
SOS 570.192924
SRD 37.351038
STD 20697.981008
STN 21.233539
SVC 8.730169
SYP 110.63796
SZL 16.948198
THB 32.635038
TJS 9.563492
TMT 3.51
TND 2.941459
TOP 2.40776
TRY 44.520504
TTD 6.768937
TWD 31.995038
TZS 2600.000335
UAH 43.698134
UGX 3743.234401
UYU 40.405091
UZS 12122.393971
VES 473.390504
VND 26340
VUV 119.00311
WST 2.766273
XAF 568.506489
XAG 0.013693
XAU 0.000214
XCD 2.70255
XCG 1.798209
XDR 0.708068
XOF 568.516344
XPF 103.361457
YER 238.650363
ZAR 16.972865
ZMK 9001.203584
ZMW 19.281421
ZWL 321.999592
  • RBGPF

    -13.5000

    69

    -19.57%

  • CMSD

    0.1100

    22.26

    +0.49%

  • BCC

    -1.8800

    73.2

    -2.57%

  • JRI

    0.0900

    12.61

    +0.71%

  • BCE

    -0.9300

    24.45

    -3.8%

  • BTI

    0.3900

    58.28

    +0.67%

  • GSK

    0.7000

    56.69

    +1.23%

  • NGG

    1.1500

    87.99

    +1.31%

  • CMSC

    0.0500

    22.04

    +0.23%

  • RELX

    0.3600

    33.59

    +1.07%

  • RIO

    -0.3600

    94.45

    -0.38%

  • VOD

    0.0800

    15.21

    +0.53%

  • AZN

    2.7600

    203.49

    +1.36%

  • RYCEF

    0.9000

    15.99

    +5.63%

  • BP

    0.9500

    47.12

    +2.02%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: © AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

E.Lau--ThChM