The China Mail - Passwords under threat as tech giants seek tougher security

USD -
AED 3.673042
AFN 63.503991
ALL 82.403989
AMD 368.150403
ANG 1.790403
AOA 918.000367
ARS 1465.449815
AUD 1.42575
AWG 1.8025
AZN 1.70397
BAM 1.705709
BBD 2.013483
BDT 122.708482
BGN 1.69088
BHD 0.37702
BIF 2985
BMD 1
BND 1.290663
BOB 6.90816
BRL 5.152304
BSD 0.999721
BTN 94.239742
BWP 13.585663
BYN 2.777729
BYR 19600
BZD 2.010527
CAD 1.415225
CDF 2280.000362
CHF 0.807055
CLF 0.02293
CLP 902.460396
CNY 6.769604
CNH 6.783725
COP 3452.68
CRC 453.506829
CUC 1
CUP 26.5
CVE 96.403894
CZK 21.091104
DJF 177.720393
DKK 6.516504
DOP 58.403884
DZD 133.34504
EGP 49.986489
ERN 15
ETB 158.37504
EUR 0.871881
FJD 2.235504
FKP 0.756415
GBP 0.755512
GEL 2.650391
GGP 0.756415
GHS 11.22504
GIP 0.756415
GMD 73.503851
GNF 8775.000355
GTQ 7.625892
GYD 209.119888
HKD 7.83685
HNL 26.68504
HRK 6.568104
HTG 130.583803
HUF 306.820388
IDR 17826.3
ILS 2.95976
IMP 0.756415
INR 94.330504
IQD 1310
IRR 1375000.000352
ISK 125.530386
JEP 0.756415
JMD 157.959917
JOD 0.70904
JPY 161.30504
KES 129.403801
KGS 87.450384
KHR 4010.00035
KMF 429.503794
KPW 900.00035
KRW 1527.650383
KWD 0.30793
KYD 0.833035
KZT 487.855928
LAK 22055.000349
LBP 89550.000349
LKR 333.641485
LRD 182.150382
LSL 16.405039
LTL 2.95274
LVL 0.60489
LYD 6.375039
MAD 9.225039
MDL 17.654036
MGA 4200.000347
MKD 53.732839
MMK 2099.727916
MNT 3581.295381
MOP 8.070939
MRU 40.060379
MUR 47.850378
MVR 15.450378
MWK 1737.000345
MXN 17.326504
MYR 4.137904
MZN 63.910377
NAD 16.403727
NGN 1360.440377
NIO 36.610377
NOK 9.680204
NPR 150.787532
NZD 1.741735
OMR 0.384983
PAB 0.999725
PEN 3.384039
PGK 4.38775
PHP 60.716504
PKR 278.325038
PLN 3.71375
PYG 6138.96617
QAR 3.640504
RON 4.568104
RSD 102.170373
RUB 73.103247
RWF 1464
SAR 3.74824
SBD 8.061424
SCR 13.683262
SDG 600.503676
SEK 9.57882
SGD 1.292404
SHP 0.746601
SLE 24.750371
SLL 20969.503664
SOS 571.503662
SRD 37.402504
STD 20697.981008
STN 21.4
SVC 8.747449
SYP 110.532098
SZL 16.403649
THB 32.890369
TJS 9.272075
TMT 3.5
TND 2.91175
TOP 2.40776
TRY 46.438204
TTD 6.779085
TWD 31.715038
TZS 2630.985038
UAH 44.909735
UGX 3638.520172
UYU 39.96965
UZS 12005.000334
VES 606.63266
VND 26310
VUV 118.773512
WST 2.751708
XAF 572.078806
XAG 0.015419
XAU 0.00024
XCD 2.70255
XCG 1.801643
XDR 0.703697
XOF 565.000332
XPF 104.250363
YER 238.603589
ZAR 16.458037
ZMK 9001.203584
ZMW 17.919703
ZWL 321.999592
  • CMSC

    0.0500

    22.37

    +0.22%

  • CMSD

    0.0000

    22.29

    0%

  • RBGPF

    -0.5300

    60.61

    -0.87%

  • VOD

    -0.2300

    14.3

    -1.61%

  • NGG

    -1.2400

    79.44

    -1.56%

  • RELX

    -0.8300

    31.18

    -2.66%

  • RYCEF

    -0.0300

    18.4

    -0.16%

  • BCC

    3.8500

    74.66

    +5.16%

  • BCE

    0.0000

    23.28

    0%

  • RIO

    -2.5900

    100.08

    -2.59%

  • JRI

    0.0500

    12.67

    +0.39%

  • AZN

    -2.9600

    174.93

    -1.69%

  • GSK

    -1.4800

    50.67

    -2.92%

  • BTI

    -0.5800

    58.91

    -0.98%

  • BP

    -1.0400

    39.1

    -2.66%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: © AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

E.Lau--ThChM