Passwords have been a huge pain point for many people, including my clients! Fortunately for everyone, I ran into some good news. Apple, Microsoft, and Google have expressed support for FIDO’s (Fast Identification Online) movement for passwordless sign-on. Before we get into the details on how that will work, let’s do a quick overview of the current state of passwords.

Accompanying video for those who prefer to watch instead!

Current state of passwords

Everyone knows by now that there is no shortage of websites, portals, or apps asking you to create an account to do business with them. There are several reasons they do this:

  • Allow access to member only content
  • Allow payment, order tracking
  • Track user details for marketing purposes
  • Etc.

Outside of the user tracking, these reasons don’t pose much of a concern to most people. The problem lies with the sheer number of places you’re required to have accounts with. When you add the growing number of data breaches and companies trying to be more secure, the end users get hit the hardest.

Good password hygiene and cybersecurity practices say to have a different password for each account and 2FA activated wherever possible. But even in 2022, I see people repeating passwords or using variations of passwords. This is a huge issue.

If you repeat passwords and a place like Facebook gets hacked, and they’ve been hacked in the past, then that means hackers can get into ALL your other accounts. Companies have come up with several solutions:

  1. Browser password storage
    1. Many browsers like Chrome, Firefox, Edge, and more have started asking users if they want to save their passwords. While this sounds good at first, it’s ridiculously easy to steal those passwords if a hacker gains access to the computer.
    2. This is not a long-term solution and whether you are a consumer or business, I recommend you get away from browser password storage ASAP.
  2. SSO
    1. You can see this across consumer and business technologies with their own implementations. You’re probably most familiar with it as an app on your mobile device. When you download a new app, it asks you to create an account/sign in with your Apple ID, Google Account, or Facebook account.
    2. While this is convenient and a step up from browser password storage, there are still ways hackers can abuse it.
    3. Once again, if a hacker gains access to your computer, they can use a cached SSO token to sign into other applications, software, or portals. This takes a more sophisticated hacker but is not difficult.
  3. Password Management software
    1. This is a web-based or downloaded software that stores your passwords. There are many options out there, but the main idea is having a Master Password that is used to gain access to all other passwords. A good password management software will, of course, allow or require you to have 2FA of some kind.
    2. While no password management software I’ve found is perfect, I find this is the best solution out of the 3 solutions out there. If you’re my client, we have one included for you with your package. Reach out to me or the team!

 

Passwordless Sign-on

An organization called FIDO Alliance, an industry group aimed at standardizing authentication methods online, announced that big browser builders, Apple, Microsoft, and Google, supported their ideal of passwordless sign-on.

That means you never have to use or create another password ever again. This could be a huge thing in terms of security. Now think of it this way. If you have a smart phone, you already use a pattern, PIN, fingerprint or face scan to unlock your phone.

Imagine if that same concept is used for ALL those websites, portals, and apps you need access to. FIDO’s passkey system plans to use your mobile device for that authentication via Bluetooth. While the details haven’t fleshed out yet, it could be promising.

 

Possible Cons

If websites and software are requiring mobile devices to authenticate logins via Bluetooth, there are a couple things business will need to keep in mind:

  1. Mobile devices for each employee that uses a login
  2. Have Bluetooth capable desktops and possibly servers

I honestly don’t see this taking mass adoption soon. Even to this day, I don’t see every website or software company adopting SSO. That means that until every website or software you use adopts this sign-on method, we recommend you continue using a password manager, and not your browser password storage.

My other concern is if this technology is like the current SSO methods. If so, this method is easier but just as vulnerable. If that’s the case, a Password Management Software continues to be the tried and tested method. As I see more news on this, I’ll update!