Site navigation

Change Your Password Day: A Password-less Approach

Michael Edgar

,

Change Your Password Day
the 1st of February is Change your Password Day, the “most boring – but safest! – celebration ever.”

Back in 2012, popular tech blog Gizmodo pitched the day to emphasise the significance of robust and secure password practises. It has since taken off to be recognised in many countries around the world. 

“While it may seem tempting and convenient, using the same password for multiple accounts poses a significant security risk,” warned Andrew Confield, senior threat analyst at Adarma. 

The day of recognition, while over a decade old now, is as relevant as ever. Credential stuffing attacks, where threat actors use passwords from previous data breaches on new websites, have been particularly fruitful in recent months. Most notably with the 23andMe breach, where the information of about 6.9 million people was exposed by credential stuffing about 14,000 accounts.

If a couple of thousand breached accounts can have that much of a reach, then the recent dark web database containing 26 billion exposed credentials should be the cause of major concern in these types of attacks continuing. 

“The process of managing passwords, with increasing complexity requirements, means that users re-use passwords across systems when they find something that works,” said Elliott Wilkes, chief technology officer at Advanced Cyber Defence Systems.

“When one of the sites is compromised and has a data breach, attackers grab the leaked username, email, and password combinations and then try those for other sites.”

While updating passwords is in theory a great way to mitigate the risk of having your credentials used by threat actors, in reality, expecting users to generate and regularly update strong, memorable passwords is impractical. 

Which is why emerging alternatives seek to minimise the reliance on passwords altogether.

Alternative Password Security Measures

One of the ways to avert possible attacks from credential stuffing, aside from changing passwords frequently, is two-factor authentication (2FA). This is where temporary codes are entered to authenticate your login. This makes accounts more secure against attacks from credential stuffing to even phishing, which is a common way for criminals to gain access to an organisation’s systems and data. 

“While (2FA) enhances security, it remains imperfect, albeit a considerable improvement over no protection at all. Unfortunately, MFA implementation remains inconsistent, lacking the universal adoption it deserves. The primary issue with authentication technologies lies not in their design flaws but in their susceptibility to misuse,” said Boris Cipot, senior security engineer at the Synopsys Software Integrity Group.

Another way is to adopt a password manager. “This powerful tool can generate and suggest alternative passwords for your various accounts, leaving you with the sole task of remembering the master password for the password manager itself,” said Confield.


Recommended reading


Along with replacing the standard username-password model with a  cryptographic key pair, this method also eliminates requirements for organisations to define and enforce their own internal password policies. 

“The way that this key pair system works is that there are two keys per pair, one public key, and one private key. The public key is stored on whichever service you are trying to sign in to, and the private key is stored within your private key ring, un-lockable only via biometric data such as facial recognition or fingerprinting. This is all underpinned by mathematical cryptography, ensuring that only the corresponding private key can decrypt the matching public key stored on your account/service,” continued Confield.

Michael Edgar

Staff Writer, DIGIT

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data