As we enter World Password Day, cybersecurity expert Grahame Williams believes the days of this particular practice are numbered.
According to Williams, we need to “drop passwords altogether” and adopt new technologies as they become increasingly “insecure” and “easily hacked”.
Williams, who is identity and access management director at security firm Thales, has called on organisations to move away from the traditional password and on to biometrics or multi-factor authentication as a means of tightening up sloppy security practices – most of which come down to easy to guess passwords, according to Williams.
Commenting, he says: “Research has come out in the last few days showing the number of CEOs who are still using ‘12356’ as their password is actually quite comical – the assumption is that we’ve moved away from that but actually the data really isn’t supporting that.
“We know that people are using these ridiculously easy passwords, but the most alarming fact is that they’re not actually just using them for one thing, they use that password over and over again. So if somebody gets access to one of your passwords they get access to your crown jewels.”
Experts advise that you use three random words when creating a password – ensuring that you don’t repeat the words across multiple accounts.
But ideally, companies should actively be trying to move away from this system as a means of protecting your “crown jewels”.
Recommended
- Scots fintech ePOS Hybrid seeking £500k funding for expansion plans
- Leader Insights | Thought email marketing was dead? Think again
- Scottish life sciences tech firms see huge investment boost
Williams adds: “Whereas passwords are really easy to guess, actually being able to use something which is unique to you – like your face or fingerprint – is obviously the logical step for us to take,” he said.
“We would recommend that everyone – whether consumer or private – to start utilising these technologies.
“Our standpoint on this is there’s no reason why you should have to still use passwords and we should all be looking to really push forward.”
Good Password Practice
Boris Cipot, senior security engineer at the Synopsys Software Integrity Group offers this advice on World Password Day: “When we consider the concept of ‘poor passwords,’ that refers to passwords that are common, easily guessable, or re-used among multiple services.
“These are also attributes of poor password security. Even replacing letters with numbers in simple one-word passwords can be guessed or cracked by automated tools in a matter of seconds. For instance, open-source tools such as John the Ripper use dictionaries as reference points and can identify common letter to number character swapping in passwords.
Changing your password regularly (every 30, 60, 90 days, etc.) is no longer considered to be enough to keep a password secure. Password policies should require long passwords that are also cryptic—in other words, passwords that don’t follow a common pattern.
Additionally, ensure your passwords aren’t re-used for multiple services. Password managers are an excellent resource to help users manage strong passwords that are changed often and not re-used.
Organizations should also implement mandatory multi-factor authentication for accessing services requiring authenticated access. Two-factor authentication through a mobile device, biometric sensors and chip cards are several examples of added layers of multi-factor authentication.
Some companies are also working to develop methods to get rid of the traditional password. Microsoft, for instance, is at the forefront of this effort. As we see advances that also provide ease of use, and more companies and users demanding stricter policies around authentication, I anticipate that more robust measures will emerge that will replace passwords in the not so distant future.”
Get the latest news from DIGIT direct to your inbox
Our newsletter covers the latest technology and IT news from Scotland and beyond, as well as in-depth features and exclusive interviews with leading figures and rising stars.
To subscribe, click here.





