Passwordless is Like Living with the Lockers Always Open?
Debesh Choudhury, PhD
Information Security Researcher, Academician, Entrepreneur | Password & Cybersecurity, Digital Identity, Biometrics Limit, 3D Education | Linux Trainer | Writer | Podcast Host
Are you thinking to accept the hype of big tech corporations and go "passwordless" with a device and biometrics? Think many times before committing that blunder. The device token you would use for the ease of your cyber life might end up in multiple hacking of your private data and digital assets. Stealing the device, and spoofing biometrics are not impossible. In fact, the biometrics spoofing technology has been progressing at an alarming rate. Please remember that convenience and security ability bear an uncertainty relationship.
A higher convenience results in a lower security
A major part of the security technology community is projecting biometrics as the passwordless authentication tool. They are arguably playing the convenience button of biometrics. But is biometrics more secure than text passwords and PIN? If so, then why the sellers of biometrics-only authentication attaching text password/PIN as the fallback measure in case of biometrics failure? This should be the burning question to the digital identity developer community.
What should be the priorities of digital identity?
The top priority of a digital identity is its security. The data privacy is the next big issue. Convenience is a secondary factor. Should it be justified to exchange security with convenience? We shouldn't discard a certain security technology because it is not providing convenience or ease of use. We should search for ways out to simplify the password security instead of going for a more convenient but less secure technology.
The digital identity must provide security, privacy and easy adaptability
The new digital identity platform should be such that it can't be easily hacked. Even it is hacked, the privacy of the digital identity data should be protected. It should be easily accessible by all strata of the global citizens - both young and elderly, tech savvy and novice citizens. The security mechanism should be easily adaptable with the existing security technologies. The installation cost should not be very high or the new security technology should not require very complex technological and device infrastructure. It appears that such a simple, secure and sustainable digital identity platform may be built utilizing the episodic memory based Extended Password System.
Do you think 'password is dead' for the future?
The tech community now promotes "passwordless" hype. What are your views about digital identity and the future of password security? I would love to get your views and suggestions. If you like this article, please click a generous "Like" or any other LinkedIn "reactions", and "Share" it among your acquaintances and network.
Join the LinkedIn Group “Identity Crisis: The Future of Password Security” to get updates about the future of password security, episodic memory based password systems and beyond.
----------------------------------------
Join me on Twitter, Medium, Facebook, beBee, Steemit and LinkedIn
More of my articles on Digital Identity, Cybersecurity and allied topics:
- Identity Crisis: The Future of Password Security
- The Biometrics Rush
- Can Cybersecurity and Quantum Computing be Friends?
- Does Cybersecurity have any Space for Digital Convenience?
- Security Ability and Convenience Bear an Uncertainty Relationship
- Convenience is the Weakest Link in Security
- Biometrics Liveness Detection May Help Criminals
- Can Liveness Detection Defeat Biometrics Spoofing Attacks?
- Biometric Data Breach Conundrum
- Is Biometrics More Secure than Text Passwords?
- Self-Sovereign Identity Depends on National Policies
- The Password Hole in the Cyber Bag
- Identity Dilemmas: Biometrics, Texts or Something Else
- Brand Identity, Digital Identity and Crypto Aspirations
- Digital Identity, Assets and Governance
- Decentralized Digital Identity: Which Distributed Ledger is Most Viable?
- Decentralized Biometrics: Is It the Ultimate Solution?
- Biometric Data Protection is a Big Challenge
- Reset Biometric Traits?
- Spoofing Biometrics isn't Impossible
- Privacy protection could have saved Aadhaar data breach
- Data Protection is a Big Challenge
For more articles, stories, and insights follow #DebeshChoudhury
* * * * * * * * * * * * * * * * * * * * * *
I am a researcher and academician of electronics and applied photonics. My current research focuses on Privacy Protected Digital Identity. My friend Jose Munoz Mata and I are researching distributed ledger technology for decentralized digital identity and other real world applications.
In June 2015, Dr. Jeffrey Strickland and I founded a new LinkedIn Group called "The Unfluencers". To learn about the history of "The Unfluencers" please read the seminal LinkedIn article by Dr. Jeffrey Strickland entitled -- "Who are the Unfluencers". This group is an open group. You are welcome to join this group and engage yourself in the discussions. The Unfluencer?? Logo is a registered trademark of Dr. Jeffrey Strickland.
Text Copyright ? 2020 Debesh Choudhury— All Rights Reserved
#digitalidentity #cybersecurity #biometrics #threats #spoofing #dataprivacy #datasecurity #passwordsecurity #technology #innovation #infosensys #dazlabsasia #learningtimes #debeshchoudhury #josemunozmata
Senior Solution Architect at LSEG
5 年In today's world, password has become a problem itself - as there are multiple systems at home and office, platforms having different standards of passwords. So in this context, doesn't "Passwordless" mean to have an alternate authentication or security mechanism instead of traditional password ?
Information Security Researcher, Academician, Entrepreneur | Password & Cybersecurity, Digital Identity, Biometrics Limit, 3D Education | Linux Trainer | Writer | Podcast Host
5 年Another point I missed earlier is that the password or "Passwordless" authentication solution should be "accident ready" to face the challenges of panicky situations. I write it in a followup article. https://www.dhirubhai.net/pulse/digital-identity-panicky-situations-debesh-choudhury-ph-d-/
Senior PM | Product Leadership Certified | Accelerate success through visionary product management ?? | From idea to global engagement ??
5 年Steven Sprague
Decentralized transactional ecosystem enabler
5 年This article is remarkable in that ALL the arguments presented are invalid.? ??
Founder at M-Tech Innovations, Inc.
5 年"Passwordless" in practice, as I understand it, means: (1) authenticate to services with a PKI certificate and (2) unlock that certificate through a biometric authentication on the client.? It does not mean "unlocked" or "unauthenticated" but it does mean 1FA (biometric) and implies strong control over the certificate material locally and a robust biometric capability on the user's device.? It also implies that server-side there is support for PKI-based authentication.? These are all pretty inflexible requirements.