Passwords Passing
Trying to remember a password!

Passwords Passing

As a vignette to illustrate the state of the digital identity world in 2022, I can do no better than tell you that when I was in San Diego this summer (at a gathering of some of the brightest stars in the digital identity universe) I had need to change my flight. I opened up my airline app and (presumably because I was logging in from a new location) was required to complete an additional authentication step, which was to tell them my favourite breed of dog.

Presumably, some years ago, when setting up this account I had been asked to choose a couple of additional security questions, but of course I had forgotten all about this. After a couple of guesses, I went for "Spaniel" and I was in (don't worry, I've changed it now so there's no need to email me about this gross security violation).

The state of internet security is pathetic. It's no wonder that fraud is at epic levels when vast swathes of the internet depend on passwords for security. “Password security” is no such thing. This was evident about a week after the world went online and smart people have been predicting the end of the password ever since.

Just to give one example, way back at the dawn of the new millennium Bill Gates was saying that smart cards should replace passwords and then in 2004 he told the RSA Security Conference that the password must go because it cannot "meet the challenge" of keeping us secure.

Yet I just had to reset the password for one of my hotel apps because the password stored in my handy password manager was somehow wrong and after three attempts to log in to try and book a hotel room I got locked out. They may as well just automatically send me straight to the "I forgot my password" page to save time when I try to log in.

Upper Case, Lower Case, Head Case

Passwords are well beyond their sell-by date. Last year, the top five passwords used in the USA, according to password manager Nordpass, were "123456", "123456789", "12345", "qwerty" and "password". It's hardly surprising that there are so many hacks, frauds, account takeovers and all sorts of other shenanigans that stem from the outdated view that passwords are some sort of security solution. They are not, and we (ie, the digital financial services sector) have known for years that they must die.

They should be replaced by real cryptography, preferably where the cryptographic keys are stored in tamper-resistant hardware rather than in software. A great many people already have suitable devices. These devices are near-prosthetic. The average smartphone user will tap the device 2,617 times a day. Around half of US smartphone users say they "couldn't live without their devices" and a third of them look at their phones more than 50 times every day.

So if most people are most of the time attached to a device capable of strong authentication of keys in tamper-resistant hardware… why are we still using passwords?

Well, we may not be in this bind for too much longer. The recent announcement from the FIDO Alliance and Microsoft, Apple and Google that they will support the expansion of the common passwordless standard created by the Alliance and the World Wide Web consortium (W3C) is really significant and should have attracted more media attention.

The three internet giants have committed to support passwordless sign-in that will work across all the desktop, mobile, and browser platforms that they control. That's a large portion of modern technology, covering everything from laptops and desktops to smartphones, tablets, and smartwatches. The announcement covers the most used operating systems (Android, iOS, Windows, and macOS) as well as the three most used web browsers (Chrome, Edge and Safari).

A passkey is a credential, tied to what is known as an "origin" (which means a website or an application that you want to log in to) and a physical device. Passkeys allow users to authenticate without having to enter a username, password, or provide any additional authentication factor. These credentials follow the FIDO and W3C Web Authentication (WebAuthn) standards. Similar to a password, websites and applications can request that a user create a passkey to access their account. Authenticators are FIDO-compliant devices which are used to, as you might imagine, authenticate the user. This includes special purpose devices (eg, Yubikeys), as well as mobile phones and other computers which meet the authenticator requirements (they have to have secure tamper-resistant storage for cryptographic keys, essentially).

The ability to log in to Windows using an Apple Watch, to Google using a Microsoft tablet and to Apple using Android phone is surely a game changer and a step towards ending the fragmentation of identity solutions that leaves the typical user struggling with password managers, sticky notes and mnemonics.

Two decades on from Bill Gates’ call for smart cards to replace passwords is about to be answered, although the smart cards will be inside mobile phones and laptops and tablets rather than sitting in wallets. As the MIT Technology Review commented recently, these alternatives to passwords are finally winning. It's not before time.


Book Dave

Are you looking for:

  • A speaker/moderator for your online or in person event?
  • Written content or contribution for your publication?
  • A trusted advisor for your company’s board?
  • Some comment on the latest digital financial services news/media?


Get in touch by clicking on the image above


One of my favorite pronouncements over the last 10-15 years has been "there are two banes of our digital lives; 1) usernames & passwords and 2) battery life". Excellent post!

Ritesh Tendulkar

Chief Innovation Officer, Modulr - unlocking business opportunity with embedded payments

2 年

Great article David Birch as always. Great news re the FIDO alliance. I haven't seen many examples of this in the wild yet but was recently pleasantly surprised to see Virgin Media let me log on to my account using biometrics using this.

Nick Telford-Reed

Award-winning technology & product innovator | communicator | leader | payments | fintech | architecture | PSD2

2 年

If you like FIDO, you're gonna love what we're doing with Secure Payment Confirmation at the W3C.

Efi Pylarinou

Top Global Fintech & Tech Influencer ? Trusted by Finserv & Tech Global ? Content & Influencer Services ? Advisory for Digital Transformation ? Speaking ? [email protected]

2 年

David, your storyboard with someone pointing a gun at my head and asks for my Identity or my Money, merits becoming a meme.

要查看或添加评论,请登录

David Birch的更多文章

  • I Am A Person: The Bank Says So

    I Am A Person: The Bank Says So

    When you go to a website and are asked to distinguish between a moped and a motorcycle (rather pointlessly, as it…

    42 条评论
  • Apple Opens Up

    Apple Opens Up

    You need a digital wallet strategy. Last year, Apple announced that any third-party wallet can now build on Apple’s…

    22 条评论
  • QR Codes Are A Fraud Risk

    QR Codes Are A Fraud Risk

    Fifty years on from the invention of the barcode, it’s time to move on. Jet Propelled On 26th June 1974, the first…

    46 条评论
  • My Phone Was Stolen, I Survived

    My Phone Was Stolen, I Survived

    Claer Barrett, writing about the theft of her mobile phone in the Financial Times, summarises our modern age…

    17 条评论
  • There Is No Excuse For Biometric Honeypots

    There Is No Excuse For Biometric Honeypots

    I’m sure that responsible commentators on the world of digital finance are not supposed to have a favourite data…

    16 条评论
  • Make It Until You Can Fake It

    Make It Until You Can Fake It

    I’m sorry to say that I’d never heard of the British pop star FKA Twigs, but I was fascinated by her testimony to a US…

    12 条评论
  • Consultants Don’t Know About The Future, Artists Do

    Consultants Don’t Know About The Future, Artists Do

    During an excellent fireside chat about the future of payments at Money20/20 Asia in Bangkok earlier this year Farhan…

    9 条评论
  • JPMorgan Chase Are Bullish On Biometrics, And I Am Too

    JPMorgan Chase Are Bullish On Biometrics, And I Am Too

    JPMorgan Chase is planning a broad roll out of biometric payments with US retailers by early next year, enabling…

    23 条评论
  • Ice, Ice, AI

    Ice, Ice, AI

    At Money20/20 in Las Vegas this year, I was kindly invited to a “fireside chat” with Sophia Bantanidis from Citi. I was…

    12 条评论
  • Apple Introduce Post-Quantum Security. You Should Be Thinking About This Too.

    Apple Introduce Post-Quantum Security. You Should Be Thinking About This Too.

    Apple have introduced new security to their iMessage service in the form of the PQ3 protocol, an end-to-end encrypted…

    10 条评论

社区洞察

其他会员也浏览了