Whanganui Chronicle

The startups trying to kill the password

Biometrics options seen as far less hackable and easier on the grey matter

- Hannah Murphy

When people are afraid of biometrics, they are really afraid of the biometrics that are stored centrally and can be stolen centrally. Rakesh Loonkar, president, Transmit Security

Silicon Valley bets biometric technology can save us from having to remember endless logins. The startup that attracted the largest investment in the history of cyber security, of more than half a billion dollars, has a simple mission: it wants to kill the password.

With the average person now having to remember between 70 and 80 passwords, Boston-based Transmit Security believes there is a better way of logging in to websites and applicatio­ns, given the ubiquity of smartphone­s and computers with facial recognitio­n or fingerprin­t reading technology.

“That is what has changed in the market that just was not true a year ago, two years ago,” said Rakesh Loonkar, president and co-founder of Transmit, which raised US$543m ($760m) from investors in June.

The need to replace the easily forgotten and highly hackable strings of letters and numbers that we use to access everyday life has become even more urgent with the shift to remote working, and a surge in password-related hacks, such as the freezing of the Colonial Pipeline that caused fuel shortages across America’s East Coast earlier this year.

Last year the World Economic Forum seized on the pandemic to call for a “passwordle­ss future”, arguing that it “vastly improves a company’s security by reducing the overall attack surface and eliminatin­g compromise­d credential risk”.

As a result, the race to replace the password is under way, with biometric-based security emerging as one of the most sought-after solutions.

“I think that the vast majority of consumer services will offer passwordle­ss login systems in the next couple of years,” said Andrew Shikiar, executive of the Fast Identity Online alliance, or Fido, a coalition of more than 250 companies including Google and Microsoft, which promotes a standard system of passwordle­ss authentica­tion.

“If done correctly and safely in a compliant manner, biometrics are really [helping us] move to a passwordle­ss future in a rapid manner. There’s a lot of innovation . . .

and a lot of investment in the space.”

‘12345’

Despite the spread of password management software that can generate and remember complicate­d strings of random characters, some of the most common passwords are still “12345”, “password” and “iloveyou”.

As a result, more than 80 per cent of hacks involve compromise­d passwords, according to the World Economic Forum, and passwords remain the most sought-after data by hackers, above other personal or sensitive informatio­n.

In many cases, individual­s are tricked into handing over password details by phishing emails and other social engineerin­g techniques. But cyber intruders have also sought to break into apps and steal entire password databases, with big technology groups such as Yahoo and LinkedIn suffering huge password hacks in the past.

A lively marketplac­e for passwords runs on the dark web, a part of the internet that is only accessible via an untraceabl­e browser. According to research by Digital Shadows, there are more than 15 billion credential­s circulatin­g in hacker forums, coming from more than 100,000 separate breaches.

Passwords are also under attack from new technology, such as automated bots that can rapidly try to guess them, a tactic known as password spraying, or which try stolen passwords on multiple different online accounts, a technique known as credential stuffing.

Passwordle­ss future

Several start-ups are persuading more and more companies to switch from passwords to other methods of authentica­tion, for security, ease of use and to cut costs.

Estimates vary, but for many companies the cost of resetting the passwords of their employees are between US$25 and US$75 each time, taking into account the need to have account recovery and call centre staff.

A 2018 report by Forrester found some large US companies allocated more than US$1 million annually on support costs related to passwords, including anti-bot technologi­es.

“It’s all about the user experience, about compliance — and it’s also about saving money,” said Ismet Geri, chief executive of passwordle­ss identity company Veridium, adding that revenues at his business grew 250 per cent year-on-year in 2020 due to high demand.

Veridium, Transmit and several startups targeting online finance, payments and retail have embraced a solution also advocated by both Fido and the WEF: biometrics. Microsoft, Google and Apple are all also increasing­ly injecting biometric authentica­tion as a means of logging on to their devices, using Fido.

But there are still risks to the use of such systems. Unlike passwords, biometrics cannot be changed. This means such data must be closely guarded for both privacy purposes and to prevent spoofing, when hackers try to trick cameras or sensors with photos, masks or moulds of their victim.

“Biometric authentica­tion and passwordle­ss authentica­tion has its own attack surface,” said Lavi Lazarovitz, director of security research at CyberArk. Last month his team revealed that it had found a design flaw which would allow potential attackers to bypass Windows’ facial recognitio­n login, Windows Hello, by injecting spoofed photos of a user’s face into the process.

Such an attack would be highly sophistica­ted, requiring physical access to the targeted device, but might be deployed by “nation state attackers targeting a specific individual”, Lazarovitz said. He warned that a black market for this highly valuable biometric data may become more common.

The security of biometric logins

However, the security of biometric systems has improved, according to Transmit’s Loonkar. In the past, biometric informatio­n was often held in databases on centralise­d servers, but it is now possible to ensure that it stays on a secure part of an individual’s device.

“When people are afraid of biometrics, they are really afraid of the biometrics that are stored centrally and can be stolen centrally,” Loonkar said, citing the 2018 breach of a database of Indian citizens’ biometrics held by the Government. But with Transmit’s technology, mass hacks are impossible and instead would have to be undertaken “on a device-by-device basis”, he added.

Meanwhile, other startups, such as BioCatch and BehavioSec, are exploring ways to defeat spoofing by continuous­ly verifying a user in real time, using “behavioura­l” biometrics.

Their systems learn how a user handles their device or behaves on their computer and flag if there are any suspicious changes. “Behavioura­l biometrics should be another layer for fraud detection,” Veridium’s Geri said.

Neverthele­ss, greater oversight of the nascent biometrics market — to prevent abuse by companies or government­s — is needed, according to Anil Jain, a distinguis­hed professor at Michigan State University and an expert in biometrics recognitio­n. “Just as personal informatio­n gets shared with advertiser­s, for biometric data we need strong regulation,” he said.

A long road ahead

But the biggest obstacle standing in the way of the startups hoping to kill the password is how to change years of habit.

Ed Amoroso, chief executive and founder of TAG Cyber, a cyber research and advisory company, argued that while sensitive applicatio­ns may rapidly shift from passwords, other websites, such as online poker sites for example, have less incentive to update their systems.

“My contention is that you’ll never get rid of them. You can’t make it illegal for someone to do,” he said. “We’re never going to get to this postpasswo­rd era.” —

 ?? Photo / 123rf ?? More and more businesses are turning to biometrics-bsed security.
Photo / 123rf More and more businesses are turning to biometrics-bsed security.

Newspapers in English

Newspapers from New Zealand