The Japan Times - Passwords under threat as tech giants seek tougher security

EUR -
AED 4.282286
AFN 72.889506
ALL 95.207603
AMD 430.01375
ANG 2.087753
AOA 1070.42764
ARS 1622.784305
AUD 1.615801
AWG 2.101792
AZN 1.980037
BAM 1.948086
BBD 2.348989
BDT 143.162498
BGN 1.947198
BHD 0.439945
BIF 3468.977203
BMD 1.166043
BND 1.484988
BOB 8.058985
BRL 5.837324
BSD 1.166277
BTN 111.748109
BWP 16.426743
BYN 3.258314
BYR 22854.438042
BZD 2.345552
CAD 1.600621
CDF 2617.765364
CHF 0.914545
CLF 0.02651
CLP 1043.367038
CNY 7.911775
CNH 7.916136
COP 4418.987218
CRC 529.980953
CUC 1.166043
CUP 30.900133
CVE 110.420738
CZK 24.310883
DJF 207.229054
DKK 7.473652
DOP 69.611585
DZD 154.439062
EGP 61.655687
ERN 17.490641
ETB 183.593618
FJD 2.556084
FKP 0.862511
GBP 0.870795
GEL 3.124803
GGP 0.862511
GHS 13.304314
GIP 0.862511
GMD 84.53284
GNF 10237.855419
GTQ 8.897767
GYD 243.990718
HKD 9.133322
HNL 31.040319
HRK 7.5352
HTG 152.719375
HUF 357.85873
IDR 20501.247154
ILS 3.384559
IMP 0.862511
INR 111.602244
IQD 1527.516012
IRR 1533346.225611
ISK 143.609809
JEP 0.862511
JMD 184.399822
JOD 0.82669
JPY 184.674396
KES 150.710561
KGS 101.97073
KHR 4678.163038
KMF 492.06927
KPW 1049.40427
KRW 1743.787798
KWD 0.359712
KYD 0.971947
KZT 552.061604
LAK 25600.468408
LBP 105018.290233
LKR 379.337915
LRD 213.677252
LSL 19.227736
LTL 3.443021
LVL 0.705327
LYD 7.380747
MAD 10.737796
MDL 20.047359
MGA 4871.140463
MKD 61.623214
MMK 2448.532445
MNT 4174.584911
MOP 9.409221
MRU 46.630148
MUR 54.687743
MVR 17.953612
MWK 2030.079949
MXN 20.097411
MYR 4.5843
MZN 74.521703
NAD 19.22769
NGN 1596.510503
NIO 42.811215
NOK 10.814812
NPR 178.792592
NZD 1.975224
OMR 0.448341
PAB 1.166257
PEN 4.019331
PGK 5.084821
PHP 71.905202
PKR 324.858355
PLN 4.243469
PYG 7106.858587
QAR 4.250809
RON 5.201602
RSD 117.404153
RUB 85.416661
RWF 1703.588468
SAR 4.323481
SBD 9.347158
SCR 15.925798
SDG 700.210747
SEK 10.964079
SGD 1.488553
SHP 0.870569
SLE 28.742478
SLL 24451.336053
SOS 666.396592
SRD 43.384983
STD 24134.730844
STN 24.778409
SVC 10.204331
SYP 128.881228
SZL 19.227966
THB 37.837714
TJS 10.898504
TMT 4.08115
TND 3.367544
TOP 2.807551
TRY 53.109051
TTD 7.918441
TWD 36.822696
TZS 3025.881057
UAH 51.26883
UGX 4361.616853
USD 1.166043
UYU 46.444895
UZS 14044.985317
VES 594.855331
VND 30719.39644
VUV 137.683599
WST 3.158251
XAF 653.355863
XAG 0.013988
XAU 0.000251
XCD 3.151288
XCG 2.101868
XDR 0.810364
XOF 650.065331
XPF 119.331742
YER 278.276306
ZAR 19.248742
ZMK 10495.787518
ZMW 21.954032
ZWL 375.465292
  • RBGPF

    0.8900

    61.68

    +1.44%

  • JRI

    0.0100

    13.14

    +0.08%

  • BCE

    -0.2000

    24.19

    -0.83%

  • BP

    -0.0200

    44.12

    -0.05%

  • BTI

    1.3500

    66.7

    +2.02%

  • CMSC

    0.0898

    23.14

    +0.39%

  • RELX

    -0.1600

    31.46

    -0.51%

  • RYCEF

    -0.1300

    15.9

    -0.82%

  • BCC

    2.4200

    69.4

    +3.49%

  • GSK

    -0.0300

    50.96

    -0.06%

  • RIO

    -2.4500

    109.59

    -2.24%

  • VOD

    -0.0300

    15.48

    -0.19%

  • NGG

    0.4500

    87.43

    +0.51%

  • CMSD

    0.0400

    23.6

    +0.17%

  • AZN

    -2.7600

    184.96

    -1.49%

Passwords under threat as tech giants seek tougher security
Passwords under threat as tech giants seek tougher security / Photo: Chris Delmas - AFP/File

Passwords under threat as tech giants seek tougher security

Fingerprints, access keys and facial recognition are putting a new squeeze on passwords as the traditional computer security method -- but also running into public hesitancy.

Text size:

"The password era is ending," two senior figures at Microsoft wrote in a July blog post.

The tech giant has been building "more secure" alternatives to log in for years -- and has since May been offering them by default to new users.

Many other online services -- such as artificial intelligence giant OpenAI's ChatGPT chatbot -- require steps like entering a numerical code emailed to a user's known address before granting access to potentially sensitive data.

"Passwords are often weak and people re-use them" across different online services, said Benoit Grunemwald, a cybersecurity expert with Eset.

Sophisticated attackers can crack a word of eight characters or fewer within minutes or even seconds, he pointed out.

And passwords are often the prize booty in data leaks from online platforms, in cases where "they are improperly stored by the people supposed to protect them and keep them safe," Grunemwald said.

One massive database of around 16 billion login credentials amassed from hacked files was discovered in June by researchers from media outlet Cybernews.

The pressure on passwords has tech giants rushing to find safter alternatives.

- Tricky switchover -

One group, the Fast Identity Online Alliance (FIDO) brings together heavyweights including Google, Microsoft, Apple, Amazon and TikTok.

The companies have been working on creating and popularising password-free login methods, especially promoting the use of so-called access keys.

These use a separate device like a smartphone to authorise logins, relying on a pin code or biometric input such as a fingerprint reader or face recognition instead of a password.

Troy Hunt, whose website Have I Been Pwned allows people to check whether their login details have been leaked online, says the new systems have big advantages.

"With passkeys, you cannot accidentally give your passkey to a phishing site" -- a page that mimics the appearance of a provider such as an employer or bank to dupe people into entering their login details -- he said.

But the Australian cybersecurity expert recalled that the last rites have been read for passwords many times before.

"Ten years ago we had the same question... the reality is that we have more passwords now than we ever did before," Hunt said.

Although many large platforms are stepping up login security, large numbers of sites still use simple usernames and passwords as credentials.

The transition to an unfamiliar system can also be confusing for users.

Passkeys have to be set up on a device before they can be used to log in.

Restoring them if a PIN code is forgotten or trusted smartphone lost or stolen is also more complicated than a familiar password reset procedure.

"The thing that passwords have going for them, and the reason that we still have them, is that everybody knows how to use them," Hunt said.

Ultimately the human factor will remain at the heart of computer security, Eset's Grunemwald said.

"People will have to take good care of security on their smartphone and devices, because they'll be the things most targeted" in future, he warned.

T.Maeda--JT