• bitcoinBitcoin(BTC)$77,845.00-1.89%
  • ethereumEthereum(ETH)$2,462.40-1.56%
  • tetherTether(USDT)$1.00-0.01%
  • binancecoinBNB(BNB)$716.69-4.47%
  • rippleXRP(XRP)$1.38-3.48%
  • usd-coinUSDC(USDC)$1.000.00%
  • solanaSolana(SOL)$101.08-3.05%
  • tronTRON(TRX)$0.3402860.40%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.030.00%
  • zcashZcash(ZEC)$1,222.67-3.39%
  • HyperliquidHyperliquid(HYPE)$82.90-3.98%
  • dogecoinDogecoin(DOGE)$0.085203-6.25%
  • RainRain(RAIN)$0.016119-0.41%
  • USDSUSDS(USDS)$1.00-0.01%
  • moneroMonero(XMR)$506.852.54%
  • whitebitWhiteBIT Coin(WBT)$80.45-1.86%
  • chainlinkChainlink(LINK)$11.82-2.45%
  • leo-tokenLEO Token(LEO)$9.230.50%
  • cardanoCardano(ADA)$0.212654-3.47%
  • stellarStellar(XLM)$0.179369-5.04%
  • bitcoin-cashBitcoin Cash(BCH)$245.42-5.09%
  • daiDai(DAI)$1.000.01%
  • Ethena USDeEthena USDe(USDE)$1.00-0.01%
  • USD1USD1(USD1)$1.000.00%
  • litecoinLitecoin(LTC)$52.25-3.86%
  • CantonCanton(CC)$0.101871-3.89%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.37-2.35%
  • uniswapUniswap(UNI)$6.02-9.93%
  • hedera-hashgraphHedera(HBAR)$0.076220-3.11%
  • avalanche-2Avalanche(AVAX)$7.73-2.96%
  • Global DollarGlobal Dollar(USDG)$1.000.01%
  • nearNEAR Protocol(NEAR)$2.41-7.69%
  • suiSui(SUI)$0.76-6.32%
  • shiba-inuShiba Inu(SHIB)$0.000005-5.32%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • crypto-com-chainCronos(CRO)$0.056405-5.93%
  • MemeCoreMemeCore(M)$1.201.36%
  • tether-goldTether Gold(XAUT)$4,374.24-0.69%
  • Circle USYCCircle USYC(USYC)$1.140.01%
  • Ripple USDRipple USD(RLUSD)$1.00-0.01%
  • BittensorBittensor(TAO)$251.46-5.18%
  • okbOKB(OKB)$111.88-2.34%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.14-0.13%
  • mantleMantle(MNT)$0.59-7.87%
  • AsterAster(ASTER)$0.71-5.27%
  • aaveAave(AAVE)$123.05-4.94%
  • pax-goldPAX Gold(PAXG)$4,375.05-0.76%
  • polkadotPolkadot(DOT)$1.10-6.42%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0561990.80%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

The password identity crisis: Evolving authentication methods in 2024 and beyond

December 30, 2023
in AI & Technology
Reading Time: 6 mins read
A A
The password identity crisis: Evolving authentication methods in 2024 and beyond
ShareShareShareShareShare

Join leaders in San Francisco on January 10 for an exclusive night of networking, insights, and conversation. Request an invite here.


In today’s sprawling IT landscape patchworking numerous cloud and SaaS apps and disparate devices and networks, just typing in a username and password no longer cuts it from a cybersecurity standpoint. 

YOU MAY ALSO LIKE

Fujitsu Signs New Palantir AIP Agreement, Becomes Global FDE Partner – Unite.AI

AppleCare One Now Has A $50 Tier Per Month For Families

First of all, usernames are often simple and predictable — typically a person’s email, name or initials. Secondly, passwords can be easy to guess. Startlingly, the most common passwords (yes, even in 2023) are “Admin,” “12345,” “12345678,” “1234” and “password,” according to research from Outpost24. 

Not surprisingly, then, using stolen credentials is one of the top ways attackers access an organization, and more than half (54%) of all attacks in the last year began with compromised logins. 

All of this, experts say, means we need to move towards a passwordless — or at least password-enhanced — future marked by heightened authentication methods. 

VB Event

The AI Impact Tour

Getting to an AI Governance Blueprint – Request an invite for the Jan 10 event.

 

Learn More

Here are a few evolving identity management techniques to keep an eye on in 2024. 

If you don’t have MFA in place, you’re already way behind

Multi-factor authentication (MFA) is one of the most basic step-ups in identity management: If your enterprise has not incorporated it already, you’re far behind, experts warn. 

The method requires users to provide more than a username and password — typically an SMS from their smartphone, a one-time password (OTP) sent to their email address, a USB key or authenticator app or biometric authenticator (more on that below). 

According to the Cybersecurity and Infrastructure Security Agency (CISA): “MFA increases security because even if one credential becomes compromised, unauthorized users will be unable to meet the second authentication requirement and will not be able to access the targeted physical space, computing device, network or database.” 

Zero trust on its way to becoming real

Zero trust, or “least privilege access” is another emerging method that assumes that every user could pose a legitimate threat. Throughout their time in a network or system, users must continually verify themselves, and they are only granted access to what they need when they need it. 

“Everything is authenticated and authorized,” Dell global CTO John Roese told VentureBeat. “Everything is tightly coupled in real-time.”

Zero trust systems log and inspect all network traffic and grant access to users at various stages based on their level of privilege and an enterprise’s security policies. The method also authenticates every device, network and connection based on policies and context from numerous data points. 

While the concept has been talked about for some time, it has yet to be fully realized because it is complex to incorporate, particularly when it comes to legacy systems that already have numerous security controls in place. But with the increased growth of AI built-from-scratch ‘greenfield’ systems, experts say that 2024 will be the year zero trust becomes real. 

“We’ve spent 2023 talking about zero trust and its importance to cybersecurity,” said Roese. “In 2024, zero trust will evolve from a buzzword to a real technology with real standards, and even certifications emerging to clarify what is and is not zero trust.”

Just-in-time extends limited, temporary access

An extension of zero trust is just-in-time (JIT) access, which grants temporary and time-limited access only when required for specific tasks. 

“This access is provided on-demand, right at the moment when the user requests it, and it is automatically revoked after the allotted time or task completion,” explains the SaaS management platform Zluri.

Critical to privileged access management (PAM), it is based on access policies and rules and incorporates verification methods such as temporary tokens. 

Users request access to a specific instance, device or virtual machine, which is then evaluated by admins and either granted or denied. After use in a short-term timeframe, they then log off and access is automatically revoked until required again in the future. 

“Instead of always granting access, JIT access limits it to a specific timeframe,” Zluri writes. This way, it reduces the risk of cyber attackers or insiders misusing privileged accounts and gaining unauthorized access to sensitive data.”

Passkeys eliminate the need for passwords altogether

Moving toward the passwordless future, passkeys are digital credentials that allow users to create online accounts without the need for passwords. 

“Passkeys allow users to authenticate without having to enter a username or password, or provide any additional authentication factor,” according to Google. 

Passkeys leverage Web Authentication (WebAuthn) APIs jointly developed by the industry association FIDO Alliance and the World Wide Web Consortium (W3C). Using public and private keys that are mathematically linked, passkeys can determine whether a user is who they claim to be. 

“You can think of them like interlocking puzzle pieces; they’re designed to go together, and you need both pieces to authenticate successfully,” according to password management company 1Password. 

Public keys can be seen by websites or apps, while private keys remain secret — they are never shared with sites users want to visit or stored on their servers. 

When users visit websites that support passkeys, they create an account and choose an option to secure it with a passkey — whether a phone, computer, tablet or other device — rather than a password. They then confirm their authenticator and a passkey is generated for that specific site locally on a user’s device. 

The next time the user signs in, the website challenges their authenticator, prompting it to complete a signature that is verified against the public key. 

“If 2022 was the year of being passkey-curious and 2023 was the year of hedging bets by making passkeys optional, 2024 will be the year that we see two or three major services providers go all in on passkeys,” predicts 1Password chief product officer Steve Won. 

Still, “It will still take another five years for passkey-only authentication to be adopted more broadly,” he added. 

At the same time, challenges such as integration with legacy systems and user education must be addressed, cautioned Michael Crandell, CEO of password management platform Bitwarden. 

“A balanced approach prioritizing both security and user experience will be key in advancing these security measures,” he said. 

Biometrics: The ultimate credential that can’t be lost or stolen

But the real identity authenticator of the future, many say, is biometrics, or various physical characteristics that are unique to a specific person. 

This can include voice, facial, iris and retina recognition and fingerprint and palm scanning.

Researchers also claim that the shape of a person’s ear, the way they sit and walk, their veins, facial expressions and even body odors are unique identifiers. 

“Each person’s unique biometric identity can be used to replace or at least augment password systems for computers, phones, and restricted access rooms and buildings,” according to cybersecurity company Kaspersky. 

Advanced systems use computer vision, sensors and scanners to capture a person’s unique characteristics, then leverage AI and machine learning (ML) to scan that information across a saved database to approve or deny access. 

While there are still many security, privacy and surveillance concerns around the use of biometrics, experts say their obvious advantages are that users don’t have to remember usernames or passwords and that personal characteristics are always with that one person — they can’t be lost or stolen. 

“In other words,” writes Kaspersky, “biometric security means your body becomes the ‘key’ to unlock your access.”

VentureBeat’s mission is to be a digital town square for technical decision-makers to gain knowledge about transformative enterprise technology and transact. Discover our Briefings.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Fujitsu Signs New Palantir AIP Agreement, Becomes Global FDE Partner – Unite.AI
AI & Technology

Fujitsu Signs New Palantir AIP Agreement, Becomes Global FDE Partner – Unite.AI

September 10, 2026
AppleCare One Now Has A  Tier Per Month For Families
AI & Technology

AppleCare One Now Has A $50 Tier Per Month For Families

September 10, 2026
DeepSeek AI Released DeepSeek-V4.1-Flash with 1M Context, FP4 KV Cache, and Cross-Layer Attention Reuse
AI & Technology

DeepSeek AI Released DeepSeek-V4.1-Flash with 1M Context, FP4 KV Cache, and Cross-Layer Attention Reuse

September 10, 2026
2028 Volvo XC40 First Look: Hello new tech, goodbye EV
AI & Technology

2028 Volvo XC40 First Look: Hello new tech, goodbye EV

September 10, 2026
Next Post
Teen charged in ‘racially motivated’ Cape Cod drowning attempt

Teen charged in 'racially motivated' Cape Cod drowning attempt

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
The Model, Tools, Memory, and Control Loop – Unite.AI

The Model, Tools, Memory, and Control Loop – Unite.AI

September 5, 2026
Georgia school shooter’s confession played in court

Georgia school shooter’s confession played in court

September 5, 2026
Brent crude rises above 0 a barrel as Middle East conflict escalates – Reuters

Brent crude rises above $100 a barrel as Middle East conflict escalates – Reuters

September 9, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!