Eskenzi PR ad banner Eskenzi PR ad banner
  • About Us
Thursday, 4 June, 2026
IT Security Guru
Eskenzi PR banner
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us
No Result
View All Result
IT Security Guru
No Result
View All Result

Passwords Will Never Die

by The Gurus
October 5, 2015
in This Week's Gurus
Share on FacebookShare on Twitter

Passwords Will Never Die

When I first joined Siber Systems in 2005 the internet was about 5% of the size it is now, but it was clear that its voracious expansion was not going to slow down any time soon. As the uses of the web multiplied year after year, it was equally clear that consumers wouldn’t be able to remember unique passwords for all the websites they visit.
I attended my first RSA conference in February 2007 in San Francisco, eager to propose our new RoboForm password manager as the best solution to this oncoming problem. Yet everywhere I went I would hear the same confident pronouncement: passwords are going to die soon. This might have been somewhat expected: RSA is somewhere software companies from across the world flock to tout their security innovations, and whether you’ve got a full-fledged secure enterprise integration or just a gimmicky idea, being ahead of the game is key.
I must have met at least 10 people from different companies that had biometric authentication solutions that were going to revolutionize the way we log into our computers, websites, business applications, and everything else.  I won’t deny that seeing all those advanced technologies in one place at one time made me go home and think very carefully about the future of the password management industry.
Back then, the future as portrayed in films like Minority Report seemed imminent – fingerprint scans, voice recognition, retina readers all getting people through doors and logging them into computers with speeds that made passwords look like bronze-age technology. People in the biometrics industry were sure their time had come.
However, it was clear after testing these devices and talking to colleagues that neither the technology nor the population expected to use it was ready for prime-time. So I continued down the password manager route, confident that we didn’t live in a sci-fi era quite yet.
Since then the internet has ballooned in size, we have seen the adoption of big data, cloud computing, the internet of things and we see a billion users of Facebook every day. But the challenges of the biometrics industry remain remarkably similar to those it faced ten years ago.
Chief among these is simply the human factor: most of us just don’t value our security over our convenience. Biometrics may be secure, but we still haven’t found a way of making fingerprint scanners and the rest simple and reliable for large audiences to use, and so they have simply refused to adopt it.
There’s another rather more basic problem looming over the sector, though. After the various data breaches over the last year, whether Carphone Warehouse, Sony, Target, or even Ashley Madison, the advice for customers has been to change your password. While this may be irritating to most of us, especially if you don’t use a password manager, it’s not the end of the world.
The biggest selling point of biometric identification is that your eyes and fingerprints are unique to you and thus cannot be changed. Unfortunately, that uniqueness comes with a price.  In the event that your biometric data is breached, it is permanently lost to those hackers. It cannot simply be changed.
And stealing your biometric data might be easier than many in the industry are willing to admit. Earlier this year, security firm FireEye demonstrated a fingerprint hack at the RSA conference, showing how they could intercept your biometric data before it hits your devices’ secure zone.  According to FireEye, the flaw is simple: rather than trying to break into the secure zone where your information is stored, the attackers simply focus on reading the data coming directly from the fingerprint sensor before it reaches the secure zone.
Once you have that data you can potentially reconstruct the fingerprint and use it as often as you want.  Your eyes are not safe either.  In another recent case, security researcher Jan “Starbug” Krissler claimed he could bypass iris scanners just by holding up high-resolution print outs to the camera.
There’s no point in arguing about which security solution is the “best”. It’s pretty clear that the future lies with individuals using a combination of security options, each making up for the weaknesses of the others. This “greater than the sum of the parts” solution is multifactor authentication, and comes in three parts:

  • Something you have, such as a hardware or software token
  • Something you know, like a password or answer to a security question
  • Something you are, for example a fingerprint or retina scan.

So rather than try to prove that a new technology is the Holy Grail and should replace passwords, it’s time to educate the public to use more than one factor of authentication.  Using multiple factors will certainly increase a user’s security more than using one factor alone, no matter how secure we believe that one factor may be.
Passwords have been used for thousands of years for a very good reason – they’re an easy and unique way of identifying individuals who are granted access to private information.  In addition,  their ability to be easily changed makes them even more attractive to the general public.
Passwords aren’t going to go away anytime soon.  While the world continues to welcome new technologies and additional methods of gaining access to our computers, websites and apps, passwords or some form of them will always be an acceptable factor for authentication.  It was true back in 2007; it’s still true today and will likely stay true for many years to come.
 
About the Author
Bill Carey is Vice President of Marketing & Business Development at Siber Systems Inc., which offers the top-rated RoboForm Password Manager solution. Find out more about RoboForm at http://www.roboform.com/

ShareTweet
Previous Post

White Hat Wifatch Malware Infects Thousands

Next Post

Edward Snowden reveals how Government can hack into YOUR smartphone and see EVERYTHING

Recent News

Nagomi Control Brings CTEM Into Action

IT Security Guru picks for Infosecurity Europe 2026

June 1, 2026
Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

Nine in Ten Security Leaders Concerned About AI-Generated Code Risks as Salt Security Launches New Governance Tool

June 1, 2026
Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

Acumen Cyber and AttackIQ Partner to Strengthen Cyber Defense Validation

May 29, 2026
Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

Check Point Launches AI Agents That Think Like Attackers as Autonomous Exploitation Reaches Critical Threat Level

May 28, 2026

The IT Security Guru offers a daily news digest of all the best breaking IT security news stories first thing in the morning! Rather than you having to trawl through all the news feeds to find out what’s cooking, you can quickly get everything you need from this site!

Our Address: 10 London Mews, London, W2 1HY

Follow Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol

  • About Us
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
  • Manage options
  • Manage services
  • Manage {vendor_count} vendors
  • Read more about these purposes
View preferences
  • {title}
  • {title}
  • {title}
No Result
View All Result
  • Home
  • Features
  • Insight
  • Channel News
  • Events
    • Most Inspiring Women in Cyber 2026
  • Topics
    • Cloud Security
    • Cyber Crime
    • Cyber Warfare
    • Data Protection
    • DDoS
    • Hacking
    • Malware, Phishing and Ransomware
    • Mobile Security
    • Network Security
    • Regulation
    • Skills Gap
    • The Internet of Things
    • Threat Detection
    • AI and Machine Learning
    • Industrial Internet of Things
  • Multimedia
  • Product Reviews
  • About Us

© 2015 - 2024 IT Security Guru - Website Managed by Dessol