The Password Isn’t Dead (And Will Never Die) Series

Fill out the form below to read!

Part 1:

If you’ve been keeping up with cybersecurity industry news lately, you’ve probably seen a few headlines unabashedly declaring the death of the password and the dawn of the passwordless era. A couple of security tech brands are hedging their bets, spending millions on software development for passwordless authentication, and forking out obscene ad budgets to evangelize the password’s supposed impending demise.

Key takeaways:

  1. The Theory of Password (and Passwordless) Authentication
  2. Eradicating the Password is Not a Fix.
  3. Biometrics are Not as Reliable as You Think.
  4. Passwordless Authentication Won’t Save You in the Event of Device Theft
  5. Passwordless Authentication Isn’t the Answer

Part 2:

One of the biggest problems with conducting nearly every facet of our personal and professional lives online is that we’re always at risk of our sensitive data becoming exposed. And as we continue to increase our reliance on digital tools at work and home, that risk will only continue to grow.

How can we be safer online? A growing number of cybersecurity vendors believe making the password obsolete is the answer. In the first part of this whitepaper series, we explored why this idea is dangerous in theory. Now, we’re diving into why it’s also reckless in practice.

Key takeaways:

  1. Passwordless Authentication Can (and Has) Failed
  2. Strong Passwords are Proven to Prevent Theft
  3. Passwordless Vendors Cause More Issues than They Solve
  4. Passwordless Authentication Doesn’t Solve the Root Problems of Worsening Cybersecurity Threats
  5. The Answer is Creating Stronger Passwords – Not Eliminating Them

Part 3:

While it might seem like removing passwords and relying on devices and biometrics will make your organization more secure, taking individuals’ power off the table will create yet another layer of abstraction between your workforce and your security efforts.

In the first and second parts of this series, we covered why passwordless authentication is dangerous in theory and practice. Now, we’re breaking down why passwordless environments can wreck your security culture, how it could make it even harder to attract and retain top talent, and what you should be doing instead.

Key takeaways:

  1. Removing Passwords is an Attack on Your Employees
  2. Passwordless Authentication Won’t Stop Social Engineering (and May Help It)
  3. Passwordless Authentication Fosters Bad Security Culture
  4. Passwordless Authentication Decreases Trust Between Employers and Employees
  5. Removing Passwords Creates Tension Between Security Teams and the Rest of the Workforce