Is the smoke beginning to clear for password security?

Issue 3 2022 Access Control & Identity Management, Security Services & Risk Management


Steven Hope.

It seems that not a day goes by without the publication of a new survey revealing that people are using so-called weak passwords. As the CEO of a company that develops password security management, passwordless and other authentication solutions aimed at protecting organisations from being compromised, I read these reports with mixed feelings.

On the one hand it is important to hammer home the message that password security needs to be taken seriously. Yet with every new statistic being similar to the last, I wonder whether we are making any progress. Like any story that hits the headlines, we initially sit up and take notice, but the longer it goes on, the more desensitised we become to it.

Let’s be honest, everyone knows that 12345 is a bad password. So, if you are using it to access one, or likely more accounts, you are doing so knowingly. That means you are either unaware of or ambivalent to the repercussions that can befall you as an individual or your organisation. Similarly, those of us working in the IT and security profession have known for many years about the pitfalls of poor password security, yet still it is the cause of the vast majority of data breaches.

So, if the awareness is not being accompanied by action we are at an impasse.

However, recently while watching the world go by in the sunshine outside in a pub garden, I was given a sense of optimism from an unexpected place. I suddenly noticed how no one was smoking cigarettes. As a non-smoker I would rather have sat inside than inhale the smoke of people who had been banished to the garden, but apart from a few people vaping, the air was fresh.

My point is that everyone who smoked knew it was bad for them (and those around them), but they did it anyway. The price of tobacco was steadily increased, bans on where they could light up were introduced, even horrific images of the damage it does to your body were added to packets, but still people chose to smoke. It was the introduction of vaping and e-cigarettes that changed the game completely. Smokers could continue to behave in a very similar way, but the risks to them and those around them were reduced. Vape shops quickly appeared and the price of maintaining their habit was competitive, making the swap easy.

This is where we need to get to with passwords. We need to clear the smoke (pardon the pun) and create a clear and simple path for people to follow. Technology vendors (Authlogics included) have brought to market a plethora of different products and solutions all trying to solve the same problem in a different way – use a password manager, ditch passwords, use multifactor authentication, introduce biometrics – the list goes on. These solutions will solve the problem but the message to the world is unclear and confusing, with every vendor arguing about the best approach.

Passwordless may be the next big leap, but just like those addicted to nicotine, very few will leap from 20 a day to quitting. Having tried to convince the market to jump to passwordless (albeit with some success, but not quite global domination), I am convinced that the right approach for the mass corporate market is password security management. This approach enables people to continue to behave in a similar way, continuing to use passwords, but within an ecosystem that ensures they are being used in accordance with best practice. For some organisations this may be enough, for others it may provide them with the roadmap they need to take the next step to improve how information and systems are accessed in a secure and compliant way.

The password problem is the result of bad habits, and they can be hard to break. But ask anyone that has done it and they will not tire of telling you the benefits. We can make progress and the survey results will improve, but it is going to take time, effort, and education.




Share this article:
Share via emailShare via LinkedInPrint this page



Further reading:

Partnership addresses fire hazard mitigation
Brigit Fire (a Division of Hudaco Trading) Elvey Security Technologies Fire & Safety Security Services & Risk Management
Brigit Fire has partnered with the Elvey Group. The collaboration will see Brigit Fire distributing both the advanced C-TEC addressable fire detection systems (CAST Technology) and GreenMist lithium extinguishers.

Read more...
Fire protection for a solvent extraction plant in Africa
FS Systems Fire & Safety Security Services & Risk Management Mining (Industry)
A prominent mining site operates a state-of-the-art solvent extraction (SX) plant, integral to separating and purifying metals from ores, which pose significant fire risks, as SX processes involve highly flammable organic solvents and elevated operating temperatures.

Read more...
Taking fire safety seriously
G2 Fire Editor's Choice Fire & Safety Security Services & Risk Management
To gain insights into how fire systems must be designed, installed and maintained, SMART Security Solutions asked Nichola Allan, MD of G2 Fire, for some insights into the local fire market.

Read more...
SMARTpod talks to The Risk Management Forum
SMART Security Solutions Editor's Choice News & Events Security Services & Risk Management Videos Training & Education
SMART Security Solutions recently released its first SMARTpod podcast, discussing the upcoming Risk Management Forum Conference 2024, which will be held on 26 September 2024 at the Indaba Conference Centre in Fourways, Johannesburg.

Read more...
There is a SaaS for everything, but at what cost, especially to SMEs?
Editor's Choice Information Security Security Services & Risk Management
Relying on SaaS platforms presents significant cybersecurity risks as the number of providers in your landscape increases, expanding your attack surface. It is important to assess the strength of the SaaS providers in your chain.

Read more...
New State of Physical Access Control Report from HID
HID Global Editor's Choice Access Control & Identity Management News & Events
HID released the 2024 State of Physical Access Control Report, identifying five key trends shaping access control's future and painting a picture of an industry that has been undergoing considerable transformation.

Read more...
Smart intercoms are transforming access control
Access Control & Identity Management Products & Solutions
Smart intercoms have emerged as a pivotal tool in modern access control. They provide a seamless and secure way to manage entry points without the need for traditional security guards to validate visitors before granting them access.

Read more...
Innovation and security go hand in hand
Technews Publishing Facilities & Building Management Security Services & Risk Management
In a world where the demand for tech innovation is matched only by the acceleration of cybersecurity threats, businesses face the challenge of balancing new product development and robust security measures.

Read more...
Easy, secure access for student apartments
Paxton Access Control & Identity Management Surveillance
Enhancing Security and Convenience at Beau Vie II Student Accommodation, a student apartment block located at Banghoek Road, Stellenbosch, with Paxton's access control and video management solution

Read more...
Invixium acquires Triax Technologies
News & Events Access Control & Identity Management
Invixium has announced it has acquired Triax Technologies to expand its biometric solutions with AI-based RTLS (Real-Time Location Systems) offering for improved safety and productivity at industrial sites and critical infrastructure.

Read more...