So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

Recently, the research company "Javelin Strategy & Research" published a report titled "The State of Strong Authentication 2019." Its creators gathered information on what methods of authentication are used in corporate environments and consumer applications, and also made interesting conclusions about the future of strong authentication.

We have already published the translation of the first part with the authors' conclusions on Habr. . And now we present to you the second part — with data and charts.I won’t fully copy the entire section with the same name from the first part, but I will duplicate one paragraph.

From the Translator

All the figures and facts are presented without the slightest changes, and if you disagree with them, it's better to argue not with the translator, but with the authors of the report. However, my comments (formatted as quotes and noted in the text

) are my evaluative judgments, and I would be happy to debate each of them (as well as the quality of the translation). italic) are my evaluative judgments, and I would be glad to argue about each one (as well as about the quality of the translation).

User Authentication

Since 2017, the use of strong authentication in consumer applications has sharply increased, mainly due to the availability of cryptographic authentication methods on mobile devices, although a slightly smaller percentage of companies use strong authentication for web applications.

Overall, the percentage of companies employing strong authentication in their business has tripled from 5% in 2017 to 16% in 2018 (figure 3).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"
The capabilities for using strong authentication for web applications are still limited (because only the very latest versions of certain browsers support interaction with cryptographic tokens; however, this issue is being addressed by installing additional software, such as Routoken Plugin), which is why many companies use alternative methods for online authentication, such as mobile applications that generate one-time passwords.

Hardware cryptographic keys (here we mean only those that comply with FIDO standards), such as those offered by Google, Feitian, One Span, and Yubico, can be used for strong authentication without installing additional software on desktops and laptops (because most browsers already support the WebAuthn standard from FIDO.), but only 3% of companies take advantage of this for user login.

Comparison of cryptographic tokens (like RUTOKEN EDS PKI) and secret keys operating according to FIDO standards goes beyond the scope of this report, as well as my comments on it. To summarize briefly, both types of tokens utilize similar algorithms and operational principles. Currently, FIDO tokens receive better support from browser manufacturers, although this situation is expected to change as more browsers begin to support Web USB API. However, classic cryptographic tokens are protected by a PIN code, can sign electronic documents, and are used for two-factor authentication in Windows (any version), Linux, and Mac OS X. They have APIs for various programming languages that allow implementation of 2FA and digital signatures in desktop, mobile, and web applications, while tokens produced in Russia support Russian GOST algorithms. In any case, a cryptographic token, regardless of the standard it is created under, is the most reliable and convenient method of authentication.

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"
So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"
So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

Beyond security: other benefits of strict authentication

It is no surprise that the implementation of strict authentication is closely linked to the importance of data stored by businesses. Companies storing confidential personal information (Personally Identifiable Information — PII), such as social security numbers or personal health information (Personal Health Information — PHI), face the greatest legal and regulatory pressure. Such companies are typically the most aggressive advocates for strict authentication. The pressure on businesses is heightened by customer expectations that organizations entrusted with their most confidential data employ reliable authentication methods. Organizations processing sensitive PII or PHI are over twice as likely to use strict authentication compared to those that only store user contact information (Figure 7).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

Unfortunately, companies are still reluctant to implement reliable authentication methods. Nearly a third of decision-makers in business consider passwords the most effective authentication method among all options listed in Figure 9, while 43% believe passwords are the simplest authentication method.

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

This chart demonstrates that developers of business applications around the world are very much alike… They do not see the benefits of implementing advanced access control mechanisms to accounts and share the same misconceptions. Only actions from regulators can change the situation.

Let’s not touch on passwords. But what must one believe to think that security questions are safer than cryptographic tokens?? The effectiveness of security questions, which can be easily guessed, is estimated at 15%, while unbreakable tokens at only 10. They could at least watch the movie 'Now You See Me,' which, even in allegorical form, shows how easily magicians tricked a con artist out of all the necessary answers and left him without money.

Yet another fact speaks volumes about the qualifications of those responsible for security mechanisms in user applications. In their understanding, the process of entering a password is seen as a simpler operation than authenticating with a cryptographic token. Although, it seems, what could be easier than connecting a token to a USB port and entering a simple PIN code.

It is important to note that the implementation of strict authentication allows enterprises to stop worrying about authentication methods and operating rules needed to block fraudulent schemes, thereby addressing the real needs of their customers.

While compliance with regulatory requirements is a perfectly reasonable main priority for both enterprises using strict authentication and those that do not, companies already employing strict authentication are much more likely to say that increasing customer loyalty is the most important metric they consider when evaluating an authentication method. (18% versus 12%) (Figure 10).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

Corporate authentication

Since 2017, the implementation of strict authentication in enterprises has been growing, but somewhat more modestly than in consumer applications. The proportion of enterprises using strict authentication increased from 7% in 2017 to 12% in 2018. Unlike consumer applications, in the corporate environment, the use of passwordless authentication methods is somewhat more common in web applications than in mobile devices. About half of enterprises report using only usernames and passwords for authenticating their users during system login, with one in five (22%) relying solely on passwords for secondary authentication when accessing particularly sensitive data.That is, the user initially logs into the application using a simpler authentication method, and if they want to access critical data, they will perform another authentication procedure, usually using a more secure method this time.).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

It is important to understand that the report does not account for the use of cryptographic tokens for two-factor authentication in Windows, Linux, and Mac OS X operating systems. As of now, this is the most widespread use of 2FA. (Unfortunately, tokens created according to FIDO standards can implement 2FA only for Windows 10).

Moreover, while implementing 2FA in online and mobile applications requires a set of measures, including modifications to these applications, implementing 2FA in Windows only requires setting up PKI (for example, based on Microsoft Certification Server) and authentication policies in AD.

And since securing access to a work PC and domain is a crucial element of protecting corporate data, the number of implementations of two-factor authentication is increasing.

The next two most common methods of user authentication during system login are one-time passwords provided through a separate application (13% of enterprises) and one-time passwords delivered via SMS (12%). Although the percentage of usage for both methods is quite similar, OTP SMS is most often used to elevate authorization levels (in 24% of companies).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

The rise in the use of strict authentication in enterprises can likely be attributed to the increased availability of cryptographic authentication implementations on enterprise identity management platforms (in simpler terms, corporate SSO and IAM systems have learned to use tokens).

For mobile authentication of employees and contractors, enterprises tend to rely more on passwords than in consumer applications. Just over half (53%) of enterprises use passwords to authenticate user access to company data via mobile devices (Figure 13).

In the case of mobile devices, one might believe in the great power of biometrics, if it weren’t for the numerous cases of fingerprint, voice, facial, and even iris forgery. A simple search query will reveal that a reliable method of biometric authentication simply does not exist. Truly accurate sensors do exist, but they are expensive and large—making them unsuitable for smartphones.

Therefore, the only effective method of 2FA on mobile devices is the use of cryptographic tokens that connect to smartphones via NFC, Bluetooth, and USB Type-C interfaces.

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

The protection of company financial data is the primary reason for investing in passwordless authentication (44%), with the fastest growth since 2017 (an increase of eight percentage points). Next is the protection of intellectual property (40%) and HR data (39%). And it’s clear why—besides the widely recognized value associated with these types of data, they are also managed by a relatively small number of employees. This means implementation costs are not very high, and only a few individuals need to be trained to work with a more complex authentication system. In contrast, the types of data and devices that most employees typically interact with are still exclusively protected by passwords. Employee documents, workstations, and corporate email portals represent the highest-risk areas, as only a quarter of enterprises protect these assets with passwordless authentication (Figure 14).

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

In fact, corporate email is quite dangerous and 'leaky', with the degree of potential danger underestimated by most IT directors. Every day, employees receive dozens of emails, so why not have at least one phishing email (that is, fraudulent) among them? This email will be styled like official company correspondence, so the employee will click the link without hesitation. What follows could be anything, such as downloading a virus onto the attacked machine or credential theft (including through social engineering by entering information into a fake authentication form created by the attacker).

To prevent such incidents, emails should be signed. This way, it will be immediately clear which email was created by a legitimate employee and which was created by a malicious actor. In Outlook/Exchange, for example, an electronic signature based on cryptographic tokens is implemented quite quickly and easily and can be used in conjunction with two-factor authentication on PCs and Windows domains.

Among those executives who rely solely on password authentication within their organizations, two-thirds (66%) do so because they believe that passwords provide sufficient security for the type of information their company needs to protect (see figure 15).

However, strict authentication methods are becoming increasingly widespread. This is largely due to their growing accessibility. More and more identity and access management (IAM) systems, browsers, and operating systems support authentication using cryptographic tokens.

Strict authentication also has another advantage. Since passwords are no longer used (replaced with a simple PIN code), there are no more requests from employees to reset forgotten passwords. This, in turn, reduces the burden on the company's IT department.

So, what will happen with authentication and passwords? The second part of the Javelin report, "The State of Strict Authentication"

Summary and Conclusions

  1. Executives often lack the necessary knowledge to assess the actual effectiveness of various authentication options. They tend to rely on such outdated methods of protection as passwords and security questions simply because 'it used to work'.
  2. Users possess even less understanding, for them, the main thing is – Simplicity and convenience. They currently have no incentives to choose more secure solutions.
  3. Developers of user applications often have no reason, to implement two-factor authentication instead of passwords. Competition in terms of security among user applications is missing.
  4. All responsibility for hacking is placed on the user. If you give a one-time password to an attacker – you're to blame. If your password was intercepted or spied on – you're to blame. If you did not demand the developer to use reliable authentication methods in the product – you're to blame.
  5. The correct regulator should primarily demand companies to implement solutions that block data leaks (specifically two-factor authentication), rather than punish for already occurred data leaks.
  6. Some software developers try to sell consumers old and not particularly reliable solutions in attractive packaging of an "innovative" product. For example, authentication tied to a specific smartphone or using biometrics. As seen in the report, truly reliable solutions can only be based on strict authentication, that is, cryptographic tokens. The same
  7. cryptographic token can be used for a wide range of tasks : forstrict authentication in the enterprise operating system, in corporate and user applications, for electronic signatures of financial transactions (important for banking applications), documents, and emails. 🥇 So what will happen to authentication and passwords? The second part of the Javelin report "The State of Strict Authentication" | ProHoster

Source: habr.com

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster