{"id":33885,"date":"2019-10-31T21:55:12","date_gmt":"2019-10-31T18:55:12","guid":{"rendered":"https:\/\/prohoster.info\/blog\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii\/"},"modified":"2019-10-31T21:55:12","modified_gmt":"2019-10-31T18:55:12","slug":"tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii","status":"publish","type":"post","link":"https:\/\/prohoster.info\/en\/blog\/news\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii","title":{"rendered":"So, what will happen with authentication and passwords? The second part of the Javelin report, \"The State of Strict Authentication\"","gt_translate_keys":[{"key":"rendered","format":"text"}]},"content":{"rendered":"<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/fec8eb0cd69ddb065bb370c08b65fab8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nRecently, the research company \"Javelin Strategy &amp; Research\" published a report titled \"The State of Strong Authentication 2019.\" Its creators gathered information on what methods of authentication are used in corporate environments and consumer applications, and also made interesting conclusions about the future of strong authentication.<\/p>\n<p>We have already published the translation of the first part with the authors' conclusions on Habr. <noindex><a rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/aktiv-company\/blog\/449442\/\">. And now we present to you the second part \u2014 with data and charts.<\/a><\/noindex>I won\u2019t fully copy the entire section with the same name from the first part, but I will duplicate one paragraph.<br \/>\n<noindex><a rel=\"nofollow\" name=\"habracut\"><\/a><\/noindex><br \/>\n<b class=\"spoiler_title\">From the Translator<\/b><\/p>\n<blockquote><p>All the figures and facts are presented without the slightest changes, and if you disagree with them, it's better to argue not with the translator, but with the authors of the report. However, my comments (formatted as quotes and noted in the text<\/p>\n<p>) are my evaluative judgments, and I would be happy to debate each of them (as well as the quality of the translation). <i>italic<\/i>) are my evaluative judgments, and I would be glad to argue about each one (as well as about the quality of the translation). <\/p><\/blockquote>\n<p><\/p>\n<h2>User Authentication<\/h2>\n<p>\nSince 2017, the use of strong authentication in consumer applications has sharply increased, mainly due to the availability of cryptographic authentication methods on mobile devices, although a slightly smaller percentage of companies use strong authentication for web applications.<\/p>\n<p>Overall, the percentage of companies employing strong authentication in their business has tripled from 5% in 2017 to 16% in 2018 (figure 3).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/e4ac6c30844041b2278e6d55b2d8255e.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\nThe capabilities for using strong authentication for web applications are still limited (<i>because only the very latest versions of certain browsers support interaction with cryptographic tokens; however, this issue is being addressed by installing additional software, such as <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rutoken.ru\/products\/all\/rutoken-plugin\/\">Routoken Plugin<\/a><\/noindex><\/i>), which is why many companies use alternative methods for online authentication, such as mobile applications that generate one-time passwords.<\/p>\n<p>Hardware cryptographic keys (<i>here we mean only those that comply with FIDO standards<\/i>), such as those offered by Google, Feitian, One Span, and Yubico, can be used for strong authentication without installing additional software on desktops and laptops (<i>because most browsers already support the WebAuthn standard from FIDO.<\/i>), but only 3% of companies take advantage of this for user login.<\/p>\n<blockquote><p>Comparison of cryptographic tokens (like <noindex><a rel=\"nofollow\" href=\"https:\/\/www.rutoken.ru\/products\/all\/rutoken-ecp-pki\/\">RUTOKEN EDS PKI<\/a><\/noindex>) and secret keys operating according to FIDO standards goes beyond the scope of this report, as well as my comments on it. To summarize briefly, both types of tokens utilize similar algorithms and operational principles. Currently, FIDO tokens receive better support from browser manufacturers, although this situation is expected to change as more browsers begin to support <noindex><a rel=\"nofollow\" href=\"https:\/\/developer.mozilla.org\/en-US\/docs\/Web\/API\/USB\">Web USB API<\/a><\/noindex>. However, classic cryptographic tokens are protected by a PIN code, can sign electronic documents, and are used for two-factor authentication in Windows (any version), Linux, and Mac OS X. They have APIs for various programming languages that allow implementation of 2FA and digital signatures in desktop, mobile, and web applications, while tokens produced in Russia support Russian GOST algorithms. In any case, a cryptographic token, regardless of the standard it is created under, is the most reliable and convenient method of authentication.<\/p><\/blockquote>\n<p>\n<img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/a7d3552a472ebf65b76a54a2c4b25ab3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/f225e7b01e52c8a107b11a4499359fdd.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/097b47dd24a8b3d9c4f60eb461147e52.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h3>Beyond security: other benefits of strict authentication<\/h3>\n<p>\nIt is no surprise that the implementation of strict authentication is closely linked to the importance of data stored by businesses. Companies storing confidential personal information (Personally Identifiable Information \u2014 PII), such as social security numbers or personal health information (Personal Health Information \u2014 PHI), face the greatest legal and regulatory pressure. Such companies are typically the most aggressive advocates for strict authentication. The pressure on businesses is heightened by customer expectations that organizations entrusted with their most confidential data employ reliable authentication methods. Organizations processing sensitive PII or PHI are over twice as likely to use strict authentication compared to those that only store user contact information (Figure 7).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/8f80bbbb670c7d1c1dcf0de5ae5a9a98.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nUnfortunately, companies are still reluctant to implement reliable authentication methods. Nearly a third of decision-makers in business consider passwords the most effective authentication method among all options listed in Figure 9, while 43% believe passwords are the simplest authentication method.<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/926ac3e30ae04334acdbc4f6c0a0b2bb.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<\/p>\n<blockquote><p>This chart demonstrates that developers of business applications around the world are very much alike\u2026 They do not see the benefits of implementing advanced access control mechanisms to accounts and share the same misconceptions. Only actions from regulators can change the situation. <\/p>\n<p>Let\u2019s not touch on passwords. But what must one believe to think that security questions are safer than cryptographic tokens?? The effectiveness of security questions, which can be easily guessed, is estimated at 15%, while unbreakable tokens at only 10. They could at least watch the movie 'Now You See Me,' which, even in allegorical form, shows how easily magicians tricked a con artist out of all the necessary answers and left him without money.<\/p>\n<p>Yet another fact speaks volumes about the qualifications of those responsible for security mechanisms in user applications. In their understanding, the process of entering a password is seen as a simpler operation than authenticating with a cryptographic token. Although, it seems, what could be easier than connecting a token to a USB port and entering a simple PIN code. <\/p><\/blockquote>\n<p>\nIt is important to note that the implementation of strict authentication allows enterprises to stop worrying about authentication methods and operating rules needed to block fraudulent schemes, thereby addressing the real needs of their customers.<\/p>\n<p>While compliance with regulatory requirements is a perfectly reasonable main priority for both enterprises using strict authentication and those that do not, companies already employing strict authentication are much more likely to say that increasing customer loyalty is the most important metric they consider when evaluating an authentication method. (18% versus 12%) (Figure 10).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/a496437b972c53bff44090f1866167a8.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<h2>Corporate authentication<\/h2>\n<p>\nSince 2017, the implementation of strict authentication in enterprises has been growing, but somewhat more modestly than in consumer applications. The proportion of enterprises using strict authentication increased from 7% in 2017 to 12% in 2018. Unlike consumer applications, in the corporate environment, the use of passwordless authentication methods is somewhat more common in web applications than in mobile devices. About half of enterprises report using only usernames and passwords for authenticating their users during system login, with one in five (22%) relying solely on passwords for secondary authentication when accessing particularly sensitive data.<i>That is, the user initially logs into the application using a simpler authentication method, and if they want to access critical data, they will perform another authentication procedure, usually using a more secure method this time.<\/i>).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/20f93b9f28588e3857d656af82a695db.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<blockquote><p>It is important to understand that the report does not account for the use of cryptographic tokens for two-factor authentication in Windows, Linux, and Mac OS X operating systems. As of now, this is the most widespread use of 2FA. (Unfortunately, tokens created according to FIDO standards can implement 2FA only for Windows 10).<\/p>\n<p>Moreover, while implementing 2FA in online and mobile applications requires a set of measures, including modifications to these applications, implementing 2FA in Windows only requires setting up PKI (for example, based on Microsoft Certification Server) and authentication policies in AD. <\/p>\n<p>And since securing access to a work PC and domain is a crucial element of protecting corporate data, the number of implementations of two-factor authentication is increasing.<\/p><\/blockquote>\n<p>\nThe next two most common methods of user authentication during system login are one-time passwords provided through a separate application (13% of enterprises) and one-time passwords delivered via SMS (12%). Although the percentage of usage for both methods is quite similar, OTP SMS is most often used to elevate authorization levels (in 24% of companies).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/486e73591147365d20b0b57ae3fa4ab6.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe rise in the use of strict authentication in enterprises can likely be attributed to the increased availability of cryptographic authentication implementations on enterprise identity management platforms (in simpler terms, corporate SSO and IAM systems have learned to use tokens). <\/p>\n<p>For mobile authentication of employees and contractors, enterprises tend to rely more on passwords than in consumer applications. Just over half (53%) of enterprises use passwords to authenticate user access to company data via mobile devices (Figure 13).<\/p>\n<blockquote><p>In the case of mobile devices, one might believe in the great power of biometrics, if it weren\u2019t for the numerous cases of fingerprint, voice, facial, and even iris forgery. A simple search query will reveal that a reliable method of biometric authentication simply does not exist. Truly accurate sensors do exist, but they are expensive and large\u2014making them unsuitable for smartphones.<\/p>\n<p>Therefore, the only effective method of 2FA on mobile devices is the use of cryptographic tokens that connect to smartphones via NFC, Bluetooth, and USB Type-C interfaces.<\/p><\/blockquote>\n<p>\n<img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/2fc3d5777f7622cd7e3c56c97715ceca.jpeg\" style=\"display:block;margin: 0 auto;\" \/><br \/>\n<br \/>\nThe protection of company financial data is the primary reason for investing in passwordless authentication (44%), with the fastest growth since 2017 (an increase of eight percentage points). Next is the protection of intellectual property (40%) and HR data (39%). And it\u2019s clear why\u2014besides the widely recognized value associated with these types of data, they are also managed by a relatively small number of employees. This means implementation costs are not very high, and only a few individuals need to be trained to work with a more complex authentication system. In contrast, the types of data and devices that most employees typically interact with are still exclusively protected by passwords. Employee documents, workstations, and corporate email portals represent the highest-risk areas, as only a quarter of enterprises protect these assets with passwordless authentication (Figure 14).<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/94cac53239473da25002331f086d7582.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<blockquote><p>In fact, corporate email is quite dangerous and 'leaky', with the degree of potential danger underestimated by most IT directors. Every day, employees receive dozens of emails, so why not have at least one phishing email (that is, fraudulent) among them? This email will be styled like official company correspondence, so the employee will click the link without hesitation. What follows could be anything, such as downloading a virus onto the attacked machine or credential theft (including through social engineering by entering information into a fake authentication form created by the attacker).<\/p>\n<p>To prevent such incidents, emails should be signed. This way, it will be immediately clear which email was created by a legitimate employee and which was created by a malicious actor. In Outlook\/Exchange, for example, an electronic signature based on cryptographic tokens is implemented quite quickly and easily and can be used in conjunction with two-factor authentication on PCs and Windows domains.<\/p><\/blockquote>\n<p>\nAmong those executives who rely solely on password authentication within their organizations, two-thirds (66%) do so because they believe that passwords provide sufficient security for the type of information their company needs to protect (see figure 15).<\/p>\n<p>However, strict authentication methods are becoming increasingly widespread. This is largely due to their growing accessibility. More and more identity and access management (IAM) systems, browsers, and operating systems support authentication using cryptographic tokens. <\/p>\n<p>Strict authentication also has another advantage. Since passwords are no longer used (replaced with a simple PIN code), there are no more requests from employees to reset forgotten passwords. This, in turn, reduces the burden on the company's IT department.<\/p>\n<p><img decoding=\"async\" alt=\"So, what will happen with authentication and passwords? The second part of the Javelin report, &quot;The State of Strict Authentication&quot;\" src=\"\/wp-content\/uploads\/2019\/05\/761781ab78ce90cefdcce36cbf5622a3.jpeg\" style=\"display:block;margin: 0 auto;\" \/><\/p>\n<blockquote>\n<h4>Summary and Conclusions<\/h4>\n<p><\/p>\n<ol>\n<li>Executives often lack the necessary knowledge to assess <b>the actual <\/b>effectiveness of various authentication options. They tend to rely on such <b>outdated <\/b>methods of protection as passwords and security questions simply because 'it used to work'. <\/li>\n<li>Users possess even<b> less understanding<\/b>, for them, the main thing is \u2013 <b>Simplicity and convenience<\/b>. They currently have no incentives to choose <b>more secure solutions<\/b>.<\/li>\n<li>Developers of user applications often <b>have no reason<\/b>, to implement two-factor authentication instead of passwords. Competition in terms of security among user applications <b>is missing<\/b>.<\/li>\n<li>All responsibility for hacking<b> is placed on the user<\/b>. If you give a one-time password to an attacker \u2013 <b>you're to blame<\/b>. If your password was intercepted or spied on \u2013 <b>you're to blame<\/b>. If you did not demand the developer to use reliable authentication methods in the product \u2013 <b>you're to blame<\/b>.<\/li>\n<li><b>The correct <\/b>regulator <b>should primarily<\/b> demand companies to implement solutions that <b>block <\/b>data leaks (specifically two-factor authentication), rather than punish for <b>already occurred<\/b> data leaks.<\/li>\n<li>Some software developers try to sell consumers <b>old and not particularly reliable<\/b> solutions <b>in attractive packaging<\/b> of an \"innovative\" product. For example, authentication tied to a specific smartphone or using biometrics. As seen in the report, truly reliable <b>solutions can only be based on strict authentication, that is, cryptographic tokens.<\/b> The same<\/li>\n<li><b>cryptographic token can be used for<\/b> a wide range of tasks <b>: for<\/b>strict authentication <b>in the enterprise operating system, in corporate and user applications, for<\/b> electronic signatures <b>of financial transactions (important for banking applications), documents, and emails.<\/b> \ud83e\udd47 So what will happen to authentication and passwords? The second part of the Javelin report \"The State of Strict Authentication\" | ProHoster<\/li>\n<\/ol>\n<\/blockquote>\n<p>Source: <a content=\"nofollow\" rel=\"nofollow\" href=\"https:\/\/habr.com\/ru\/company\/aktiv-company\/blog\/452146\/\">habr.com<\/a><\/p>","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"excerpt":{"rendered":"<p>\u041d\u0435\u0434\u0430\u0432\u043d\u043e \u0438\u0441\u0441\u043b\u0435\u0434\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0430\u044f \u043a\u043e\u043c\u043f\u0430\u043d\u0438\u044f \u00abJavelin Strategy &amp; Research\u00bb \u043e\u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0430 \u043e\u0442\u0447\u0451\u0442 \u00abThe State of Strong Authentication 2019\u00bb. \u0415\u0433\u043e \u0441\u043e\u0437\u0434\u0430\u0442\u0435\u043b\u0438 \u0441\u043e\u0431\u0440\u0430\u043b\u0438 \u0438\u043d\u0444\u043e\u0440\u043c\u0430\u0446\u0438\u044e \u043e \u0442\u043e\u043c \u043a\u0430\u043a\u0438\u0435 \u0441\u043f\u043e\u0441\u043e\u0431\u044b \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438 \u0438\u0441\u043f\u043e\u043b\u044c\u0437\u0443\u044e\u0442\u0441\u044f \u0432 \u043a\u043e\u0440\u043f\u043e\u0440\u0430\u0442\u0438\u0432\u043d\u043e\u0439 \u0441\u0440\u0435\u0434\u0435 \u0438 \u043f\u043e\u043b\u044c\u0437\u043e\u0432\u0430\u0442\u0435\u043b\u044c\u0441\u043a\u0438\u0445 \u043f\u0440\u0438\u043b\u043e\u0436\u0435\u043d\u0438\u044f\u0445, \u0430 \u0442\u0430\u043a\u0436\u0435 \u0441\u0434\u0435\u043b\u0430\u043b\u0438 \u043b\u044e\u0431\u043e\u043f\u044b\u0442\u043d\u044b\u0435 \u0432\u044b\u0432\u043e\u0434\u044b \u043e \u0431\u0443\u0434\u0443\u0449\u0435\u043c \u0441\u0442\u0440\u043e\u0433\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438. \u041f\u0435\u0440\u0435\u0432\u043e\u0434 \u043f\u0435\u0440\u0432\u043e\u0439 \u0447\u0430\u0441\u0442\u0438 \u0441 \u0432\u044b\u0432\u043e\u0434\u0430\u043c\u0438 \u0430\u0432\u0442\u043e\u0440\u043e\u0432 \u043e\u0442\u0447\u0435\u0442\u0430, \u043c\u044b \u0443\u0436\u0435 \u043f\u0443\u0431\u043b\u0438\u043a\u043e\u0432\u0430\u043b\u0438 \u043d\u0430 \u0425\u0430\u0431\u0440\u0435. \u0410 \u0441\u0435\u0439\u0447\u0430\u0441 \u043f\u0440\u0435\u0434\u0441\u0442\u0430\u0432\u043b\u044f\u0435\u043c [&hellip;]<\/p>\n","protected":false,"gt_translate_keys":[{"key":"rendered","format":"html"}]},"author":1,"featured_media":25549,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[702],"tags":[],"class_list":["post-33885","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO 5.0.1.1 - aioseo.com -->\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"Yuri Gagarin\"\/>\n\t<link rel=\"canonical\" href=\"https:\/\/prohoster.info\/en\/blog\/news\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"\ud83e\udd47\u0422\u0430\u043a \u0447\u0442\u043e \u0436\u0435 \u0431\u0443\u0434\u0435\u0442 \u0441 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0435\u0439 \u0438 \u043f\u0430\u0440\u043e\u043b\u044f\u043c\u0438? \u0412\u0442\u043e\u0440\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u043e\u0442\u0447\u0435\u0442\u0430 Javelin \u00ab\u0421\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0441\u0442\u0440\u043e\u0433\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438\u00bb | ProHoster\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/prohoster.info\/en\/blog\/news\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii\" \/>\n\t\t<meta property=\"og:image\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:secure_url\" content=\"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg\" \/>\n\t\t<meta property=\"og:image:width\" content=\"350\" \/>\n\t\t<meta property=\"og:image:height\" content=\"350\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2019-10-31T18:55:12+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2019-10-31T18:55:12+00:00\" \/>\n\t\t<meta property=\"article:publisher\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<meta property=\"article:author\" content=\"https:\/\/www.facebook.com\/prohoster\" \/>\n\t\t<!-- All in One SEO -->\n\n","aioseo_head_json":{"title":"\ud83e\udd47So what will happen with authentication and passwords? The second part of the Javelin report \"The State of Strong Authentication\" | ProHoster","description":"","canonical_url":"https:\/\/prohoster.info\/en\/blog\/news\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii","robots":"max-image-preview:large","keywords":"","webmasterTools":{"miscellaneous":""},"schema":null,"og:locale":"en_US","og:site_name":"ProHoster | \u041a\u0443\u043f\u0438\u0442\u044c \u043d\u0430\u0434\u0435\u0436\u043d\u044b\u0439 \u0445\u043e\u0441\u0442\u0438\u043d\u0433 \u0434\u043b\u044f \u0441\u0430\u0439\u0442\u043e\u0432 \u0441 \u0437\u0430\u0449\u0438\u0442\u043e\u0439 \u043e\u0442 DDoS, VPS VDS \u0441\u0435\u0440\u0432\u0435\u0440\u044b","og:type":"article","og:title":"\ud83e\udd47\u0422\u0430\u043a \u0447\u0442\u043e \u0436\u0435 \u0431\u0443\u0434\u0435\u0442 \u0441 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0435\u0439 \u0438 \u043f\u0430\u0440\u043e\u043b\u044f\u043c\u0438? \u0412\u0442\u043e\u0440\u0430\u044f \u0447\u0430\u0441\u0442\u044c \u043e\u0442\u0447\u0435\u0442\u0430 Javelin \u00ab\u0421\u043e\u0441\u0442\u043e\u044f\u043d\u0438\u0435 \u0441\u0442\u0440\u043e\u0433\u043e\u0439 \u0430\u0443\u0442\u0435\u043d\u0442\u0438\u0444\u0438\u043a\u0430\u0446\u0438\u0438\u00bb | ProHoster","og:url":"https:\/\/prohoster.info\/en\/blog\/news\/tak-chto-zhe-budet-s-autentifikatsiej-i-parolyami-vtoraya-chast-otcheta-javelin-sostoyanie-strogoj-autentifikatsii","og:image":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:secure_url":"https:\/\/prohoster.info\/wp-content\/uploads\/2021\/11\/logo-350.jpg","og:image:width":350,"og:image:height":350,"article:published_time":"2019-10-31T18:55:12+00:00","article:modified_time":"2019-10-31T18:55:12+00:00","article:publisher":"https:\/\/www.facebook.com\/prohoster","article:author":"https:\/\/www.facebook.com\/prohoster"},"aioseo_meta_data":{"post_id":"33885","title":null,"description":null,"keywords":null,"keyphrases":null,"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":null,"og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"","isEnabled":true},"graphs":[]},"schema_type":null,"schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":null,"robots_max_videopreview":null,"robots_max_imagepreview":"large","priority":null,"frequency":null,"local_seo":null,"seo_analyzer_scan_date":"2026-01-21 17:06:19","breadcrumb_settings":null,"limit_modified_date":false,"reviewed_by":null,"ai":null,"created":"2021-03-01 02:31:23","updated":"2026-01-21 17:06:19","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"gt_translate_keys":[{"key":"link","format":"url"}],"_links":{"self":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33885","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/comments?post=33885"}],"version-history":[{"count":0,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/posts\/33885\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media\/25549"}],"wp:attachment":[{"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/media?parent=33885"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/categories?post=33885"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/prohoster.info\/en\/wp-json\/wp\/v2\/tags?post=33885"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}