Commentary on World Password Day: There are no “strong” passwords

May 2, 2023

Chris Meidinger, Technical Director, EMEA, Beyond Identity

Successful cyber attacks can often be complex in their entirety, but usually the origins are very simple or even trivial vulnerabilities. As the weakest link in the security chain, passwords have long been a favourite tool for cybercriminals: they can be easily guessed, cracked or otherwise obtained through social engineering tactics. The Verizon Data Breach Investigations Report and, more recently, the Crowdstrike Global Threat Report make it clear that criminals still use compromised credentials for initial entry in more than 75 per cent of all attacks.

The fact is that a “strong” password is wishful thinking. Complex passwords would be relevant if the attacker had to try to decrypt them. However, attacks are hardly ever perpetrated in this way. Cyber criminals prefer to grab passwords in readable form – from RAM, from keyboard input, unencrypted from databases, via phishing sites – wherever they are used and regardless of whether the password has four or 4,000 characters, contains three numbers or every special character. Considering how tedious it is for employees to remember passwords and change them regularly, it’s amazing that so many companies still try to protect their data with this outdated, insecure credential.

Every year we celebrate World Password Day while cybercriminals gleefully exploit password vulnerabilities. Instead, organisations should treat this day as “World No Password Day” and use it as an opportunity to close one of the biggest gateways in corporate security. By adopting passwordless, phishing-resistant MFA technologies, organisations can make it much more difficult for attackers to penetrate their networks – even with increased ease of use. Modern passwordless, phishing-resistant multi-factor authentication that combines biometrics and passkeys based on Fast Identity Online (FIDO) standards significantly reduces the risks associated with passwords and makes it virtually impossible for criminals to gain access to valuable corporate assets and sensitive data with their favourite tool.

Related Articles

AI boom: Data centres are becoming a security issue

AI boom: Data centres are becoming a security issue

The rapid expansion of AI infrastructure is driving investment in data centres to record levels. At the same time, power density, technical complexity and reliance on energy, cooling and communications systems are all increasing. This is also fundamentally altering...

When every second counts

Why communication is becoming a key resource for resilient infrastructure The new European CER guidelines are changing the way we view critical infrastructure. Resilience no longer simply means protecting buildings, networks and technical facilities against failures....

Rail transport infrastructure: Platform barriers?

Rail transport infrastructure: Platform barriers?

From ticket gates to security architecture: what Germany can learn from other countries Will access to the platform soon be restricted to holders of a valid ticket only? The idea of platform barriers is back in Germany. Yet even a brief international comparison shows...

Share This