Implementing Passwordless Authentication – CW Walker, SpyCloud
CW Walker, director of product strategy for SpyCloud, explains what’s really required to implement passwordless authentication as more organizations look to reduce their reliance on passwords to improve cybersecurity
Transcript
This is Textron TV. Hey guys. Thanks for the throw.
We're here with CW Walker who's director of product strategy or spy cloud and we're talking about passwordless authentication something that's probably long overdue. But as we're about to discover might be a little harder to actually achieve them. We think CW welcome the show.
Oh, it's pleasure. Thank you for having me. I feel like we've been talking about this subject for a long time and we have biometric authentication mechanisms here and there and yet today the most prevalent way of granting access to anybody is that same old password that people have been using ever since the caveman grunted who goes there?
You know you why are we in this current situation? What is the challenge and how soon might we find our way towards something better? Well as soon as so relative of you know, I think that that we have been talking about password that's authentication for a long time and it's really only taken us 50 years to get to the point where we're discussing things like actual pathless authentication with things like passkeys.
But it's a spectrum right where no authentication is at one end and something very secure that maybe doesn't quite exist yet. But we're closer to that with past Keys is on the other end and multi-factor is there and passwords on maybe with a different complexity requirement. There are certainly steps along that path.
And I think that organizations are going to take time to move along that path to get to the point where everyone is able to say a little bit more secure without passwords. Is it going to be more like an arc where depending on the use case I will use different types of authentication mechanisms. And therefore I need to kind of evaluate how much effort I'm going to put in to kind of manage this whole process versus what actually I'm trying to secure.
I think maybe until we get to the point where there's less friction. We already see a little bit of this Arc if you will of complexity or friction for different types of applications. You know, I've got my handy fido-based security tokens here for some of my most sensitive applications, but Netflix is not one of those right?
I'm not even sure it's supports something like that, but it's pain. It's really really a pain to use. And so I think that once we get to the point where we have something that is significantly more secure and maybe past keys are this we'll be able to secure more accounts with higher levels because it reduces friction.
But while friction is part of the process, we're going to end up falling back on on less secure methods because It's just the pain. It's a pain to use UB keys or you know, one-time passwords and authenticator app and text message. That's more convenient, but significantly less secure, right?
So I think you're right. We will have a A spectrum of how secure does this application need to be until we get to the point where we have a highly secure authentication mechanism that has lower friction than what we have for multi. multifactor currently Once your best advice to folks about how to reduce that friction, what should they be looking about and thinking about before they go down this path because I think a lot of folks go down and initially and they don't have the right expectations and then they get frustrated and go home.
Oh man. Amen to that. Um, I can't tell you how many hours of family it I can log for for just managing passwords in our family.
Now there certainly things that help increase our security and reduce friction on password managers despite some of the challenges of Outsourcing that are really actually very good for helping. Especially multiple users. I keep random passwords for every account and have something that is local that they can still put in one password or use Biometrics to log in that makes a massive difference for personal security on the Enterprise side.
I think what you suggested with depending on the type of application a different more secure method depending on on what you're doing and what you're access is makes a lot of sense and that's generally what we recommend as well but bad guys, they're interested in passwords and no matter how secure a password it is if it gets stolen it doesn't really matter. It could be 50 characters and intensely complex, but if a bad guy has access to it. Well complexity doesn't really help it in that situation visibility does.
You talked about the hours that people spend. Managing passwords plus there's all the time and effort on the end user side. They go get a new password and a lot of times they don't change them enough and then that's part of the security mess that we're in do you think that organizations really understand the total cost of a current approach to managing passwords that we have and just how inefficient the whole thing is.
I mean that's a really good question. And I think that we don't as an industry really comprehend the cost of managing these types of things and despite that passwords are still the biggest entry point into networks. And our cause I think Verizon still has them over 70% of compromises are related to credential either theft or leakage.
And and so until we're able to move into a passwordless future, which we're taking baby steps towards that'll still end up being the case, right? Why do we never ever seem the required people to change their passwords on some sort of regular continuous basis? I know some folks have tried but the bulk of people out there.
Yeah, so one time issue and they hope for the best and I guess the the best practice quote unquote is, you know, when people forget their username and password they come up with another password, but no one actually seems that force that issue in a proactive manner. Yeah and nist actually had some guidance around password rotation every 90 days and and in their most recent and documentation around passwords and Security in Special publication 800 63 B and if you want just some delightful reading on your next vacation crack that open but they recommend two things. Actually they used to recommend rotation of passwords.
They no longer do that. But what they recommend is checking passwords that are being created and now stored for a longer time be continuously monitored against a large databases of exposed passwords to see whether or not any user has ever had that same password exposed and the example I use is, you know, we having really just met today and may have dogs that have the same name. And I've never used my dog's name for a password before but maybe I'll start today.
But if you have used your dog's name for a password and some number that maybe I choose as well. If your password has been stolen that actually reduces my account security and and so being able to check users passwords against a store of globally stolen exposed leaked passwords becomes even more critical in that case and and then with complexity Although Enterprises require generally higher complexity requirements than you know, like a video game forum or you know, a general chat room something like that. Users don't want to remember multiple passwords.
So they take the easy path. It's word that they have for their private life and they add an exclamation point and a one two three and bad guys know that too. So being able to understand not just a complexity requirement.
But that users I password life and history starts to become more important, especially as we get into more sensitive applications. All right. Well, I think you just made a case for having multiple dogs.
But other than that, oh, that's what my wife tells me. Do you think that there's any combination of usernames and passwords out there and it's just not on the dark web somewhere. I mean it seems like there's more of that stuff every day and it's almost impossible to protect them.
So what's your sense of just how much did the bad guys know? Oh man, the bad guys know a lot just in you know our research and collection. We're talking tens of billions of email and and password pairs, which is enough to cover everyone on Earth multiple times from a personal security standpoint.
There are some really neat things that you can do and to help protect against that like if you have an Apple device with a paid iCloud subscription, you can create random emails. For every account that you create online and then the email gets forwarded to your main email, which is really cool with a random email and a random password that really reduces the risk of even if those two things are stolen. It's a throwaway email so they can't plug that into every website like your bank and your tax software and you're streaming sites and and that's what I've started doing and I love it.
I'd recommend but again, it does increase a little bit of complexity and friction not everyone is built a career on paranoia like like we have right Speaking of friction multi-factor authentication this seems to be a lot of fatigue on this. We're just wrapping our heads around it in many cases and already yeah, we're going you know what this is kind of a pain. So what's your sense of what will ultimately be the adoption of MFA?
I think MFA adoption right now. We're sitting at the last metric I saw for all accounts generally speaking is a little less than 20% If you're looking at just Enterprise logins. It's a little bit higher.
I think it's closer to 40 and but friction, it's it's painful and I think that even though it does dramatically increase the security of account. It's still painful for users. And so they find ways around it and multi-factor generally isn't the Silver Bullet either.
We saw late last year a bunch of examples with multi-factor bombing where someone gets a notification on their phone that says yes, it's me log in and bad guys just harassed those accounts. So they were getting notifications at all hours of the day until they just say I don't even care just take the account over because I want the notifications to stop on. so friction is one piece, but I user.
Behavior is still going to find ways around even the most Secure Solutions. and even Beyond multi-factor Bad guys hate multi-factor, but they don't mind multi-factor when they're able to steal cookies. So after a user has already logged in the things that we're seeing criminals get most excited about are actually session identity tokens or cookies because if they can steal a cookie, it doesn't matter how authentication happened whether it's multi-factor or and past keys or an email and password.
They don't need the email and password or authentication method. They just take over the session and and so we're on the bleeding edge of new ways of authenticating and bad guys are seeing that too and they're finding new ways to get past authentication where they don't even have to use a password which is wild. Thanks puncture heard it here cookies still crumbled.
Hey CW. Thanks for trouble. That's a pleasure.
Thank you again for having me. All right back to you guys in the studio.