The most popular and comprehensive Open Source ECM platform
Security: Gradual Adoption of Two-Factor Authentication
We’ve known that security based on passwords alone are weak. We’ve known this for some time. Bill Gates commented in 2004 that “there is no doubt that over time, people are going to rely less and less on passwords. People use the same password on different systems, they write them down and they just don’t meet the challenge for anything you really want to secure.”
How weak is weak? Consider the UK National Cyber Security Center found when analyzing passwords posted due to a major breach, that the password “123456” was used 23 million times by users. Second place was “123456789”. Other popular commonly used passwords included “password” and “qwerty”.
Tim Vidas, an engineer at SecureWorks, said that “passwords aren’t great, but as an industry, we don’t know what the next step is. We have empirical evidence that nobody likes passwords, they don’t work very well, but there’s not a clear solution.”
That’s not that there are no alternatives. Alternatives to plain passwords include biometric and two-factor authentication (2FA). Two factor authtentication requires a user to enter a password typically followed by a second step that involves verification based on a code sent by email or text message.
A recent survey by ThumbSignIn of security managers at industries from finance, IT and education found that 40 percent of businesses still rely only on passwords, but 36 percent are now using 2FA.
Andrew Shikiar, executive director and chief marketing officer of the FIDO Alliance, said that “there’s no question that passwords plus 2FA is better than passwords-only. People need to remember that this is a journey, it’s not a matter of flipping a switch and everything will be passwordless.”













