< ciso
brief />
Tag Banner

All news with #passwordless tag

41 articles

Security professionals still rely on passwords often

🔐 A Yubico and Okta study finds 48% of cybersecurity professionals use usernames and passwords for personal accounts and 43% for work accounts, despite rating them as among the least secure methods. Device-bound passkeys were viewed as most secure but used by only 25% at work and 20% personally, while password managers saw 24% workplace adoption. The report highlights fragmented authentication practices, limited MFA mandates, and legacy onboarding defaults as factors driving insecure choices.
read more →

Why common MFA methods no longer stop account takeovers

🔒 Organizations long celebrated multi-factor authentication as the key defense against account takeover, but the metric "MFA enabled" obscures crucial differences in technique. Push notifications, SMS one-time codes, and hardware keys all count equally on compliance reports despite offering vastly different protection levels. Push fatigue, SIM swap, and phishing/real-time proxy attacks routinely defeat push and OTP-based MFA. Newer, phishing-resistant standards like FIDO2 and passkeys provide origin-bound cryptographic protection that stops these attacks at the protocol level.
read more →

AWS adds phone number verification for accounts

📱 AWS Accounts now support phone number verification using SMS one-time passcodes for primary contact numbers. Customers can initiate verification via the AWS Management Console or the new SendPhoneNumberVerification API, and confirm with VerifyPhoneNumber. Verification status is exposed in GetContactInformation and changes via PutContactInformation require re-verification. Organizations can inherit verified numbers from the management account for member accounts.
read more →

Microsoft urges Entra ID migration to passkeys

🔐 Microsoft reminded administrators to migrate Entra ID users to phishing-resistant authentication methods, such as passkeys, ahead of the retirement of SMS first-factor sign-ins in February 2027. Admins can also use QR code authentication, FIDO2 security keys, or other Entra ID-supported methods. The retirement affects workforce tenant authentication and not Azure AD B2C or Entra External ID scenarios. Microsoft provided guidance and tools, including a PowerShell scanner, to help identify impacted users.
read more →

Microsoft shifts Entra ID to passkeys as default

🔐 As of Sept. 1, Microsoft made passkeys the default authentication method for Entra ID, and plans to retire Microsoft-provided SMS and voice authentication by Feb. 1, 2027. The change accelerates enterprise adoption of passwordless methods but leaves many organizations operating in a hybrid environment due to legacy applications, recovery and governance challenges. Experts praise the phishing resistance of passkeys while warning about device lifecycle, ecosystem lock-in, fragmented cross-platform support, and account recovery complexities that can keep passwords in place for specialized or older systems.
read more →

Equifax adopts AI to modernize cybersecurity

🔒 Equifax is combating evolving threats by combining strengthened cybersecurity hygiene with AI-driven automation across operations and development. EVP and CISO Jeremy Koppen highlights a 30% rise in attacks driven by automation and a shrinking window to patch vulnerabilities. Equifax has rolled out passwordless access for partners, a business exposure map, automated certificate management, and AI-assisted code review that reduced review time from 46 to 18 days.
read more →

Google adds selfie video account recovery option

📹 Google introduced an opt-in selfie video sign-in method to help users recover access when they cannot use their usual phone or computer. Users set up a short guided video with head movements to capture their face from multiple angles; later recordings are compared to the saved video to confirm identity. The feature stores videos encrypted at rest, is not available for Workspace, Child, or Advanced Protection accounts, and can be deleted or toggled for service improvement.
read more →

Verification Step Emerges as New ATO Attack Surface

🛡️ Passkeys and passwordless flows are reducing credential stuffing, but attackers now target identity verification and recovery paths such as magic links, step-up flows, and re-enrollment. Generative AI has made impersonation and synthetic media widespread, increasing fraudulent verification attempts. Defenders must adopt biometric liveness, risk-based re-verification, intent binding, and network-effect signals to stay ahead as regulations and threats evolve.
read more →

Apple adds AI to automatically fix compromised passwords

🔒 Apple announced at WWDC 2026 an Apple Intelligence-powered capability that can automatically detect and update weak, duplicate, or compromised passwords in Safari and the built-in Passwords app. The feature, arriving with iOS 27, uses on-device and Private Cloud Compute foundation models co-developed with Google to perform agentic actions that update eligible accounts to strong credentials. Apple emphasizes privacy-first design, saying personal data handled in the cloud is not stored or accessible to Apple.
read more →

World Password Day 2026: Why Passwords No Longer Protect

🔐 The World Password Day 2026 post contends that conventional password guidance is now inadequate: a 16-character secret can be lifted by infostealer malware from browser caches or exposed when employees paste credentials into unmanaged AI chatbots. It exposes a global, commoditized underground on platforms like Telegram where harvested credentials are bought and sold. The article warns organizations that passwords alone cannot prevent account takeover and urges layered technical and policy controls.
read more →

Microsoft to Deploy Entra Passkeys on Windows in Late April

🔐 Microsoft will roll out Entra passkey support for phishing‑resistant passwordless authentication on Windows devices starting in late April, with general availability expected by mid‑June 2026. The capability enables device‑bound FIDO2 passkeys stored in the Windows Hello container and used via face, fingerprint, or PIN on corporate, personal, and shared devices, including unmanaged Windows machines. Administrators can control rollout and access through Conditional Access and Authentication Methods policies.
read more →

DORA and Operational Resilience: Credential Controls

🔐 DORA's Article 9 makes credential management a binding financial risk control for EU financial entities, requiring least-privilege access, phishing‑resistant FIDO2/WebAuthn authentication, and cryptographic key protection. The regulation extends to third-party providers and mandates evidenceable controls. Organisations must deploy vaulting, JIT access, and continuous monitoring to reduce dwell time and meet supervisory expectations.
read more →

Fixing Authentication: Resilient Interoperable Systems

🔐 Authentication is breaking at critical front lines because a fragmented mix of cards, readers, middleware and identity platforms rarely interoperate under real-world pressure. This brittle stack allows downgrades, fallback paths and patch regressions to undermine even passwordless and FIDO2 deployments, producing outages and safety risks in healthcare, government and aerospace. The article outlines three architectural shifts — modular secure elements, reader‑agnostic middleware and a unified credential ecosystem — and a five-point CISO action plan to remove weak fallbacks, require downgrade transparency, harden patching, embed interoperability in contracts and run constrained high‑value pilots.
read more →

Rethinking Human Risk: Awareness Isn't a Control, Period

🔒 Organizations frequently treat security awareness training as a control, but this article contends it is primarily a cultural measure that cannot guarantee consistent outcomes. While training and phishing simulations reduce risk at the margins, they do not eliminate human variability or stop sophisticated business email compromise, credential harvesting, and modern MFA bypass techniques. The author recommends engineering systems to assume human fallibility—through phishing-resistant authentication, enforced financial controls, continuous identity telemetry, and real-time anomaly detection—so a single mistake cannot cause material harm.
read more →

AWS Releases Aurora DSQL Connectors for .NET and Rust

🔐 The new Aurora DSQL connectors for .NET (Npgsql) and Rust (SQLx) simplify secure application access by automating IAM token generation, SSL setup, and connection pooling. They remove reliance on static user passwords while remaining fully compatible with existing driver features. The connectors also provide opt-in optimistic concurrency control retries with exponential backoff, custom IAM credential providers, and AWS profile support to ease credential management.
read more →

6 Key Trends Reshaping the Identity and Access Market

🔐 The IAM market is shifting from traditional login and MFA toward treating identity as a security control plane, driven by demand for phishing-resistant authentication and stronger governance for non-human accounts. Buyers are prioritizing FIDO2/passkeys, biometrics, and controls for service accounts, API keys, and AI agents. Regulatory change, managed services, and vendor consolidation are reshaping architectures and procurement decisions.
read more →

Microsoft Entra Adds Phishing-Resistant Passkeys on Windows

🔐 Microsoft is introducing passkey support in Microsoft Entra for Windows, enabling phishing-resistant, passwordless sign-ins via Windows Hello. The opt-in feature enters public preview worldwide from mid‑March through late April 2026, with government clouds (GCC, GCC High, DoD) following mid‑April through mid‑May. Passkeys are device-bound, stored in the Windows Hello container, and never transmitted over the network, preventing credential theft and MFA bypass. IT administrators must enable the Passkeys (FIDO2) authentication method, create a passkey profile including the required Windows Hello AAGUIDs, and assign the profile to appropriate groups to enroll devices.
read more →

Bitwarden Enables Passkey Sign-in for Windows 11 Devices

🔐 Bitwarden now supports logging into Windows 11 using passkeys stored in the Bitwarden vault, enabling phishing‑resistant, passwordless sign-in across devices. The capability is available on all plans, including the free tier, and uses a QR scan and mobile confirmation to release a vault‑stored Entra ID passkey. Required: Entra ID–joined devices, FIDO2 sign‑in enabled, and a registered Entra ID passkey in the vault. Microsoft will roll out the Windows support this month, subject to Entra configuration.
read more →

PayPal's Hesitant Move Away From SMS for MFA, Operational Friction

🔐 PayPal announced it will begin removing unencrypted SMS for login MFA starting March 2026 but provided no firm timeline and said SMS will remain in use for fraud-related security checks. The company urged customers to adopt authenticator apps or FIDO2 security keys, though its email contained confusing setup instructions and account pages initially lacked direct update flows. Analysts say the move reflects security pressure, potential cost savings, and adoption friction between business and security teams.
read more →

Passwords to Passkeys: ISO 27001 Compliance Practical Guide

🔐 Password-based authentication is increasingly replaced by passkeys—FIDO2/WebAuthn-backed credentials that store private keys on devices and typically meet AAL2/AAL3 assurance per NIST SP 800-63B. This article explains how organizations can adopt passkeys while remaining compliant with ISO/IEC 27001, mapping changes to Annex A controls (Access Control, Authentication Information, Secure Authentication) and documenting risk treatment. It highlights benefits, common risks such as device loss and downgrade attacks, and practical migration steps for enterprise deployment.
read more →