{"id":2145,"date":"2020-11-03T10:57:58","date_gmt":"2020-11-03T10:57:58","guid":{"rendered":"http:\/\/www.intelligentcio.com\/north-america\/?p=2145"},"modified":"2021-02-23T12:07:11","modified_gmt":"2021-02-23T12:07:11","slug":"simeio-solutions-expert-says-most-breaches-are-from-exploited-passwords-lets-get-rid-of-them","status":"publish","type":"post","link":"https:\/\/www.intelligentcio.com\/north-america\/2020\/11\/03\/simeio-solutions-expert-says-most-breaches-are-from-exploited-passwords-lets-get-rid-of-them\/","title":{"rendered":"Simeio Solutions expert says: \u201cMost breaches are from exploited passwords. Let\u2019s get rid of them.\u201d"},"content":{"rendered":"\n<p><strong><em>James R Quick,Director, Solutions &amp; Advisory for Simeio Solutions, tells us it\u2019s time to get rid of passwords and instead automate and secure the authentication process.<\/em><\/strong><\/p>\n\n\n\n<p>There are two things we can do to secure our corporate assets; get rid of users or eliminate passwords. I say that tongue and cheek, but there\u2019s truth to half of that statement.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1000\" height=\"1000\" src=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2020\/11\/1000-4.jpg\" alt=\"\" class=\"wp-image-2147\" srcset=\"https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2020\/11\/1000-4.jpg 1000w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2020\/11\/1000-4-300x300.jpg 300w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2020\/11\/1000-4-150x150.jpg 150w, https:\/\/www.intelligentcio.com\/north-america\/wp-content\/uploads\/sites\/45\/2020\/11\/1000-4-768x768.jpg 768w\" sizes=\"auto, (max-width: 1000px) 100vw, 1000px\" \/><figcaption><em><strong>James R Quick,Director, Solutions &amp; Advisory for Simeio Solutions<\/strong><\/em><\/figcaption><\/figure><\/div>\n\n\n\n<p>Ok. We obviously need users but employees are on the front lines in a cyberwar over corporate and consumer data, battling myriad cyberattacks. Most data breaches are caused by credential theft. That\u2019s why, our most important endpoints are users. They are the most likely to unknowingly give away the \u2018kingdom keys\u2019.<\/p>\n\n\n\n<p>I\u2019m not being flippant about passwords. I\u2019d like to see them gone. The best way to eliminate nefarious activity from stolen passwords is to eliminate them. To secure employees, systems, applications, corporate secrets and consumer data, we must rein in repetitive and weak passwords that expose organizations to attacks.<\/p>\n\n\n\n<p><strong>Time to shift away from passwords<\/strong><\/p>\n\n\n\n<p>Everyone recognizes password weaknesses. We\u2019re frustrated with having to create and remember them, and where we stored them. So, we repeatedly use the same weak passwords, that are easily memorized. We know this creates a security risk but do it anyway.<\/p>\n\n\n\n<p>Security teams are overwhelmed managing, storing and protecting credentials. They may not have the budget or resources for the most up-to-date systems. They might lack the processes and policies to consistently update software, and don\u2019t have the domain expertise to keep up with the latest technologies to protect their business. They know hackers can acquire user credentials and move laterally across their network to access anything they want. They\u2019re also challenged to keep up with ever-growing privacy regulations.<\/p>\n\n\n\n<p><strong>A password replacement must be pervasive<\/strong><\/p>\n\n\n\n<p>Our smartphones are almost another appendage. They\u2019re with us constantly and are ubiquitous in our personal lives and business. While there are many methods and strategies for avoiding stolen and misused passwords, there is one that scales and permeates our personal and business activities. We can harden endpoints, like smartphones, tablets, smart speakers and laptops, with standards-based public key cryptography.<\/p>\n\n\n\n<p><strong>How it works<\/strong><\/p>\n\n\n\n<p>Secure key-enabled user devices remove the need for passwords, eliminate user registration and login friction, and globally scale. To initiate the process, users authenticate with the website using their device\u2019s private key, which responds to the website\u2019s security challenge.<\/p>\n\n\n\n<p>The private key can be used only after the security code has been unlocked by the user, by swiping a finger, entering a PIN etc. The device creates a new public\/private key pair, unique to the online service, and the user\u2019s account. The public key is sent to the online service and associated with the user\u2019s account. The private key and local authentication information never leaves the device.<\/p>\n\n\n\n<p>Passwords require human interaction which is a formula for disaster. We must automate and secure the authentication process. This means removing people from the equation. While there are many approaches to eliminating the password conundrum, standards-based public key cryptography provides strong authentication that scales and can be deployed on devices we use to register and login to online applications and services.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>James R Quick,Director, Solutions &amp; Advisory for Simeio Solutions, tells us it\u2019s time to get rid of passwords and instead automate and secure the authentication process. There are two things we can do to secure our corporate assets; get rid of users or eliminate passwords. I say that tongue and cheek, but there\u2019s truth to [&hellip;]<\/p>\n","protected":false},"author":18,"featured_media":2146,"comment_status":"closed","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[42,43],"tags":[121,1150,1106,213,1151],"class_list":["post-2145","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-thought-leadership","category-top-stories","tag-cybersecurity","tag-james-r-quick","tag-passwordless","tag-passwords","tag-simeio-solutions"],"acf":[],"publishpress_future_workflow_manual_trigger":{"enabledWorkflows":[]},"_links":{"self":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/2145","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/users\/18"}],"replies":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/comments?post=2145"}],"version-history":[{"count":7,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/2145\/revisions"}],"predecessor-version":[{"id":2154,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/posts\/2145\/revisions\/2154"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media\/2146"}],"wp:attachment":[{"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/media?parent=2145"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/categories?post=2145"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.intelligentcio.com\/north-america\/wp-json\/wp\/v2\/tags?post=2145"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}