{"id":1566,"date":"2020-09-29T13:13:00","date_gmt":"2020-09-29T13:13:00","guid":{"rendered":"https:\/\/sectigostore.com\/blog\/?p=1566"},"modified":"2020-12-28T12:32:36","modified_gmt":"2020-12-28T12:32:36","slug":"what-is-passwordless-authentication","status":"publish","type":"post","link":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/","title":{"rendered":"What Is Passwordless Authentication?"},"content":{"rendered":"\n<h2 class=\"wp-block-heading\"><a rel=\"noreferrer noopener\" href=\"https:\/\/enterprise.verizon.com\/resources\/reports\/2020-data-breach-investigations-report.pdf?mkt_tok=eyJpIjoiWm1NeE16ZzJaak16T1dWbSIsInQiOiIwVFZjOFFSSG43YVZ5SWZRUlhaMmg0NjVuZjc3NksrbUlOZzBmc2pYR0Z0NDJITGNZZlhxWVVIMWF3QVhYQVhxc0JzcWhvVmoydDczWVwvTTkxVytaNG5TQUVIVlJGYW1DcHpnWjdiQnk1OUV2bytEUFhwSFZNOXRNODRidDVzWUkifQ%3D%3D\" target=\"_blank\">Verizon\u2019s 2020 DBIR<\/a> reports that 80% of breaches within hacking involve brute force or the use of lost or stolen credentials. Learn how passwordless authentication can help you avoid such cyberthreats<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Passwordless authentication is all about making the authentication process more user-friendly and improving the security. But why did the need for passwordless technology arise in the first place? <\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/nordpass.com\/press-area\/\">NordPass<\/a> estimates that the average user has between 70 and 80 passwords. It&#8217;s not feasible for a person to remember 80 unique and complicated passwords. That\u2019s why people often use easy-to-remember passwords or reuse the same passwords for multiple accounts.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">But then also, according to a survey by <a rel=\"noreferrer noopener\" href=\"https:\/\/www.hypr.com\/hypr-password-study-findings\/\" target=\"_blank\">HYPR<\/a>, 78% of respondents said they had to reset their passwords due to forgetting them within the previous 90 days. Apart from causing an inconvenience to users, passwords also pose a great cyber risk to organizations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">In this article, we\u2019re going to talk about passwordless authentication methods and how they work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">What Is Passwordless Authentication?<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Authentication means confirming your identity in a way that third parties make sure you are the person\/entity\/organization that you claim to be. Traditionally, a cumbersome password is used for identity verification. But with passwordless authentication, you may use one of the following authentication factors:<\/p>\n\n\n\n<ul class=\"wp-block-list\" id=\"block-2645cb2c-66b1-4082-b955-38eeabc2a71a\"><li>A one-time password (OTP),<\/li><li>Magic links,<\/li><li>Hardware that produces system-generated PINs or codes,<\/li><li>Biometrics, or<\/li><li>Cryptographic digital certificates.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Don\u2019t worry, we will talk about each of these in detail shortly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, for example, whenever you log into your bank account, you generally use the traditional password-based method to authenticate yourself to that financial institution. But if the bank has enabled any passwordless method, you will be using one of the above-stated techniques instead of providing the cumbersome, hard-to-remember password. <\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"558\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page-1024x558.png\" alt=\"A screenshot of the vanguard.com website to showcase traditional, non passwordless authentication methods\" class=\"wp-image-1567 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page-1024x558.png 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page-300x163.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page-560x305.png 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page-940x512.png 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/vanguard-login-page.png 1426w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>A screenshot of the personal investor login portal on the vanguard.com website.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Passwordless authentication is something you can implement on everything from personal laptops to smartphones. Organizations can implement it on their public-facing and intranet websites, internal email network, work accounts, as well as on hardware resources like computers, tablets, and smart phones.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5 Passwordless Authentication Tools<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s explore some common tools of passwordless authentication.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>1. Biometrics<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">This category includes <strong>fingerprint scans, retina scans, and facial recognition scans<\/strong>. Biometric authentication is convenient for users because, barring any terrible accidents, users are always going to have those authentication factors with them. They\u2019re parts of users&#8217; bodies. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, you need to neither remember anything nor carry any hardware devices or cards. Many desktop, laptop, tablet, and cellphone manufacturers have already embedded biometrics authentication to provide security and convenience to their users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">However, there have been cases of biometric data (fingerprints) getting leaked or stolen in data breaches:<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><a rel=\"noreferrer noopener\" href=\"https:\/\/www.cpomagazine.com\/cyber-security\/breach-of-biometrics-database-exposes-28-million-records-containing-fingerprint-and-facial-recognition-data\/\" target=\"_blank\">VPNmentor researchers<\/a> discovered 28 million fingerprint and facial recognition records in Suprema\u2019s BioStar 2 data breach. &nbsp;&nbsp;<\/li><li>The U.S. government\u2019s <a rel=\"noreferrer noopener\" href=\"https:\/\/www.reuters.com\/article\/us-usa-cybersecurity-fingerprints\/5-6-million-fingerprints-stolen-in-u-s-personnel-data-hack-government-idUSKCN0RN1V820150923\" target=\"_blank\">Office of Personnel Management (OPM) hack<\/a> leads to the theft of 5.6 million fingerprint records. <\/li><li><a rel=\"noreferrer noopener\" href=\"https:\/\/www.safetydetectives.com\/blog\/antheus-leak-report\/\" target=\"_blank\">SafetyDetectives researchers discovered an insecure database<\/a> owned by Antheus Tecnologia containing 2.3 million data points, including 76,000 unique fingerprints.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Although there are ways to bypass the biometrics authentication, it requires a lot of hard work on the hacker\u2019s end to replicate biometrics even for a single account. Hence, the chances for bulk hacking are negligible.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>2. One-Time Passwords<\/strong> <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">When users register new accounts, they need to provide their phone numbers and create user IDs. <strong>Every time<\/strong> users want to log in to their accounts, they receive <strong>unique one-time passwords (OTPs)<\/strong> on their mobile phones via push notifications, SMS text messages, or on their registered email addresses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each OPT stays valid for a limited period of time (generally 30 seconds to 24 hours) and can be used only once. In this way, users don\u2019t need to remember the password.<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"701\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-1024x701.jpg\" alt=\"A series of three screenshots from a banking website's two-step verification process\" class=\"wp-image-1569 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-1024x701.jpg 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-300x205.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-560x383.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-1536x1052.jpg 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-2048x1402.jpg 2048w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/2fa-otp-login-example-940x644.jpg 940w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>This series of screenshots is from a popular unnamed banking mobile app. It showcases the two-step verification process that involves the use of a one time password (OTP) that\u2019s sent via SMS text message.<\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>3. Security Tokens <\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A security token is a physical device that validates a user&#8217;s identity and lets them access the system and resources. These are often called dongles. The user must possess this token to complete the authentication process. There are three main types of security tokens:<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. Connected Tokens:<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">A user must plug the security token into the system, computer, cardholder, etc. to complete the verification. Two examples of this type of token includes a USB token and a common access card (CAC), the latter of which requires the use of a CAC reader.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>USB Tokens: <\/strong>You can log in and\/or access some confidential resources on a computer only after plugging in this USB device. It generally involves 2-factor authentication (2FA). So, even after plugging it, you might need to activate the USB using your fingerprint or providing a secret code as a second form of authentication.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2. Disconnected Tokens<\/strong><\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">These are the small devices that look like a sim card, keychain fob, or USB flash drive. These tokens generate a unique and temporary cryptographic code that must be input by the user to gain access to a computer resource. <strong>Users don\u2019t need to insert the token in the system. Check out the image below. <\/strong><\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"640\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-1024x640.jpg\" alt=\"A photograph of a disconnected hardware security token\" class=\"wp-image-1570 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-1024x640.jpg 1024w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-300x188.jpg 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-560x350.jpg 560w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-1536x960.jpg 1536w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-940x588.jpg 940w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token-480x300.jpg 480w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/hardware-security-token.jpg 1600w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><figcaption>This is an example of a disconnected (or connectionless) hardware security token, which can be used as a secondary authentication factor. <\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">Another example of disconnected tokens is grid cards.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Grid Cards: <\/strong>Almost reminiscent of Bingo cards, these cards have grids containing combinations of numbers and letters in different rows and columns. When users need to verify their identities, they have to log in with their biometrics or PINs. Then the system will ask to supply a particular value from the tables in the card.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">See the example below for an idea of what one of these cards looks like:<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"784\" height=\"584\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/grid-card-example.png\" alt=\"An example of a grid card for passwordless authentication\" class=\"wp-image-1572 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/grid-card-example.png 784w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/grid-card-example-300x223.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/grid-card-example-560x417.png 560w\" sizes=\"auto, (max-width: 784px) 100vw, 784px\" \/><figcaption>This is an example of a grid card that we created for this topic.<\/figcaption><\/figure><\/div>\n\n\n\n<p class=\"wp-block-paragraph\">This is an example of a grid card. If the system asks you &#8220;B1, F3, D2&#8221;, you need to find and input the values written on those cells. So, using the card example above, the values will be Q3JRS6.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Eployees can carry that card in their wallet, or the company may choose to imprint it behind the employee badge.<\/p>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3. Contactless Tokens<\/strong> <\/h4>\n\n\n\n<p class=\"wp-block-paragraph\">Some tokens don\u2019t require users to plug the token in the system or insert any key. The authentication is done automatically \u2014 for example, Bluetooth tokens.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>4. Magic Links<\/strong><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In this passwordless authentication method, anauthenticator sends a unique link-URL to your registered email address or on the SMS. The URL contains a special token. When you click on the link, the server verifies it and sends it back to you (client). The token is then saved on your browser as a cookie for that particular session. If the link is not clicked on within a specific time period, it expires.&nbsp;<\/p>\n\n\n\n<div class=\"wp-block-image\"><figure class=\"aligncenter size-large\"><img loading=\"lazy\" decoding=\"async\" width=\"718\" height=\"650\" src=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/auth0.png\" alt=\"A screenshot from Auth0 that shows a passwordless authentication method known as a magic link\" class=\"wp-image-1568 addshadow\" srcset=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/auth0.png 718w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/auth0-300x272.png 300w, https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/auth0-560x507.png 560w\" sizes=\"auto, (max-width: 718px) 100vw, 718px\" \/><figcaption>Image source: <a href=\"https:\/\/auth0.com\/docs\/connections\/passwordless\/guides\/email-magic-link\" target=\"_blank\" rel=\"noreferrer noopener\">Auth0<\/a><\/figcaption><\/figure><\/div>\n\n\n\n<h3 class=\"wp-block-heading\"><strong>5. Client Certificates<\/strong> <\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">These <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-pki-certificate\/\">PKI certificates<\/a> are of great benefit to organizational setups, especially for businesses with remote employees. These certificates, which authenticate users, are also known as client certificates, personal authentication certificates (PACs), user certificates, and email signing certificates. (They are sometimes called this because they are used to digitally sign and encrypt emails, too.)<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These certificates are installed on the organization&#8217;s server and employees&#8217; devices (desktop, laptop, or even smartphones). What they do is make mutual authentication possible, authenticating both the users\u2019 clients and the servers they\u2019re connecting to through an exchange of certificates. This twist on the traditional TLS handshake involves the server providing its SSL\/TLS certificate as usual with the addition of the client providing its own certificate and public key.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The organization\u2019s server stores public keys while the client devices store private keys. So, employees can only access the company&#8217;s resources only when they log in from the devices where the corresponding private keys are stored. If the server can\u2019t verify and authenticate the user\u2019s certificate, it\u2019ll reject the connection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Hence, even if hackers steal the user\u2019s credentials, they can\u2019t access anything on the company&#8217;s server. Because here, the authentication is done via the certificate exchange. And since the private key never gets sent to the server, it remains secure.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The certificates, particularly when used with trusted platform modules (TPMs), offer greater security than phone-based multi-factor authentication methods<\/strong>. TPMs are cryptographic hardware modules that allow you to securely store your digital certificates or keys.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">5 Crucial Reasons to Avoid Using Password-Based Authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Let\u2019s understand why a password is considered a weak security measure and why you may want to consider passwordless authentication methods:&nbsp;<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">1. Cybercriminals Can Guess Passwords with Social Engineering<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">People often aren\u2019t serious about setting strong passwords. <a href=\"https:\/\/press.avast.com\/83-of-americans-are-using-weak-passwords\">Avast<\/a> reports that 83% of Americans use weak passwords, and 53% of Americans use the same password to protect multiple accounts. In general, people frequently use the names of their loved ones, friends, pets, or their favorite movie, sports, celebrities as their passwords. They also use their dates of birth, marriage anniversaries, or other important dates as their passwords.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">While this info makes it easier for people to memorize the passwords, it also makes it easier for hackers to guess them using <a href=\"https:\/\/www.thesslstore.com\/blog\/social-engineering-attacks-a-look-at-social-engineering-examples-in-action\/\">social engineering<\/a>. This method allows a cybercriminal to gather and use the information they learn about the victim through their social media profiles, career networking sites, and other information that\u2019s available on the public domain.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">2. Hackers Use Brute-Force Attacks to Bypass Password-based Authentication<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In <a href=\"https:\/\/medium.com\/@Protectimus\/how-does-brute-force-attack-work-38a883c0275f\">brute force attacks<\/a>, hackers set a script or bot on login fields, which keeps applying a pre-guessed database of millions of user IDs and passwords automatically until it makes a successful login attempt. Sometimes a <a href=\"https:\/\/sectigostore.com\/blog\/botnet-attacks-what-is-a-botnet-how-does-it-work\/\">botnet<\/a> is used, where a large number of infected devices deploy the brute force attack on a targeted login field.&nbsp;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">According to <a href=\"https:\/\/www.safetydetectives.com\/blog\/the-most-hacked-passwords-in-the-world\/\">SafetyDetectives<\/a>, which has collected more than 18 million passwords, these are the10 most commonly used passwords in the world:<\/p>\n\n\n\n<ol class=\"wp-block-list\" type=\"1\"><li>123456<\/li><li>password<\/li><li>123456789<\/li><li>12345<\/li><li>12345678<\/li><li>qwerty<\/li><li>1234567<\/li><li>111111<\/li><li>1234567890<\/li><li>123123<\/li><\/ol>\n\n\n\n<p class=\"wp-block-paragraph\">This shows how careless people can be when creating passwords. When users use weak passwords, hackers can easily bypass the authentication mechanism through brute force attacks.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">3. Risk of Password Leakage Increases When Multiple Users Sharing the Same Password<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">In an organizational setup, it\u2019s common for multiple employees and teammates to share the credentials of the company&#8217;s core accounts, resources, services, and email addresses. This may help to save money on purchasing licenses for separate accounts, but it can be far more costly in terms of credential compromise.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Sometimes, these employees reside in different cities, countries, and\/or are working remotely. If any of those employee&#8217;s device is infected with malware, gets stolen, or otherwise becomes compromised via the <a href=\"https:\/\/sectigostore.com\/blog\/a-man-in-the-browser-attack-what-it-is-how-to-prevent-it\/\">man-in-the-browser<\/a>, <a href=\"https:\/\/www.thesslstore.com\/blog\/protecting-against-man-in-the-middle-attacks\/\">man-in-the-middle<\/a>, or <a href=\"https:\/\/sectigostore.com\/blog\/botnet-attacks-what-is-a-botnet-how-does-it-work\/\">botnet trojan<\/a>, the credentials get compromised. The hacker can break into the corporate email network, files, and access confidential data.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">4. Hackers Buy and Share Password Lists on the Dark Web<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Some attackers find leaky databases or use malware to steal users\u2019 login credentials and passwords. They use the lists themselves or sell these credentials to other cybercriminals on the dark web. <\/p>\n\n\n\n<p class=\"wp-block-paragraph\">There are <a href=\"https:\/\/www.upguard.com\/blog\/biggest-data-breaches\">numerous data breach incidents<\/a> that took place in the past, and big companies like <strong>Yahoo, Equifax, First American Financial Corp, Facebook, and Marriot <\/strong>became victims of data theft. For example, in May 2020, a hacker group named Shiny Hunters stole <a href=\"https:\/\/www.zdnet.com\/article\/25-million-user-records-leak-online-from-popular-math-app-mathway\/\">25 million<\/a> students\u2019 email addresses and passwords from a math solving app, Mathway. They were selling that database on the dark web for $4,000.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, the perpetrators who don\u2019t know programming or common hacking techniques can also buy and misuse the passwords. When people use the same passwords for multiple accounts, it becomes very easy for attackers to hack all other accounts, too.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\">5. Keyloggers and Other Malware Can Record or Steal Your Passwords<\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">A keylogger is a software that can monitor and record users&#8217; actions and behaviors. This type of software can read, copy-paste, and take screenshots of the devices&#8217; in which they are installed. Hackers use keyloggers to steal passwords, along with other personal data. But if you\u2019re not using a password-based method of authentication, it helps to mitigate some of the risks associated with keyloggers. &nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Multi-Factor Authentication (MFA) vs. Passwordless Authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><a href=\"https:\/\/sectigostore.com\/blog\/what-is-multi-factor-authentication-and-how-does-it-differ-from-2fa-sfa\/\">Multi factor authentication<\/a> (MFA) is related to passwordless authentication but is also still different because it traditionally involves the use of a password. In MFA, there are two or more layers of verification. In general, a password, followed by at least one secondary verification method like a hardware token or a biometric scan. Many often refer to these secondary authentication factors as \u201cwhat you know,\u201d \u201cwhat you have\u201d and \u201cwhat you are:\u201d<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>1) What you know<\/strong>: Passwords, security questions\u2019 answers and pass phrases.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>2) What you have<\/strong>: A possession that you have in your control such as a smartphone, laptop, USB token, or grid card.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>3) What you are: <\/strong>Biometrics such as fingerprints, iris or facial scans, etc.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">With passwordless authentication, however, no password or other types of knowledge-based secrets are necessary. It does, however, involve the use of cryptographic key pairs (we\u2019ll talk more about those soon). And passwordless authentication mechanisms may or may not have multiple layers of authentication. This means that it may only use one standalone verification method or may rely on more than one method (this is often referred to as \u201cpasswordless MFA\u201d).<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Role of PKI in Passwordless Authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Public key infrastructure<\/strong> (PKI) is the very foundation (the processes, procedures and technologies) that internet security is built upon. It\u2019s all about asymmetric encryption, and many passwordless authentication methods are based on PKI at their core.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Certificate-based authentication methods \u2014 such as SSL\/TLS certificates for websites or the client certificates we just talked about moments ago \u2014 rely on asymmetric encryption. This involves the use of digital certificates that are issued by trusted third parties (known as <a href=\"https:\/\/sectigostore.com\/blog\/what-is-a-certificate-authority-certification-authorities-explained\/\">certificate authorities<\/a>, or CAs) and asymmetric key pairs. These certificates, which CAs sign, authenticate third parties while the keys encrypt and decrypt data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These key pairs consist of two mathematically related yet distinct keys.<\/p>\n\n\n\n<ul class=\"wp-block-list\"><li><strong>Public key: <\/strong>This key is available in the public domain and is something users\u2019 clients and websites share to prove their identities through third party authentication<strong>.<\/strong> This is what you use to encrypt data to keep it secure from prying eyes.<\/li><li><strong>Private key: <\/strong>This key, like the name would imply, is private and must be kept secret. This key is what you use to decrypt data that\u2019s encrypted by the public key. What\u2019s great about these keys is that they\u2019re virtually impossible to crack. For example, a 2048-bit RSA key would take approximately <em>300 trillion years<\/em> to crack using modern computers, according to <a href=\"https:\/\/www.quintessencelabs.com\/blog\/breaking-rsa-encryption-update-state-art\/\">Quintessence Labs<\/a>.<\/li><\/ul>\n\n\n\n<p class=\"wp-block-paragraph\">Only when you have the right combination of validated certificates and public and private keys, the authentication gets completed, and you can securely access the system. <strong>The onus of PKI\u2019s success entirely relies upon the secrecy of the private key and the trusthworthiness of certificate authorities.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For more information about <a href=\"https:\/\/sectigostore.com\/blog\/what-is-pki-a-laymans-guide-to-public-key-infrastructure\/\">public key infrastructure<\/a>, be sure to check out our in-depth piece on this topic.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Wrapping Up on Passwordless Authentication<\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Passwordless technology provides a robust private key to organizations, websites that offer online services, and the users&#8217; devices. Users don\u2019t need to memorize a large number of passwords or hit \u201cforgot password\u201d numerous times and reset them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Passwordless authentication frees up the IT department\u2019s time as they no longer require setting password policies and comply with password storage laws and regulations.&nbsp; They don\u2019t need to be constantly alert to detect and prevent password leaks.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">So, is a passwordless solution right for your organization? Are there any disadvantages to passwordless authentication to consider? Let\u2019s explore these questions in one of our next articles that talks about the advantages and disadvantages of passwordless authentication.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Verizon\u2019s 2020 DBIR reports that 80% of breaches within hacking involve brute force or the use of lost or stolen credentials. Learn how passwordless authentication can help you avoid such&#8230;<\/p>\n","protected":false},"author":6,"featured_media":1571,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[13],"tags":[35,136],"class_list":["post-1566","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","tag-authentication","tag-passwordless-authentication","post-with-tags"],"yoast_head":"<!-- This site is optimized with the Yoast SEO plugin v28.0 - https:\/\/yoast.com\/product\/yoast-seo-wordpress\/ -->\n<title>What Is Passwordless Authentication? - InfoSec Insights<\/title>\n<meta name=\"description\" content=\"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means &amp; how it all works.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"What Is Passwordless Authentication? - InfoSec Insights\" \/>\n<meta property=\"og:description\" content=\"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means &amp; how it all works.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/\" \/>\n<meta property=\"og:site_name\" content=\"InfoSec Insights\" \/>\n<meta property=\"article:published_time\" content=\"2020-09-29T13:13:00+00:00\" \/>\n<meta property=\"article:modified_time\" content=\"2020-12-28T12:32:36+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg\" \/>\n\t<meta property=\"og:image:width\" content=\"1600\" \/>\n\t<meta property=\"og:image:height\" content=\"1000\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/jpeg\" \/>\n<meta name=\"author\" content=\"Medha Mehta\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Medha Mehta\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"13 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#article\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/\"},\"author\":{\"name\":\"Medha Mehta\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\"},\"headline\":\"What Is Passwordless Authentication?\",\"datePublished\":\"2020-09-29T13:13:00+00:00\",\"dateModified\":\"2020-12-28T12:32:36+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/\"},\"wordCount\":2611,\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/passwordless-authentication.jpg\",\"keywords\":[\"authentication\",\"passwordless authentication\"],\"articleSection\":[\"Cyber Security\"],\"inLanguage\":\"en-US\"},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/\",\"name\":\"What Is Passwordless Authentication? - InfoSec Insights\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#primaryimage\"},\"image\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#primaryimage\"},\"thumbnailUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/passwordless-authentication.jpg\",\"datePublished\":\"2020-09-29T13:13:00+00:00\",\"dateModified\":\"2020-12-28T12:32:36+00:00\",\"author\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\"},\"description\":\"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means & how it all works.\",\"breadcrumb\":{\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#primaryimage\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/passwordless-authentication.jpg\",\"contentUrl\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/wp-content\\\/uploads\\\/2020\\\/09\\\/passwordless-authentication.jpg\",\"width\":1600,\"height\":1000,\"caption\":\"Strong and weak password on pieces of paper. Password security and protection.\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/what-is-passwordless-authentication\\\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"What Is Passwordless Authentication?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#website\",\"url\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/\",\"name\":\"InfoSec Insights\",\"description\":\"SectigoStore.com Blog\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/sectigostore.com\\\/blog\\\/#\\\/schema\\\/person\\\/41d095943b7798ade1bc3683c8822f15\",\"name\":\"Medha Mehta\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"contentUrl\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g\",\"caption\":\"Medha Mehta\"},\"description\":\"Medha is a regular contributor to InfoSec Insights. She's a tech enthusiast and writes about technology, website security, cryptography, cyber security, and data protection.\",\"sameAs\":[\"https:\\\/\\\/sectigostore.com\\\/\"]}]}<\/script>\n<!-- \/ Yoast SEO plugin. -->","yoast_head_json":{"title":"What Is Passwordless Authentication? - InfoSec Insights","description":"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means & how it all works.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/","og_locale":"en_US","og_type":"article","og_title":"What Is Passwordless Authentication? - InfoSec Insights","og_description":"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means & how it all works.","og_url":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/","og_site_name":"InfoSec Insights","article_published_time":"2020-09-29T13:13:00+00:00","article_modified_time":"2020-12-28T12:32:36+00:00","og_image":[{"width":1600,"height":1000,"url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg","type":"image\/jpeg"}],"author":"Medha Mehta","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Medha Mehta","Est. reading time":"13 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#article","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/"},"author":{"name":"Medha Mehta","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15"},"headline":"What Is Passwordless Authentication?","datePublished":"2020-09-29T13:13:00+00:00","dateModified":"2020-12-28T12:32:36+00:00","mainEntityOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/"},"wordCount":2611,"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg","keywords":["authentication","passwordless authentication"],"articleSection":["Cyber Security"],"inLanguage":"en-US"},{"@type":"WebPage","@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/","url":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/","name":"What Is Passwordless Authentication? - InfoSec Insights","isPartOf":{"@id":"https:\/\/sectigostore.com\/blog\/#website"},"primaryImageOfPage":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#primaryimage"},"image":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#primaryimage"},"thumbnailUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg","datePublished":"2020-09-29T13:13:00+00:00","dateModified":"2020-12-28T12:32:36+00:00","author":{"@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15"},"description":"Passwordless authentication is important in digital identity. Discover what going passwordless in authentication means & how it all works.","breadcrumb":{"@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#primaryimage","url":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg","contentUrl":"https:\/\/sectigostore.com\/blog\/wp-content\/uploads\/2020\/09\/passwordless-authentication.jpg","width":1600,"height":1000,"caption":"Strong and weak password on pieces of paper. Password security and protection."},{"@type":"BreadcrumbList","@id":"https:\/\/sectigostore.com\/blog\/what-is-passwordless-authentication\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/sectigostore.com\/blog\/"},{"@type":"ListItem","position":2,"name":"What Is Passwordless Authentication?"}]},{"@type":"WebSite","@id":"https:\/\/sectigostore.com\/blog\/#website","url":"https:\/\/sectigostore.com\/blog\/","name":"InfoSec Insights","description":"SectigoStore.com Blog","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/sectigostore.com\/blog\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Person","@id":"https:\/\/sectigostore.com\/blog\/#\/schema\/person\/41d095943b7798ade1bc3683c8822f15","name":"Medha Mehta","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/a1e5b5025e87d4e1acfd683fbede8c366e652e9ddb2164b7a0d0a77e2d9da727?s=96&d=mm&r=g","caption":"Medha Mehta"},"description":"Medha is a regular contributor to InfoSec Insights. She's a tech enthusiast and writes about technology, website security, cryptography, cyber security, and data protection.","sameAs":["https:\/\/sectigostore.com\/"]}]}},"_links":{"self":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1566","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/comments?post=1566"}],"version-history":[{"count":0,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/posts\/1566\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media\/1571"}],"wp:attachment":[{"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/media?parent=1566"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/categories?post=1566"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sectigostore.com\/blog\/wp-json\/wp\/v2\/tags?post=1566"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}