Skip to content
Tiatra, LLCTiatra, LLC
Tiatra, LLC
Information Technology Solutions for Washington, DC Government Agencies
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact
 
  • Home
  • About Us
  • Services
    • IT Engineering and Support
    • Software Development
    • Information Assurance and Testing
    • Project and Program Management
  • Clients & Partners
  • Careers
  • News
  • Contact

Customer Passwords are a Target for Cybercriminals: How to Address the Threat

Companies face various cyber risks, ranging from ransomware to data theft. Cyber threat actors gain access to an organization’s systems in various ways. However, cybercriminals commonly take the path of least resistance, and organizations’ reliance on password-based authentication provides numerous avenues of attack. Passwords are known to be a weak form of authentication, and the widespread use of weak and reused passwords puts companies and their customers at risk.

CISOs have been working hard to address the threat vectors that target their workforce for years. The workforce is the most common vector for ransomware, data theft, and many other breaches. However, with the pandemic-fueled rise of digital, customers are an increasing threat vector. CISOs are increasingly expected to “secure what you sell,” presenting a new domain of security. To secure this customer domain, CISOs must address the same issue they’ve been dealing with on the workforce side: passwords.

Password-based authentication hurts usability and security

Passwords are the most widely-used form of customer account authentication. Customers use passwords to log into mobile apps, websites, and other customer channels. However, while passwords are ubiquitous, they are a weak and high-friction form of authentication. This friction harms both the security and the customer experience of an organization’s digital channels.

The security impacts of password-related friction arise because customers will attempt to avoid painful, time-consuming processes, such as generating and storing random, unique passwords for all their online accounts. As a result, passwords are commonly weak and reused across accounts, which makes account takeover (ATO) attacks possible. Think about your own use of passwords for the websites and apps you use. If you don’t use a password manager, you likely reuse user IDs and passwords across many disparate sites.

The poor customer experience of passwords also hurts an organization’s business. Password-related friction can reduce guest user conversions, inspire shopping cart abandonment, cause drop offs when switching between brands or channels, and require greater customer effort (which is a leading indicator of reduced brand loyalty). Passwords are bad for security, and bad for customer experience.

Bolted-on security doesn’t work

To shore up the weak security of passwords, companies commonly bolt on additional protections that do little to improve security but cause further harm to the user experience.

Common examples include:

  • SMS one-time passwords (OTPs): OTPs sent via SMS or other means are a common form of multi-factor authentication (MFA). However, these codes are vulnerable to interception or phishing attacks. Moreover, they often fail to send, and they always take extra time and effort to use.
  • Out-of-wallet security questions: Online accounts may ask out-of-wallet questions to prove a user’s identity. However, the answers to these questions are often accessible to attackers via public records, phishing attacks, data breaches, and social media. And not only do they add time and effort, many customers forget the answers they chose, resulting in additional steps needed for account recovery.
  • CAPTCHAs: CAPTCHAs are designed to protect against automated attacks. However, they can be defeated by attackers and make it more difficult for legitimate users to access their accounts.

At best, these password bolt-ons frustrate users and create additional friction; at worst, they are accessibility problems for those with cognitive or physiological disabilities. In both cases, they are easily circumvented by a determined cybercriminal performing an account takeover attack.

Passwordless authentication is the solution

Password-based authentication is not secure and will never be secure. Even if customers used unique, random passwords for each online account, these passwords would still be vulnerable to phishing attacks, data breaches, and other threats.

Creating a secure, streamlined user experience requires an alternative approach. The best solution is going passwordless with a FIDO-based approach. FIDO, or Fast Identity Online, is an open set of standard protocols promoted by the FIDO Alliance[1] for strong authentication using everyday consumer devices like mobile phones. While FIDO does not solve the problem overnight – it takes users time to switch to passwordless authentication – when done right, it begins to eliminate your biggest business risk: customer passwords.

FIDO-based authentication, as part of a well-designed customer identity and access management (CIAM) service, provides protection against the most common tactics used in ATO attacks, including:

  • Compromised credentials: FIDO-based authentication uses biometrics or digital signatures stored on-device for authentication. Users don’t need to memorize and enter secret data, so they can’t be tricked into revealing it to an attacker.
  • Phishing pages: Phishing attacks commonly use fake, lookalike pages to collect users’ credentials. FIDO-based authentication utilizes two-factor authentication: it validates both the customer and the online service they are using before authenticating, protecting against these attacks.
  • Credential stuffing: Credential stuffing attacks test for weak and reused passwords via automated attacks. FIDO-based authentication uses public-key cryptography for authentication, which requires access to a random, cryptographic private key to log in.

The best implementations of FIDO-based authentication completely eliminate passwords for users, from the point of registration through the entire customer journey. By eliminating passwords entirely, the right FIDO-based solution both reduces customer friction and eliminates a very common threat vector: stolen credentials.

Your customers care about cybersecurity

In a January 2022 research report entitled, “Build the Business Case for Cybersecurity and Privacy”, Forrester states that people are “drawn to brands with a strong security and privacy reputation.” They go on to say: “As a result of improved security and better self-service, clients mentioned that implementing services for customer identity and access management (CIAM) resulted in greater efficiency in customer acquisition, lower customer and shopping cart abandonment, and better conversion rates (customers signing up and buying on the site). Over time, these improved customer experiences will clearly link to increased customer loyalty, satisfaction, and revenue.”

Your customers are likely savvier than ever about how their accounts are protected. They care about cybersecurity, but they also choose to do business with companies that provide exceptional digital user experiences. By implementing the right passwordless CIAM service for your digital channels, you can both address the threat vector of stolen credentials and significantly reduce the effort your customers go through to login and transact. Achieve better security and a better experience.

To learn more about passwordless authentication, visit Transmit Security.


[1] Source


Read More from This Article: Customer Passwords are a Target for Cybercriminals: How to Address the Threat
Source: News

Category: NewsMay 5, 2022
Tags: art

Post navigation

PreviousPrevious post:The reality of workload portability across cloudsNextNext post:vFunction tool assesses technical debt for app modernization

Related posts

휴먼컨설팅그룹, HR 솔루션 ‘휴넬’ 업그레이드 발표
May 9, 2025
Epicor expands AI offerings, launches new green initiative
May 9, 2025
MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까?
May 9, 2025
오픈AI, 아시아 4국에 데이터 레지던시 도입··· 한국 기업 데이터는 한국 서버에 저장
May 9, 2025
SAS supercharges Viya platform with AI agents, copilots, and synthetic data tools
May 8, 2025
IBM aims to set industry standard for enterprise AI with ITBench SaaS launch
May 8, 2025
Recent Posts
  • 휴먼컨설팅그룹, HR 솔루션 ‘휴넬’ 업그레이드 발표
  • Epicor expands AI offerings, launches new green initiative
  • MS도 합류··· 구글의 A2A 프로토콜, AI 에이전트 분야의 공용어 될까?
  • 오픈AI, 아시아 4국에 데이터 레지던시 도입··· 한국 기업 데이터는 한국 서버에 저장
  • SAS supercharges Viya platform with AI agents, copilots, and synthetic data tools
Recent Comments
    Archives
    • May 2025
    • April 2025
    • March 2025
    • February 2025
    • January 2025
    • December 2024
    • November 2024
    • October 2024
    • September 2024
    • August 2024
    • July 2024
    • June 2024
    • May 2024
    • April 2024
    • March 2024
    • February 2024
    • January 2024
    • December 2023
    • November 2023
    • October 2023
    • September 2023
    • August 2023
    • July 2023
    • June 2023
    • May 2023
    • April 2023
    • March 2023
    • February 2023
    • January 2023
    • December 2022
    • November 2022
    • October 2022
    • September 2022
    • August 2022
    • July 2022
    • June 2022
    • May 2022
    • April 2022
    • March 2022
    • February 2022
    • January 2022
    • December 2021
    • November 2021
    • October 2021
    • September 2021
    • August 2021
    • July 2021
    • June 2021
    • May 2021
    • April 2021
    • March 2021
    • February 2021
    • January 2021
    • December 2020
    • November 2020
    • October 2020
    • September 2020
    • August 2020
    • July 2020
    • June 2020
    • May 2020
    • April 2020
    • January 2020
    • December 2019
    • November 2019
    • October 2019
    • September 2019
    • August 2019
    • July 2019
    • June 2019
    • May 2019
    • April 2019
    • March 2019
    • February 2019
    • January 2019
    • December 2018
    • November 2018
    • October 2018
    • September 2018
    • August 2018
    • July 2018
    • June 2018
    • May 2018
    • April 2018
    • March 2018
    • February 2018
    • January 2018
    • December 2017
    • November 2017
    • October 2017
    • September 2017
    • August 2017
    • July 2017
    • June 2017
    • May 2017
    • April 2017
    • March 2017
    • February 2017
    • January 2017
    Categories
    • News
    Meta
    • Log in
    • Entries feed
    • Comments feed
    • WordPress.org
    Tiatra LLC.

    Tiatra, LLC, based in the Washington, DC metropolitan area, proudly serves federal government agencies, organizations that work with the government and other commercial businesses and organizations. Tiatra specializes in a broad range of information technology (IT) development and management services incorporating solid engineering, attention to client needs, and meeting or exceeding any security parameters required. Our small yet innovative company is structured with a full complement of the necessary technical experts, working with hands-on management, to provide a high level of service and competitive pricing for your systems and engineering requirements.

    Find us on:

    FacebookTwitterLinkedin

    Submitclear

    Tiatra, LLC
    Copyright 2016. All rights reserved.