Select your language

300% increased the number of password thefts

robo contraseñasInternational. Successfully logging in using a password no longer guarantees legitimate access to a sensitive system and accounts. This is why Appgate, a company specialized in cybersecurity, explained the importance of implementing secure authentications to protect against digital threats.

The number of exposed credentials has increased by 300% since 2018, according to data from Security Magazine, and that growth has exposed that user keys and passwords are an ineffective method as secure authentication. However, the vast majority of organizations continue to bet on this model.

The first thing to be clear about is that each authentication factor has a place within one of these three categories:

Knowledge: This category refers to something that is known. The simplest example is a user's password. However, because it is easy to manipulate these credentials, the knowledge category is the least effective at implementing secure authentication.

- Publicidad -

Possession: It relates to something that is possessed and is considered a category of strong authentication because it is more difficult to manipulate. That the user must have something physically with them adds a challenge, but it is still not an infallible measure.

Inherent: This is the strongest category of authentication. It's much harder for scammers to replicate human characteristics, so this inherent category becomes a less affordable target for cybercriminals.

"None of these three categories is enough to successfully apply secure authentication, so it is necessary to use at least two models that belong to different categories. Something that the user knows (knowledge) combined with something that is (inherent), protects more efficiently," explains David López, vice president of sales for Latin America at Appgate.

Each authentication factor has its advantages and disadvantages. Appgate then presents an overview of the evolution of authentication.

● The first password-based system was created in the early 60s at MIT, which means that the password is more than five decades old and even back then, it was also not secure. Although they are easy to install and are cost-effective, they end up being a weak authentication factor and easy to breach.

● Hard tokens were first patented in the late 80s. They provided a one-time password and displayed a random number that changed periodically. Although the unique numerical code changes with frequency and makes it difficult to manipulate, it is an outdated system that has been replaced by much more accessible smart devices.

● Device recognition: Cookies were created in the late 90s and became commonplace in the early 2000s. They were the first example of large-scale device recognition. This technology has evolved and improved by incorporating various methods that are constantly updated, however, fraudulent actors can access a device remotely using a Remote Access Trojan (RAT).

● SMS: They were widely used in the early 2000s and marked the beginning of the distribution of passwords to phones in general. It's a simple way to implement a secure authentication system. However, it turns out to be an inconvenience for users who have lost their device, or who no longer have access to the registered phone number.

● Push: Blackberry was the first to use push notifications, but Google and Apple took it upon themselves to generalize them in 2009 and 2010. This factor presents a pop-up message on a mobile device allowing the user to accept or reject a transaction or login attempt. It is a very secure method as it is reinforced at the device level, but it depends on the user having access to the device originally registered in the account.

- Publicidad -

● Fingerprint biometrics: Apple's touch ID popularized fingerprint biometrics in 2013. This method simply requires the thumbprint of the registered user to confirm their identity, which makes it difficult for a scammer to replicate.

● QR authentication: The WhatsApp website launched QR authentication in 2015. QR codes offer a secure way of authentication, providing each user with a unique code. It is a fast, convenient and very secure form of authentication, but it can only be used in out-of-band processes.

● Facial Biometrics: Apple's Face ID was one of the first examples of facial biometrics for authenticating users. Among the disadvantages is that it depends on the lighting and the angle of the user's face and can also be intercepted by a photo or video of the user.

"It will be interesting to see how the various authentication systems continue to evolve. Biometrics is likely to be the way of the future and will eliminate passwords altogether. Data and context analysis based on the user's usual behavior provide a broader view, so they are a challenge for the user without causing problems," says López.

Although many authentication models provide some level of protection, no model is effective enough on its own. That's why it's important to ensure that organizations implement secure authentications using multiple models within different categories.

Duván Chaverra Agudelo
Duván Chaverra AgudeloEmail: [email protected]
Editor Jefe
Jefe Editorial en Latin Press, Inc,. Comunicador Social y Periodista con experiencia de más de 13 años en medios de comunicación. Apasionado por la tecnología.

No comments

• If you're already registered, please log in first. Your email will not be published.

Leave your comment

In reply to Some User
Security becomes a technological platform

Security becomes a technological platform

Mexico. Security is moving from a set of standalone systems to an integrated technology platform that combines artificial intelligence, video analytics, sensors, access control, and data platforms....

Security industry in Mexico and Latin America continues its expansion and professionalization

Security industry in Mexico and Latin America continues its expansion and professionalization

International. The security industry in Mexico and Latin America maintains a growth trend driven by digital transformation, the increase in physical and cyber risks, as well as the need to protect...

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

Veeam Introduces Agent Commander to Address AI Agent Risks in Enterprise Environments

United States. Veeam Software today announced the launch of Agent Commander, a solution aimed at helping organizations detect risks associated with artificial intelligence, protect AI-based systems...

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

Key and asset management, the key to optimizing operations in logistics, distribution and construction companies

In industries where every minute counts, efficient asset and resource management has become a strategic factor to ensure operational continuity, safety, and productivity. By: Héctor Meléndez,...

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Genesis Security Reduces False Alarms by 62% Through Milestone Integration and Actuate AI Analytics

Puerto Rico. A centralized monitoring operation developed by Genesis Security was able to significantly reduce the volume of false alarms in its security systems, thanks to the integration of...

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Case study: Solar cameras and thermal intelligence optimize the safety of aquaculture farms

Türkiye. An open-ocean fish farming farm in Turkey implemented a smart surveillance system based on Dahua solar cameras, thermal monitoring, and wireless data transmission to improve safety and...

 The Hidden Security Gap in Data Centers

The Hidden Security Gap in Data Centers

Imagine the journey of an authorized technician inside a data center. When he arrives, he presents his credential and enters the premises, and before entering the server corridor he needs a key to...

Digital fraud increased at Christmas

Digital fraud increased at Christmas

Colombia. During the holiday season, as e-commerce and digital transactions intensified, online fraud attempts also increased. Fake promotions, impersonation of businesses and messages that...

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Milestone XPerience Days arrived in Mexico City with innovations in intelligent video management

Mexico. Milestone Systems, a leading provider of open platform video management software (VMS), hosted the Milestone XPerience Days Mexico 2025 event, a gathering that brought together industry...

Hikvision Mexico launches the third edition of

Hikvision Mexico launches the third edition of "Hikvision Women"

Mexico. Hikvision Mexico announced the launch of the third edition of its "Hikvision Women" program, an initiative aimed at strengthening the participation and professional development of women in...

Suscribase Gratis
Remember Me
SUBSCRIBE TO OUR ENGLISH NEWSLETTER
DO YOU NEED A SERVICE OR PRODUCT QUOTE?
LATEST INTERVIEWS
SITE SPONSORS










LATEST NEWSLETTER
Latest Newsletter