• Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
SUBSCRIBE
Smart Solutions World
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions
No Result
View All Result
No Result
View All Result
Home Solutions News World | Latest Tech & Innovation Updates

World Password Day: Sophos Calls For the End of the Password

SmartSolutionUser1 by SmartSolutionUser1
May 1, 2025
in Solutions News World | Latest Tech & Innovation Updates
0
World Password Day: Sophos Calls For the End of the Password
74
SHARES
1.2k
VIEWS
Share on FacebookShare on Twitter

On the occasion of World Password Day, Sophos stresses the limits of passwords and knowledge-based authentication methods. Indeed, the sophisticated techniques, tactics, and procedures (TTPs) of cyber attackers in 2025 will enable them to easily circumvent traditional authentication methods. As such, the 2025 edition of Sophos’ Active Adversary report indicates that compromised credentials represent the leading cause of attack for the second year running (41% of cases). It is therefore essential that users and companies adopt more robust methods to protect their data against credential theft.

You might also like

Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

The limits of knowledge-based protection

Dual or multi-factor authentication (2FA/MFA) solutions are widely adopted. However, like the password, these additional layers of protection often rely on knowledge-based secret codes shared via SMS or authentication applications. Unfortunately, many of these methods remain vulnerable. Hackers now have tools at their disposal which, like evilginx2, make it easy to bypass these protections by automating phishing or stealing session cookies.

This means that the path of constantly postponing the moment when passwords become obsolete, through fragile additions, seems fraught with danger. The reality of the cyberthreat landscape should push companies towards a paradigm shift away from the password model and knowledge-based shared secrets.

WebAuthn and access keys: towards stronger multifactor authentication?

To protect against phishing, the WebAuthn protocol – which uses access keys or passkeys in particular – is now the subject of consensus among cybersecurity experts. With this method, when an account is created, a unique public/private cryptographic key pair is generated. These are then stored locally: on the site’s server for the public key, and on the user’s terminal for the private key, along with the site name and user ID.

To log in, the user no longer needs to enter a password or secret code shared via SMS or an authentication application. Instead, the server sends a digital authentication request that can only be resolved if the user is in physical possession of a device and can prove that he or she is the owner of the private key – through biometric verification, for example. Authentication is therefore still based on two factors, but these do not depend on the user’s knowledge, but on the physical possession of the device and the user’s own biometric characteristics. In principle, therefore, they cannot be stolen using conventional phishing methods.

What’s more, the authentication process includes a two-way check that enables the user to verify the identity of the service by means of the site domain, sent when the server requests authentication. Unlike methods that use knowledge-based passwords and secret codes, the user is no longer the only one required to prove his or her legitimacy.

Precautions to be taken to ensure robust, simplified authentication

This new industry standard, based on the FIDO2 standard, appears to offer proven protection against phishing – the main threat vector for credential theft – while simplifying authentication for users.

Nevertheless, while WebAuthn represents a major step forward, several vulnerabilities remain, and vigilance is still called for:

  • It is imperative to ensure that the device or cloud where keys are stored is secure;
  • The successful transition to WebAuthn requires buy-in and adoption by businesses and departments;
  • The theft of session cookies remains an attack vector that would enable cyber-attackers to bypass this protection.

It is important to bear in mind that cybercriminals are constantly perfecting their attack methods. That’s why adopting these technologies should be a strategic cybersecurity priority for businesses today.

According to Chester Wisniewski, Director, Global Field CISO at Sophos: “We need to move away from reliance on passwords and shared secrets. Access keys or passkeys today represent the most robust solution for building a future without passwords, phishing and, hopefully, large-scale compromise.”

Tags: World Password Day
Share30Tweet19
SmartSolutionUser1

SmartSolutionUser1

Recommended For You

Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

by SmartSolutions
December 5, 2025
0
Calculus Partners with Aprecomm to Bring Next Generation AI-Powered Network Intelligence to ISPs Throughout MEA, Asia, and Latam

Calculus, a global leader in advanced network innovation, announced a strategic partnership with Aprecomm, a leading provider of intuitive, self-healing network and customer experience solutions. The collaboration sees...

Read moreDetails

Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

by SmartSolutions
November 19, 2025
0
Tech Mahindra and DFKI Collaborate to Co-innovate and Co-create Smart Factory Solutions for German Enterprises

Tech Mahindra, a leading global provider of technology consulting and digital solutions to enterprises across industries, and Deutsches Forschungszentrum für Künstliche Intelligenz GmbH (DFKI), German Research Center for...

Read moreDetails

GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

by SmartSolutions
November 13, 2025
0
GoPro Unveils MAX2, LIT HERO, and Fluid Pro AI Cameras in India

GoPro announced the availability of its three new cameras in the Indian market. MAX2 – the highly anticipated next-generation GoPro 360 camera featuring Emmy® Award-Winning 360 Technology for...

Read moreDetails

Delvitech closes a $40 million investment round, among the most significant Deep Tech investments in Switzerland

by SmartSolutions
November 12, 2025
0
Delvitech closes a $40 million investment round, among the most significant Deep Tech investments in Switzerland

Delvitech, a Deep Tech company specializing in the development of AI-native Automated Optical Inspection (AOI) solutions for electronics, successfully closed a Series B investment round of USD 40...

Read moreDetails

SAP and Snowflake Partner to Unlock Enterprise AI and Data Potential Through a Unified Business Data Fabric

by SmartSolutions
November 12, 2025
0
SAP and Snowflake Partner to Unlock Enterprise AI and Data Potential Through a Unified Business Data Fabric

Snowflake, the AI Data Cloud company, and SAP SE, a global leader in enterprise applications and business AI, announced a new collaboration to enable organizations to seamlessly leverage...

Read moreDetails
Next Post
Tenable Appoints Eric Doerr As Chief Product Officer

Tenable Appoints Eric Doerr As Chief Product Officer

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Related News

Cisco Unveils AI Defense To Secure AI Applications

Cisco Unveils AI Defense To Secure AI Applications

January 17, 2025
Nutanix Releases Latest Version of Nutanix Enterprise AI

Google Cloud Unveils New AI Retail Solutions 

January 13, 2025
Nagarro becomes OpenAI Services Partner to support industry-scale AI adoption

Nagarro becomes OpenAI Services Partner to support industry-scale AI adoption

December 10, 2025

Browse by Category

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized
Smart Solutions World

We bring you the best Premium news, magazine, personal blog, etc. Check our landing page for details.

CATEGORIES

  • Agora
  • AI
  • Article
  • AV Solutions
  • Business
  • Careers
  • Case Study
  • Cover Story
  • cyber security
  • EDU Solutions
  • Featured Article
  • Finance
  • Gartner
  • Global Academic
  • Health
  • Indian Government
  • Innovation
  • Interview
  • Interview
  • IT industry,
  • Jobs
  • Market
  • Networking
  • Nucleus Software
  • Open Ai
  • Politics
  • Products
  • Products Plus
  • projects
  • Security
  • SentinelOne®
  • Software
  • Solutions
  • Solutions Launch world
  • Solutions News World | Latest Tech & Innovation Updates
  • Startups
  • tech mahindra
  • Technology
  • Terafac Technologies
  • Uncategorized

BROWSE BY TAG

Accenture Acquisition Adobe Agentic AI AI AI-powered AMD automation Check Point Software Cloudflare CrowdStrike CyberArk Cybersecurity Databricks Fortinet Gartner GenAI Google Cloud Hitachi Vantara Honeywell HP IBM Infosys Kramer LTIMindtree Microsoft NetApp New Relic Nvidia OpenAI Palo Alto Networks PPDS Qlik Salesforce security ServiceNow smart solutions world smartsolutionsworld smart solutions world latest news Snowflake Software Tech Mahindra Technology Tenable Vertiv

© 2024 NCN - Premium news & magazine by NCN.

No Result
View All Result
  • Solutions Launch
  • Solutions News
  • Cover Story
  • Featured Article
  • Interview
  • Products Plus
  • Case stady
  • AV Solutions
    • Article
    • Interview
    • Products
    • Case Study
  • EDU Solutions
  • Solutions

© 2024 NCN - Premium news & magazine by NCN.

Are you sure want to unlock this post?
Unlock left : 0
Are you sure want to cancel subscription?