Rising attacks make password hygiene more important than ever

Credential stuffing attacks, in which attackers automate numerous attempts to compromise a large number of user accounts with stolen passwords, are rising exponentially.

New figures from Auth0 claim that despite credentials threats rising, the use identity management tools, or other security systems designed with minimizing the risk of attack often get deprioritized.

In the first 90 days of the year, Auth0 has found, credential stuffing took up 16.5% of all attempted login traffic on its platform. At the end of March, the figure peaked at more than 40%. The two industries bearing the brunt of these blows are travel & leisure, and retail. 

Approximately 15% of all attempts to register a new account, Auth0 has further discovered, can be attributed to bots. In the same timeframe of 90 days, Auth0 has seen more than 26,000 breached passwords every day. On the most peaceful of days, there was “only” 7,300 breached passwords, while the record-breaking February 9 saw more than 182,000.

There could be many reasons to deprioritize security measures, including budget constraints, lack of resourcing, or a lack of attention from the upper echelons of management. 

Password a "protective measure from the past"

Besides credential stuffing, which Auth0 claims is the most common threat these days, criminals will often go for fraudulent registration, multi-factor authentication bypass methods, as well as breached password usage.

For Duncan Godfrey, VP of Security Engineering at Auth0, businesses are part of the problem as failure to protect data is “industry-wide”. With criminals expanding their arsenal of automated tools by the hour, and security teams not having a proper horse for the race, the “humble password is a protective measure from the past,” he claims. 

In today’s world, relying on passwords for security is a risk in itself. 

“Despite ongoing guidance around proper password creation and repeated warnings against password reuse, consumers crave convenience and continue to use the easiest and most convenient path for application access,” said Shiv Ramji, Chief Product Officer at Auth0. 

“A passwordless future is largely being driven by two primary forces — security and convenience. Companies want to secure the vulnerabilities that come with passwords, and they also want to offer their users a better digital experience.”



from TechRadar - All the latest technology news https://ift.tt/3gAyXsq
Share:

Related Posts:

No comments:

Post a Comment

Categories

Rove Reviews Youtube Channel

  1. Subscribe to our youtube channel
  2. Like our videos and share them too.
  3. Our youtube channel name Rove reviews.

WITNUX

This website is made by Witnux LLC. This website provides you with all the news feeds related to technology from large tech media industries like GSM Arena, NDTV, Gadgets 360, Firstpost and many other such ates altogether at technical depicts so that you need not go to several sites to view their post provide you advantantage of time.

From the developer
Tanzeel Sarwar

OUR OTHER NETWORKS

OUR YOUTUBE CHANNEL

ROVE REVIEWS PLEASE SUBSCRIBE

OUR FACEBOOK PAGE

The Rove Reviews

Support

Trying our best to provide you the best DONATE or SUPPORTour site Contact me with details how are you gonna help us