Taus Noor

What is the future of passwords on the Internet?

by
Where do you see passwords in the future? Do you think passwords will always be around? Or are we headed to a fully passwordless Internet/world? Bonus question: what kind of biometric auth do you feel most comfortable with? Full disclosure: I'm working on a product related to passwordless auth.
31 views

Add a comment

Replies

Best
Tedel
I will quite likely stick to using passwords for the rest of my life. I do not trust anything biometric for two reasons: It is something you cannot share in an emergency (e.g. Sister! Someone just stole my mobile! Please, log into my account and change the password!); and it is something that may be used as a motivation to keep you close. For example, if you are ever unlucky enough to be kidnapped, and all you passcodes are biometric, they will not release you until you have unlocked for them everything they want.
Arseniy
@simplytedel definitely agree with the first point, the second is more nuanced and there's a whole debate to be had about it
Taus Noor
@simplytedel Sharing in an emergency is a very interesting point. However, if you use biometric as your password -- stealing your phone should not give anyone access to anything really, right? Since they'd still you to actually log in or do anything?
Vincent Offredo
It would be interesting to think about a decentralized identity. Each user is the sole manager of his identity, which is logical! With a decentralized identity, the user could connect to any service that recognizes / validates this type of identification. With a decentralized identity, we can go further than the future of the password
Taus Noor
@vincent__off Would love to learn more about this. Would you be willing to connect over a call to discuss this?
Adrian Pradilla Portoles
I think it will be a two step authentication retina/face and password validation on the mobile or other device with the fingerprint
Taus Noor
@adrian_pradilla_portoles Do you think this will be the norm across all services we use or just specifically stuff that are more sensitive (like payments, etc.)? Having to enter a password and biometric could be inconvenient for users, so would love to learn more about your thoughts on this.
Peter Bartnik
The decentralized identity market has certainly been busy. Gartner's 2020 Market Guide to User Authentication provides a good overview of the passwordless market and the major players. For a detailed description of the challenges and one leading vendor's take, try this report from HYPR: https://www.hypr.com/wp-content/... The big challenge for new entrants is how to break down the walls of the enterprise solution providers access and authentication stacks and not be relegated to point solutions status.
Mads Schmidt Petersen
Cool. Password less, biometric less, lots of places to go. I'm working on a product in this space too. Good luck!
Taus Noor
@madsschmidtpetersen Oh wow would love to learn more. Would you be open to a call at some point?
--
Passwords will soon be a matter of history
Taus Noor
@suvigya__ We sure hope so!
ALC
When I research the identity part. I found that the most challenge is not security, but the economy around it. The authentication mechanism these days requires a lot of infrastructure. You need an internet connection (minimum is 1 USD of internet/month), a device that is not considered deprecated by the standard (ex. you can't even use the app if your android does not at least version 6), a common sense of a user (ex. aging people do not know how to use IT, younger people doesn't care enough about it). With only these factors, it already prevents more than half of people in the world to use the service.
Taus Noor
@anugoon_leelaphattarakij This is an interesting point -- how do you think we can solve that?
Mushahid Shamim
What is the probability of false prediction if every internet user in the globe use GazePass? What is the accuracy of Liveness detection? If I manage my webcam to input the recorded video of someone's account I want to hack how your system would act? Can I use this service in online payment service! If it authenticate a wrong user by any mistake who will take the responsibility? These questions resides around my mind when back then I used to think of this kind of service in action. Also it seems a vertical problem, so why big tech giants are not incorporating it in their services?
Taus Noor
@mushahid2521 Great question. We actually won't let you log in to someone else's account from your device just using face recognition -- so even if you get a webcam recording, it won't help. Email OTP verification is needed alongside face recognition to access someone's gazepass account on a new/different device. As for the rest -- subscribe and stay tuned! https://gaze.ai/ph
Muhammad Abdullah Al Akib
I am not sure password will go away, but right now i think biometric will be the option, and i also think face recognition is also a thing to consider
Richard Blake
Is it possible to make all websites use Retina sensor?
Taus Noor
@livedrawhksgp Not sure about retina alone - but definitely possible to have all websites use some form of biometrics