Hi, I'm Tom Field, senior vice president of editorial with information security media group. My topic today is passwordless authentication. It's my privilege to be speaking with Jeff Carpenter, his director of identity and access management solutions with HID Global. Jeff, thank you so much for joining me today.
Tom's good to be here with you today. So passwordless authentication, huge topic. Everybody's talking about it. But what do they really mean when they're discussing this?
Yeah, you know, the term passwordless, by the way, it's not a real word. It's kind of a word our industry is adopted. You'll get the autocorrect if you ever type it into a document. But it's been around for about five or six years and at its simplest distillation, what it means is take away the user's involvement in selecting their own password and replace it with something else, something that's stronger and more predictable and essentially change that user experience so that the result is a more seamless user interaction when they go to log into any application and a reduction in enterprise risk because you're not hanging a simple password out there that can be fished and stolen by bad guys and used to attack your organization.
So Jeff, with everybody's individual and collective dependencies on passwords, is it actually possible to achieve what we think about when we talk about a passwordless authentication? Yeah, you know, that's a great question, Tom. You know, as you know, Shakespeare's Hamlet said, it's a dream devoutly to be wished. But we think in our industry, and by the way, it's been my passion at life's work for the last 10 years to really focus on that question.
And if you ask me, you know, five or six years ago, I would have said it's going to be a real uphill struggle. But now I think we've turned the corner and we're starting to see enterprises really move towards this concept of passwordless, even though we're still in the infancy of, you know, if you look at a growth curve, we're in the very nascent early days of this concept of passwordless. But the simple answer is yes. But it's not something that you can just wave a magic wand, you know, wave your magic IT wand and achieve.
You really have to look at it and you'll breaking down into a couple phases. And the first is you have to make a dedication as an organization to say, look, you know, we've got some strong authentication over here, and we've got some loosey goosey password procedures over here on this side of the business, maybe because of an acquisition or maybe because it's just some perceived low value applications. Wherever they exist, you have to take an enterprise risk level approach and make an assessment and put MFA in front of those applications. That's really the first step.
Once you have that in place, then you need to say, well, where can we improve on this experience? Because, you know, you and I both know MFA has not been the solution. MFA has been around for, you know, 30 years. Why hasn't it solved the problem that we're trying to deal with?
And the answer is because it's difficult to deploy, users often revolt against it if they have to, you know, go through multiple hops and in different enrollments. And then for this application, I have to do this and then for that application, I have to do that. So the second phase of this is you have to take a look at the usability. You know, once you've locked everything down, now how do we make it easier for the user?
And once you've come to that part of it, the usability part, then you're going to get the buy-in from users to then move into that next phase, which is to say, how do we move to true password list? In other words, take away the user's ability to select those passwords and replace it with fill in the blank. So a biometric, a FIDO2 key that they carry around, something that they do on their mobile phone. It can even be a behavioral biometric.
Nothing that the user has to do other than be themselves. So there's a lot of different ways you can get to password lists, but it is a journey. And that's the number one thing that we advise our customers on. So Jeff, you talked about the method you talked about the usability.
What are some of the real business benefits that can be realized? Absolutely. Well, you know, the biggest benefit that most organizations will see is a stop to the breaches and hacking that we've seen. You know, there's a tremendous realization out there, first of all, you know, because I say that, you know, Thomas, as somebody who's been on this journey for a long time is, you know, a while back, people believed, and you know, 10 years ago, you went to the RSA conference, people would tell you, well, you know, you can lengthen and strengthen a password.
You know, I had one guy tell me that they required all their users to use 15-digit passwords. I mean, that's just crazy. That does not take into account the user experience. And what it does is it opens up your organization actually more hacking because users are going to write those things down.
They're going to use the same password amongst 20 different applications, some of them are their enterprise applications, some of them are their home applications. So the password can be stolen or fished from a user from their home application and then associated with your organization and then that guy's just walking in front door. But if you actually implement true passwordless authentication, you take away the user's ability to select these passwords and you replace it with something else, say like a pin plus a strong biometric, then you're going to see a reduction in breaches, you know, getting hacked from user-selected passwords. But there are also other benefits.
I mentioned usability. Users really like the ability to have one seamless experience. No matter what the application that they're trying to access, there is one pathway and they're already enrolled to get to that application. You know, and then the final benefit, I would say if you implement it right, you're actually going to increase productivity because you're not having users trying to reset passwords every 90 days, calling the IT help asking opening tickets, trying to, you know, funnel around with how to enroll in this type of authenticator to get to this type of application.
And it's just going to provide a lot of benefits for them. Jeff, you talked about the implementation. Who is actually doing this today? Yeah, as I mentioned, we're on the very early curve on this.
So if you're out there listening and you're saying, wait, you know, I haven't implemented passwordless. I must be fine. You're okay. Start your journey.
Get curious about what that looks like. An organization that's gone very public with this is Google. Google is passwordless. So when people say, well, no one's actually doing that.
I say no, you know, Google, Google passwordless. They committed as an organization three years ago to the FIDO2 standard and to issuing Yubikis to all their employees. So if you're not familiar with Yubikis, it's a USB key that inserts into your computer. So every Google employee from the day they start is issued one of these Yubikis tokens and they have to insert it into their PC.
That gives the assurance that they are who they say they are. It also does what's all proof of presence. So in other words, hacker, you know, all the way around the other side of the world could not stick physically stick that USB key into that Google user's PC. And then when they pull it out, then it logs them out and they're no longer able to access any of those applications.
And this is from public information that Google has published. They claim that since 2017, they haven't had a user breach from a user credential. And that is astounding given the high profile of that company. And, you know, all of the different pieces of business that they have out there, because really Google is the ultimate online company.
All of their stuff is out there. So Google can do it. Our message is, you know, you can do it too. You just have to figure out, you know, what way is right for you and, you know, the best approach that will work for your organization.
Jeff, as you said a few minutes ago, this has been your passion for several years now. So you've got a unique view into what the future might look like. What do you see as the future of passwordless authentication? Well, you know, I tell you Tom, I look forward to the days when we all kind of snicker and laugh at the retiring of the static password, you know, user selected password.
We will get there. You know, I have seen the future and it is right and we will get there. But I always look at this, you know, when I was taking my CISSP, you know, exam 10 plus years ago, the thing that always stuck out to me was, you know, how you think about a challenge like this, you think about it in terms of people, processes and technology. And, you know, you always look at people first, you know, where are your users at?
Where's your IT staff, you know, what's the maturity experience level of your staff there? And you start from there, because there is a realization, you know, no, no two organizations are the same. What works for Google is not going to work for example, a healthcare organization where you have users wearing gloves and masks and, you know, they're not necessarily wanting to stick a USB key into a PC, you know, that's shared by multiple people. So you start with what's going to work with your organization from a people perspective, and then you move into process.
You know, what is the process for enrolling new users? What's the process for troubleshooting existing users? And what's the user acceptance testing? Because not all users want to carry something, not all users have mobile phones, not all users can use a biometric.
And in many organizations, we're finding it's a combination of those different things. And finally, technology. And I will say I do believe the technology is there to do it today, especially you mentioned, you know, FIDO2 and Yubiki and a number of others, including HID, which have our own FIDO2 authenticators. But the technology in many ways is the minor part of the story.
And you really have to look at, you know, the organization, the people, your processes, and then the technology. And my biggest advice to organizations is get curious, start today, lock everything down with multifactor authentication, figure out your usability story, how you can make it easier for users to enroll, and then finally, take away all those passwords where they exist and replace them with this technology that you've deployed. Well, Seth, Jeff, I got one more question for you. Talk to me about HID Global.
What are you doing to help customers step into this future you've just described to us? Sure. Well, at HID Global, we are an identity company. And we've laid our claim in this area for a very long time.
Chances are, if you badge into your office, you have an HID card that allows you to do that. We've been doing that for, you know, 20 plus years, and we're really well known in this space. And as I said, we are passionate about helping organizations achieve this goal. We are a member of the FIDO Alliance.
So we're helping to steer all of these organizations that have committed to a passwordless future, you know, into that. But what I would say is, you know, as an organization, what we do, and our greatest value to you, our listener out there, if you're interested in a passwordless, is not to push any one technology on you, but to have a conversation with you about where you're at today. And it's okay if you're coming from a place of, hey, we still have static passwords out there everywhere. That's okay.
We'll have a conversation with what you can do here, given your budget, given your, you know, your IT capabilities to get something in place that's going to lower your risk profile, get your users much happier and productive in what they do. And most importantly, get you on a pathway that protects your data, provides usability, but gets you to that ultimate goal down the road of a passwordless future. Great insight, Jeff. Thanks so much for taking time to speak with me today.
You're welcome. Thanks, Tom. Again, the topic has been passwordless authentication, and I've been speaking with Jeff Carpenter, he's Director of Identity and Access Management Solutions with HID Global. For Information Security Media Group, I'm Tom Field.
Thank you very much.