Is Passwordless Authentication Secure? Why Do We Still Use Passwords?

Ғылым және технология

Rich or poor, everyone wants to have a good lock on their door, right? It’s a matter of security and it’s an obvious need. Passwords are the keys to our private slice of the internet’s cake, and perhaps its virtual nature means we don’t take it seriously enough.
We wouldn’t leave sensitive documents such as our proof of address on the bus, would we? However, we’re more than happy to make classic security mistakes when it comes to the security of our online data.
That's why security experts are constantly working on new, reliable and user-friendly authorisation methods that make it easier for us to keep our data safe.
So, are passwords going to be left in the dust of antiquity? Let’s find out.
Sumsub - empowering compliance and anti-fraud teams to fight money laundering, terrorist financing, and online fraud.
#Sumsub #digitalsecurity #personaldata
00:00 - Intro
00:59 - A Blast from the Past
04:27 -The Human Factor
10:51 - Single Sign On
13:42 - Two-factor Authentication
15:09 - Password-free Authentication
18:20 - Conclusion. Why Do We Still Use Passwords?
More about us:
sumsub.com
/ sumsubcom
/ sumsubcom
/ admin

Пікірлер: 91

  • @IKEMENOsakaman
    @IKEMENOsakaman2 жыл бұрын

    Some people watching will have good passwords, Some people will have thought about this before, Some people should have thought about this and haven't, And hopefully will, after we talk about this, a little bit more.

  • @yepitsarif
    @yepitsarif2 жыл бұрын

    This channel has insane amounts of quality content. Everything ranging from the set, to the editing and the way you speak and explain topics is fantastic. I thought you had millions of subscribers the first time I watched your videos and I was shocked to find out that that didn't. You definitely deserve more!

  • @jurgor8661

    @jurgor8661

    2 жыл бұрын

    That's why this channel is growing really fast. Success in KZread is simple but it for sure isn't easy to make top notch content like this. Simple does not equal easy.

  • @sumit6972
    @sumit69722 жыл бұрын

    I don't understand why the videos have such low view counts! This is literally gold of a content right here! For Free!

  • @Sumsubcom

    @Sumsubcom

    2 жыл бұрын

    Or is it? Maybe we're harvesting your online DNA for our matrix-style human energy converter.

  • @passionatebeast24

    @passionatebeast24

    2 жыл бұрын

    @@Sumsubcom 😂😂

  • @IKEMENOsakaman
    @IKEMENOsakaman2 жыл бұрын

    It's all fine and cool until you have to use a website that either (1) forces you to use uppercase, number, symbol, runes, smoke signals, etc. OR (2) limits your password to something like 12-16 characters...

  • @boggless2771

    @boggless2771

    2 жыл бұрын

    What's even worse is one that forces you to those smoke signals, and another website doesn't allow smoke signals. Then You really need dozens of passwords

  • @Querxes
    @Querxes2 жыл бұрын

    This channel is by far one of the best upcoming channels I've seen in a long time, hooked with every video!

  • @JasonBechervaise
    @JasonBechervaise2 жыл бұрын

    First, I love this channel. Second, it rather bothered me that the words 'authentication' and 'authorization' were used interchangeably. Athentication: proves you are who you claim to be, so that you can login to your account (e.g. username, password, 2FA/MFA, security questions, etc). Authorization: allows you to perform certain actions after you have been authenticated (e.g. account privileges for regular user vs administrative user, etc).

  • @sbcinema
    @sbcinema2 жыл бұрын

    What most people don't realize is that this benefit comes with a major downside, two-factor identification makes it difficult, to stay anonymous...

  • @Ben-li9zb

    @Ben-li9zb

    2 жыл бұрын

    And difficult to log into new devices

  • @qq84

    @qq84

    Жыл бұрын

    And if you lose your hardware key, you better have another one registered or you can't log in. And many services that offer FIDO only allow to register one. Often/mostly 2FA is only an excuse to get your phone number.

  • @TheRegelation
    @TheRegelation2 жыл бұрын

    Good times breed weak passwords. Weak passwords breed bad times. Bad times make strong passwords. Strong passwords create good times

  • @KenMiller
    @KenMiller2 жыл бұрын

    An informative video. Although I would have liked to have seen more attention given to password management systems.

  • @qq84

    @qq84

    Жыл бұрын

    Yes, he shouldn't only have called out the problem, but also offered a solution. And that's password managers.

  • @zippyit
    @zippyit2 жыл бұрын

    Do you have a different set for every video or are they a 3d rendering?

  • @Bradmagus
    @Bradmagus11 ай бұрын

    I love how much history is packed in these videos

  • @KeatingMark
    @KeatingMark2 жыл бұрын

    Quality content as always, Making boring topics interesting and entertaining!

  • @qq84
    @qq84 Жыл бұрын

    Use a password manager, and make/have backups for it! 16:04 Another big advantage is that passwords work cross platform without any problems. Try to use a USB-based FIDO hardware key (like the ones you showed) on a smartphone... 18:20 Changing passwords regularly is a bad idea and even decreases the security. 19:40 ...because "conspiracy theories" are true. Or are the Snowden leaks, that are exactly about that topic, also "just a conspiracy theory"?

  • @invincible18th51
    @invincible18th512 жыл бұрын

    Keep it up guys. I remember that password strength to pass crack chart on reddit. 12 character password is the new minimum as processing power goes up it's harder for us to remember. By the way any thoughts on making a reddit sub?

  • @_GhostMiner
    @_GhostMiner2 жыл бұрын

    *The last time I've seen a security question when creating or logging into an account was probably around 10 years ago.* 😅 I guess everyone realised how pointless and insecure they're.

  • @Cookiekeks

    @Cookiekeks

    2 жыл бұрын

    Windows uses it to this day

  • @_GhostMiner

    @_GhostMiner

    2 жыл бұрын

    @@Cookiekeks you mean the pointless shlt when creating an account with the UWP shlt?

  • @Cookiekeks

    @Cookiekeks

    2 жыл бұрын

    @@_GhostMiner UWP? I don't know what that is. I mean the normal windows accounts. They require security questions

  • @_GhostMiner

    @_GhostMiner

    2 жыл бұрын

    @@Cookiekeks UWP are the ugly windows Microsoft calls universal windows platform.

  • @whtiequillBj
    @whtiequillBj2 жыл бұрын

    Why don't we move to Secure Certificates? Where your system puts a certificate on your system. This was used by a certificate authority called AStart. They aren't around anymore. You logged in once and then they would put a certificate on your system which was then used to log you in when you came to their site. Do certificate authorities have a problem with this? If this was used then a hacker would need to get onto your hardware your very device that you are using to log into any of your sites.

  • @ShiroIsMyName

    @ShiroIsMyName

    Жыл бұрын

    A hacker could also reproduce the digital signal of your certified hardware, which would grant him access

  • @whtiequillBj

    @whtiequillBj

    Жыл бұрын

    @@ShiroIsMyName A foolproof solution is never going to happen. It would be harder, in my option, to fake security certificate then a password. Also at this time it wouldn't be expected because the technique it's used right now for log in credentials.

  • @nicolp1028
    @nicolp10282 жыл бұрын

    I love ur videos! there are really good designed and well strucurized! keep up! good and steady work wilk pay out

  • @ruknettintekir
    @ruknettintekir Жыл бұрын

    Great production.

  • @forbiddenera
    @forbiddenera2 жыл бұрын

    One of the biggest issues with password complexity requirements is the lack of consistency too..was this the site that required an uppercase or a symbol or was it another site? Plus those complexity requirements have to be advertised so the attacker knows exactly what is valid or not too. Passwords suck though.

  • @parzivaldesigns6611
    @parzivaldesigns66112 жыл бұрын

    Your content quality is unbelievable.

  • @rennnnn914
    @rennnnn9142 жыл бұрын

    I'd like to use teh fingerprint facility of my phone but I work on a farm. In the past I've had too much trouble trying to log in when my fingerprints have been worn down by work, or cuts won't let them be recognised. Voice recognition won't work when you're tired or have a cold. It's too big a risk that I can't get into my account when needed. When they come up with a biometric scanner that works better I might try again.

  • @Sumsubcom

    @Sumsubcom

    2 жыл бұрын

    Rowan, at least you're safe to burgle.

  • @jeremysanchez8118
    @jeremysanchez81182 жыл бұрын

    I'm 88.3% percent sure the set is 3d, but it looks really good regardless of it being real or not

  • @wild-radio7373
    @wild-radio73732 жыл бұрын

    Thank you sir ☺

  • @BrunodeSouzaLino
    @BrunodeSouzaLino2 жыл бұрын

    I like that some alternative authentication methods don't work for everyone. There's a significant number of people out there which don't have fingerprints. Or they wore out over time.

  • @SamiTheAnxiousBean
    @SamiTheAnxiousBean2 жыл бұрын

    pretty Interasting video great work and research as always

  • @azharable22
    @azharable22 Жыл бұрын

    Great content

  • @alexeiutgoff7955
    @alexeiutgoff79552 жыл бұрын

    I just use my username as my password for everything. So I don't forget them. Secretly added an ! At the end though so it's harder to guess. 4:00 Shout-out to that one guy who commented saying he had some hash function super computer lmao

  • @ShiroIsMyName

    @ShiroIsMyName

    Жыл бұрын

    Hackers don't guess, they use a dictionary attack where a program tries hundreds of words and characters per minute, the username followed by a character would take milliseconds to crack

  • @Brusehusbh
    @Brusehusbh2 жыл бұрын

    this channel is so underrated and needs more subs

  • @writerinrwanda
    @writerinrwanda2 жыл бұрын

    Please can you cover the issue of the Google log-in loop that locks people out of their Google/KZread channels for *life* if they forget their password and lose their phone. No e-mail reset offered. Quite a few people have mentioned this online already. It's a growing problem and it seems inconceivable that Google can't find any way to solve this and reunite divorced accounts with their owners - or at least let people delete accounts and personal data even if they won't let them continue using the accounts. At this rate, Google is going to become a graveyard of lost accounts.

  • @Wigglythegreat2

    @Wigglythegreat2

    Жыл бұрын

    What about Google backup codes in this situation?

  • @KM-bn7dg
    @KM-bn7dg2 жыл бұрын

    This set is amazing wth

  • @julianatlas5172
    @julianatlas51722 жыл бұрын

    You didn't have enough credit to password managers. That is the best solution I think

  • @Skiltra
    @Skiltra2 жыл бұрын

    I store my master password locally everything else will be cloud but i also have 2FA which i don't overlap with my password manager as if either are found i want the extra security. i have multiple emails over the years for different purposes so simply testing my email and cracking it if successful will only compromise some of my account My 20-30 long passwords still get found out but my threat is features such as links that sign a user in and malware or even password reset links which do not require you to be signed in

  • @myfirstmylast9051
    @myfirstmylast9051 Жыл бұрын

    Can anybody explain to me why you can't use any special characters that you want? When I make a password that I think has all the qualities of a good password, lo and behold, the next site I go to to use that password, it's no good because it won't allow some of the special characters I used originally. OK, I've decided to get a password manager, but still, it's one more thing we low skilled computer users will never, ever understand.

  • @davec817
    @davec8172 жыл бұрын

    i use random characters i use the same one for stuff i dont care about, unique ones for stuff i care about with a hand written copy hidden somewhere, incase i forget, mine are hidden in plain sight, just looks like a pile of mail but in it at certain areas on the page is my password 😂

  • @peterlittlehorse5695
    @peterlittlehorse5695 Жыл бұрын

    Since most websites lock you out after 3 incorrect tries there's no reason for a password to be required. If someone knows your password they'll get in, if they don't they'll have very little chance of guessing it in 3 tries. If the government wants access they'll just order the provider to let them in and they'll ALL comply. The weakness in in your selection of hints in case you forget your password. Its much easier for someone to know your mothers maiden name or the colour of your first car.

  • @kylbau
    @kylbau2 жыл бұрын

    Passwords are a great topic

  • @AsloAso
    @AsloAso2 жыл бұрын

    I use password monster to make my passwords strong a good thousand of years to guess

  • @Appleseven77
    @Appleseven772 жыл бұрын

    ur the only cool british person i love ur content man!!!

  • @ericpham5198
    @ericpham5198 Жыл бұрын

    Can smart ring and smart watch combine to match biometric but could be dangerous for Agent life

  • @iwantedtosavetheworld7358
    @iwantedtosavetheworld73582 жыл бұрын

    any updates to that Zero Knowledge Proof based logins?

  • @reastle1307
    @reastle13072 жыл бұрын

    Nice background

  • @5lanediver
    @5lanediver2 жыл бұрын

    can’t believe this wasn’t sponsored by a password manager lol

  • @qq84

    @qq84

    Жыл бұрын

    That's why he neglected them, even though password managers are the most important mention in this topic.

  • @_GhostMiner
    @_GhostMiner2 жыл бұрын

    Where/How do you make these sets? 🤔

  • @ledgeri

    @ledgeri

    2 жыл бұрын

    This particilarly looked like an extremely good cgi-bluescreen combo, when i know it is not... I would guess it is even "someone has a good contact in a movie studio" kind of thing or "it is a good interior art school/ fil academy" :)

  • @Material_Monkey

    @Material_Monkey

    2 жыл бұрын

    Looks like a green screen

  • @R-ok3cl
    @R-ok3clАй бұрын

    Saving passwords in a text document in the cloud is not unsafe. It is in essence what a (cloud) password manager does. Assuming of course, the cloud service uses encryption, which it absolutely should and in modern times overwhelmingly does. Still, I would prefer a password manager for the convenience and phishing protection.

  • @FishcatGames
    @FishcatGames2 жыл бұрын

    I hate needing a cellphone number for EVERYTHING. I don't have a phone number. I don't need or want one. there's a million ways to contact me online

  • @forbiddenera
    @forbiddenera2 жыл бұрын

    My next app will have multiple 2fa options as well as passwordless and maybe even usernameless with hw keys

  • @raunaquepatra3966
    @raunaquepatra39662 жыл бұрын

    What about public key cryptography? RSA

  • @Cookiekeks
    @Cookiekeks2 жыл бұрын

    5:18 what are you talking about? Foobar is just a placeholder for variable names in programming, not some slang word...

  • @Sumsubcom

    @Sumsubcom

    2 жыл бұрын

    Until it IS

  • @hb3393
    @hb33932 жыл бұрын

    If password managers were free I'd use them, but it's BS expecting people to pay for them. Surprised so many people use them. Bring on password free world

  • @tcbobb1613

    @tcbobb1613

    2 жыл бұрын

    Bitwarden is a free open-source password manager.

  • @Filth_Hub

    @Filth_Hub

    2 жыл бұрын

    @@tcbobb1613 This

  • @qq84

    @qq84

    Жыл бұрын

    Password managers (cloud based) are giving you a service, so they can expect a payment for it. There are even ones that gift you a free account (like Bitwarden). And there are free and open source client based password managers like Keepass. The downside there is that you have to make sync and backups of your database manually.

  • @sbcinema
    @sbcinema2 жыл бұрын

    I hate smartphones far more than passwords... and the solution to the password problem is, we simply have to combine the accounts ( then we only need one Password and the problem is solved ). But the only real solution for people who are annoyed of passwords is to turn off the computer, in the real analog world there are hardly using any passwords...

  • @Hithere.howareyou
    @Hithere.howareyou2 жыл бұрын

    *Hey* 😀👋

  • @nonelost1
    @nonelost1 Жыл бұрын

    18:20… “Why do we still love passwords so much?“… Huh?!… I have nothing but SEETHING HATRED of passwords! Having to use computer passwords today is like being forced to drive a 1963 automobile for the last 60 years and counting.(1963 was the year computer passwords were first invented)

  • @laur-unstagenameactuallyca1587
    @laur-unstagenameactuallyca15872 жыл бұрын

    the friend who only has his email password and just resets passwords all the time is funny af

  • @jacktringoli3299
    @jacktringoli32992 жыл бұрын

    Honestly the best password is a hardware device and nothing less something that's synced to a remote server that changes constantly and can only be unlocked with the device that's synced with that account like an rsa token except it's more like a USB type thing and even you don't know the password BUT it only works of its Able to use your biometrics like fingerprint etc. That way literally no one else will be able to use it even if it's stolen and hacked And I don't wanna hear "what if you lose it" well then that's your own fault you probably lose your car keys and have to order replacements lol Honestly if you need a replacement you have to go through a rigorous process to verify your identity with the whole voice recognition and even facial recognition and it's gotta be done on your phone the original device that was used to set everything up in the first place 🤷‍♂️🤷‍♂️🤷‍♂️🤷‍♂️ Find a flaw in this proposal I literally dare anyone to reasonably prove a way that someone could steal your credentials this way and have access to all your accounts lol I literally fucking dare anyone to find a flaw in this 🤷‍♂️🤷‍♂️

  • @_GhostMiner
    @_GhostMiner2 жыл бұрын

    0 views, likes, dislikes and 3 comments 👌🏻

  • @davidpiper3652
    @davidpiper36522 жыл бұрын

    I tried password managers and I found them difficult to use, they made the situation worse not better.

  • @qq84

    @qq84

    Жыл бұрын

    What's so hard in using a cloud based password manager like Bitwarden?

  • @aaron6841
    @aaron6841 Жыл бұрын

    This guy absolutely loves himself and is using his poor knowledge of something he read on Forbes to make a video lol 🤣

  • @venustheplanet8208
    @venustheplanet82082 жыл бұрын

    Why are you wearing a suit? It diminishes the weight of your words. Technicians should avoid suits and everything of that sort. Suits are the tools of people with fake personalities, and Technicians are not fake. Maybe you're fake. I don't know 😕

  • @dannymac6368

    @dannymac6368

    2 жыл бұрын

    He is a science communicator, and a damn good one at that. He is not a technician. What an incredible, eclectic bunch of generalizations. I need to know more…How are suits tools of those with fake personalities? What is a fake personality? How can you be, even a little bit sure, that all technicians are authentic in personality? Maybe he likes wearing a suit. I don’t care. 🤷🏻‍♂️

  • @jeffbrownstain

    @jeffbrownstain

    2 жыл бұрын

    Personally I've seen enough sweaty looking pc dwellers that it's quite refreshing seeing a well-spoken and well-dressed presenter give talks like this. You ever watched a defcon talk? You can smell some of those people through the screen. Bradley smells like he's been to a nice-smelling place.

  • @SgtStarSlayer
    @SgtStarSlayer11 ай бұрын

    Using picture as passwords

Келесі