enterprisesecuritymag

| | MARCH - 2019ENTERPRISE SECURITY8Eliminating Passwords: The Journey By Bret Arsenault, CVP & CISO, Microsoftccording to one estimate, the average person has 27 online accounts with user names and passwords. Choosing the right password is as confusing as trying to remember dozens of passwords--it should be complex, more than 8 characters long, it should use letters, numbers and symbols, it shouldn't be a dictionary word, it shouldn't be something that anyone else can guess, you should change your passwords frequently, you shouldn't use the same password for multiple accounts. The list goes on.All of these complicated rules lead users to try and create passwords that are easier to remember, but frequently that makes them easy for attackers to guess. And, hackers are taking every advantage of this weakness. One security industry report notes that 81 percent of hacking-related breaches leveraged either stolen and/or weak passwords. As the Chief Information Security Officer of Microsoft, this represents a huge problem for me. The good news is, I love challenging problems. And, I'm on a mission to end the use of passwords at Microsoft.Many years ago, when we started seeing the growing sophistication of hackers and their unfortunate success in breaking into the networks of big, consumer-name companies, we started a journey to find a better way to secure our employees. We knew that multi-factor authentication was a smart approach. Initially, we used physical smart-cards. This kind of authentication is much more secure, but it still didn't give people a smooth user experience. Additionally, the smart-cards require infrastructure (a card reader in each hardware device) which can be challenging to AIn My Opinion
< Page 7 | Page 9 >