Yeah, so before we start, my name is Rolf, I'm from Yubico. Did we arrive in the post-password area? I would say, kind of. I think the possibilities are definitely there. We have the authenticators that support passwordless. We have the authenticators that support also phishing-resistant, because when we speak about passwordless, we should always speak about phishing-resistant solutions as well. And of course, it is important to have a central approach using identity access management systems. I think there are a lot of good identity access management systems that we have here.
You can start with Intra, everybody knows Intra, Okta, Airlock, and many, many others. I think they more or less do all the same, a little bit different flavors maybe.
So, if you combine the authenticators using federated authentication protocols like XAML and OpenID Connect, I think we can achieve a passwordless environment. So, we have a lot of customers having a passwordless environment already that don't use any passwords, typically more modern setup organizations, but I think the options are definitely there to do that.
Right, right. Yes, Malte, you want to add something?
Yeah, hi, hello. My name is Malte, Malte Kars from Emtrix. Just as an addition, Fido Alliance just tried to describe where we are in this passwordless journey, and I have some data which I picked up at the RSA security show last week.
So, Fido describes it as we are in the early majority adopters phase, so to say. So, I think currently we look at 44 billion accounts which are Fido-enabled or passwordless-enabled, so they would, in theory, have the possibility to do it. And I think one very important way to distinguish or to… I think you need to distinguish between two different types of scenarios in terms of where we are. I think for the consumer, this is kind of a done deal.
So, everything B to C, there is a massive adaptation of passwordless right now going on currently, but that's the B to C use case, that's not the B to B use case. And I think this is… the majority of this audience might have both of these in their head, but for an enterprise to adopt Fido, we are not there yet. I think we have capabilities and forms, you know, we could use today. Speaking of Entra, speaking of, you know, different piece of technology, but it's not something we are yet able to broadly adopt.
Some are, but not the majority. Is that fair, guys?
Yeah, I totally agree. I would say we're not there yet, not even close.
I mean, do you remember… I'm sorry, I'm Daniel Esterman, head of product management at Airlock. Thank you for introducing Airlock. Swiss company, as you can hear from my accent. Do you remember how you registered for the app for this conference?
I mean, this is an identity expert conference. It still uses passwords. I would say, until Coping & Code, this is not an offense, has passwordless login, we're not even close, in my opinion.
Okay, so James Norton, used to be DB Schenker, now been just acquired by DSV, a logistics company in Denmark. I'm responsible for the identity access management, which is not Microsoft, from DB Schenker. We needed to find what password is first. Is it a static password, you know, 12 characters long, rotated every 12, 20, 30 days, 90 days? Does it have uppercase, lowercase? Is it a one-time token that is six digits and rotated every 30 seconds? They are all passwords.
For me, the bigger problem is the step zero. Once we get into the real authentication, we can use FIDO, but how do we identify the natural person to try and figure out who they are to say, you can use passwordless technologies? And until we get there, we can never achieve real passwordless, in my opinion.
Okay, okay, yeah. Well, we heard a lot passwordless, but what does passwordless actually mean, and is it about the login itself?
Malte, maybe you? I think there are tons of definitions of what passwordless is. Let me say, well, there's a difference between truly passwordless, where there is no password in the entire authentication stream. I think this is the ultimate goal, but that's not the reality for most of the systems out there right now. I think most of the systems right now just take out the password out of the equation when the user performs the authentication, and that is reducing the phishing vector dramatically.
I think this is the primary focus of what we mean when we speak about passwordless authentication at this point, but you need to distinguish between there is no password at all anymore in any of the authentication stream, or there is still a password, but it's not exposed by the user or known by the user. More importantly, exposed by the user in the logon process itself, and that thereby phishable or to be taken. And maybe to add to that is also when we talk about, is it only about the login? I would say definitely not. It's a little bit what you said already. It's a user lifecycle.
Of course, we focus on the login, because the login is like, I would say, 95, 99 percent of the time, but still we have the onboarding process, and it's going in a little bit in the direction that you mentioned earlier, but also the recovery process.
So here we have to make sure that we have a more secure authentication process, because nowadays we see hackers also actually adopt to that and see, okay, a lot of customers are starting to use phishing-resistant solutions, and they're looking for other weak points now, and they're looking at the onboarding process, and they're looking at the recovery process, and so we actually came on with a centralized approach that we can actually pre-register keys now. Of course, we still need to identify the person that is getting the keys.
That is another challenge we have, but still these options are there nowadays that are trying to look on the complete lifecycle of the user. Of course, yeah. I would say it's about establishing trust, verifying, not authenticating. So we have to verify who's coming along to authenticate them, so at least in an enterprise context, this is really difficult.
I see there's potential in the idea of decentralized identity, being able to use trusted sources from governments and so on, but right now, from our experience, unless you get someone to manually do this with a driver's license, and they can't verify if that driver's license is actually real, if it's not faked, then we don't have any way to truly replace the password. But I agree with what Malte said completely.
In the day-to-day business, if we can get rid of the fishable context, we can focus where the attackers are going to focus on the recovery process and the pairing process, I call it step zero, and we can then monitor, we can then enhance our processes to reduce risk. And to me, it's just about finding the best way to find risk and value. And I guess aiming on 100% is always good, but right now, we are not able to get to 100%. So identity verification has been one of the core issues of our entire, let's say, business area, despite being passwordless or not passwordless.
Identity verification becomes one of the critical questions here. We could ask, like, why now, right? Why do we all want to go passwordless right now? And I think fundamentally, all the tools and building blocks are there. If you look at the success FIDO Alliance has had, the passwordless options are now technically available in all of the browsers and all of the operation systems. All of the tools are there. You have the manufacturers out there which are supporting these methods. So that's one big thing.
But the other reason why everybody wants to rush passwordless is sophisticated AI phishing. It's just, it's not quadrupling, it's skyrocketing, right? So we are facing super sophisticated personalized attack on a mass scale on companies where even I have a big problem identifying this as being legit or not legit and trying to prompt my login credentials. And this is so successful. This is such a tremendous risk that everybody wants to go passwordless wherever they can at this current point.
With me, for my opinion, so I'm kind of tired of passwords, to be honest. You have 50 different services where you have to choose a unique password to each of them and then you need to help manage them.
So yeah, this is exhausting. I would just, sorry, just extend. The only thing that we've got now is that the usability and the security come together. Seldom do we find a point in a market where security is increased and the usability is increased. So we have a win-win. We can increase security, we're AI phishing resistant, we become more secure. The problem is we have maybe a little bit more management overhead now, we have different risks that we need to start to consider, but I think we have that blend of people now understand that.
And to maybe just explain it maybe in very simple words, what Malte just said is hackers actually don't hack into systems anymore, they simply log in. And they do it because they have the credentials. And where do they get the credentials? They phish them. And there are a lot of phishing as a service type of things that you can get. You don't need to be a hacker nowadays to really get to set up a phishing attack. So I think this is some of the key notes that is still a topic of awareness, that a lot of people are not aware of these threats out there.
They underestimate it and think that typically like legacy MFA is still sufficient for that, and it is not. And it's a simple answer. Right.
Yeah, we also have a lot of customers who are suffering from these phishing attacks, and there's a lot of fraud there that costs millions. But the interesting thing is, everybody knows the building blocks are there, but still, even in the B2C space where we are, and in the Scion space, there's some reluctance, some people are hesitating. And we think there's a lot of misinformation also, there's a lot of myths, especially about passkeys. And for example, some people just say, yeah, sync passkeys are not secure, something like that.
And this afternoon, my colleague Mark will have a separate speech about the passkey myth. So if you're interested to hear some answers, that's a good idea to go to that speech at three o'clock. At the end, passkeys are all, I would say, highly secure.
Of course, there are different levels of security. The passkey is itself.
Yeah, the passkey itself is secure. And depending a little bit on the use case regarding the passkeys. So for the typical syncable passkeys, I would say it's from a convenient point of view, and for the typical user, private user, ideal. We get rid of the password, and it's much more