Andre, the CTO of iC Consult, discusses the challenges and advantages of Passkeys in the realm of Identity and Access Management, highlighting the importance of moving away from passwords due to increasing spear phishing threats bolstered by Gen AI. The talk emphasizes the need to balance security and usability when implementing Passkeys, considering both device-bound and synchronized options. Andre contrasts Passkeys with traditional passwords, noting compliance and user understanding as significant hurdles, alongside specific technical challenges like operational deployment and helpdesk support. He stresses the critical need for careful enrollment processes and phased rollouts to ensure smooth transitions, particularly with end-users in mind. The session concludes with audience questions, exploring practical applications like password managers, enterprise management in controlled environments, and the unique constraints faced in manufacturing scenarios where usability and security must be weighed meticulously.
Yeah, thank you very much. Really a crowded room and that directly after the lunch break. That's much appreciated. But I think it's because of that very exciting topic, Passkey, right? And today I don't want to just focus on the very nice sides, but also discussing a little bit about the challenges.
So, my name is Andre, I'm the CTO of iC Consult. We are doing Identity and Access Management and one of the obvious challenges is authentication.
Not new, but not completely solved yet. Here we have a study focusing on a very important topic, it's password security. That study is from November 1979, year of my birth, so it's not a completely new topic, but still very, very relevant. Especially if you have in mind how the attacker landscape towards passwords changed based on the rise of Gen AI, right?
So, when it comes to spear phishing, typically a very expensive approach to attack one single person by providing a lot of context, convincing him to click a mail, providing credentials. Gen AI is tremendously reducing the effort of the attacker.
Therefore, getting rid of the password is more important nowadays than it was ever before. Now, whenever starting a project, one very important thing is managing expectations.
So, last year I was on a conference in Barcelona. I don't want to mention the name of the analysts here, but anyhow, that's not the point.
So, we were hungry, the place of the conference was a little bit outside of the city area, but we were able to identify on Google Maps a tapas bar, not looking too nice. So, we went there, not with the highest expectations, but what should I say? Tapas were good, beer was better, the stuff was nice and we had a lot of fun there.
So, it was a nice evening. But this is not the way how Passkeys is promised to us. Passkeys is a three-Michelin star menu, right?
So, more convenient, more secure, faster, better in every single aspect, right? We will discuss these aspects in a second. First of all, structuring a little bit the Passkey landscape to make sure that we are talking about the things.
So, if you look at Passkeys, you can look into that from two dimensions. The one dimension is, are we talking about something that is device-bound? For instance, a platform authenticator on your Windows notebook, and that is built-in, leveraging the TPM of the hardware.
Or, are we talking about an additional piece of hardware? From a usability point of view, cost point of view, security point of view, this is a difference, right?
So, for instance, the Thales e-token. And then, we have the synchronized Passkeys.
So, the new thing. Again, we have here the first-party thing that comes directly with your smartphone and without any additional installations and additional efforts for the end user. From the usability perspective, absolutely crucial.
Or, are we talking about something in addition to that? So, a password manager that is now also taking over the job of being the Passkey provider. For instance, one password, Dashlane, or all the others.
Now, let's focus on two dimensions. The one dimension is a level of security. The other dimension is a level of usability.
And again, top right corner. That's a promise. For your reference here, smart cards, of course, secure, user-friendly. We can discuss that, but not here, not today.
Now, let's have a look to the first one. This is a security key, so the external device. When it comes to usability and you force your users to carry something additional around, you likely will not do that in a consumer scenario.
So, that's a kind of really significant drawback. Security-wise, it's of course strong, no questions about that. And then we have the topic of the platform authenticator. Is it better from a usability perspective?
Yes, of course. As long as you don't have to migrate to a new device. If you have one Passkey enrolled, okay, not an issue, but we want to replace passwords with it. Remember that. And how many passwords do we have? 100? 200? 300? Maybe even more. And going through re-enrollment, that will never scale. That's for sure.
And then, the third-party Passkeys. Usability-wise, okay, it's better because I have it on all my devices and it doesn't matter if my devices are spread over the different ecosystems of Google, of Microsoft, of Apple. That doesn't matter because I selected one password, for instance. Security-wise, well, we don't have any hardware binding here, right?
So, at the end of the day, if I'm able to take over the Dashlane account or whatever, then I have the credential. And then we have the first-party Passkeys here, synchronized.
Also, of course, better usability. Security-wise, okay. But there's one aspect.
So, if I look and compare using a password and a Passkey, there are a lot of benefits for the Passkey. But, for instance, when it comes to speed, is a Passkey faster than a password? If you're a password manager on your device, and if you're forced to do the cross-device flow because you're an Apple user working on a Windows notebook, likely not.
So, it's not exactly on that level of usability. And the reason for that is obvious. We are all trained and all our users are trained to work with passwords from the very first steps into the IT world. And that's an aspect we must not underestimate because it's really about changing a behavior that has been trained over decades.
And, therefore, it's focusing now on some of these concrete challenges. So, one thing is when it comes to the compliance. I think we all agree that Passkeys are, of course, more secure. But then passwords, also then one-time passwords generated in an app without any binding to a transaction, with symmetric typography. There are a lot of points that make Passkeys superior, especially the resistance against phishing attacks.
But, anyhow, when it comes to regulatory points, then very often this is still an open question. Is it really kind of strong authentication? Or is it just a replacement of the password? And then I have to less secure one-time password after that.
Of course, I think one huge step forward was the possibility provided by NIST to give Passkeys authentication assurance level 2, an update mid of last year. But other regulations still have a, let's say, a kind of outdated view on that perspective based on the fact that synchronized Passkeys are clonable by nature. When it comes to usability, there's one very important point. And that is this concept is very well known to us security professionals. To all other users, they don't have any clue what is happening there.
And that's something what we have to take into consideration for the enrollment so they don't understand it. Therefore, they will likely not use it proactively. So we have to steer that process and provide communications around that.
Also, users with different authenticators on the device might end up in a situation in which they're not having a good understanding which one has been used. The Microsoft authenticator for my Xbox account or one password or the built-in one, right? Three choices. That's making the things more complicated if you're not aware of that or steering that a little bit. And then from operational point of view, it might happen during rollout that you understand that there are touch points out there that are not playing well in the Passkey world. For instance, embedded browser components.
Oh no, we don't have that. Sometimes the kind of customer identity access management systems are somehow complicated. You might provide digital services, APIs that are called by apps developed from third parties bringing together different kinds of services. And do they play well as soon as the user has to authenticate and give consent inside the app with your Passkey deployment?
Might be, might be not. So that's an area that you have to be aware of. And then the helpdesk. If you don't provide any information to your helpdesk how that particular user has been enrolled in Passkey, what should they do? Should they guess it? The good thing is based on the authenticator attestation and metadata provided by FIDO Alliance you, of course, can provide that information. You can tell your user, hey, but you used one password to enroll it.
Oh, I deinstalled it. I forgot about that. But if you're not providing that kind of information to your helpdesk then they will try to bring the user into a process to enroll it again. And you have no possibility to really improve that quality over time. So that kind of analytics information is a very, very important point you should have in mind in order to move forward with your Passkey deployments.
And then let's talk a little bit about concrete recommendations because what we must do, and it's mandatory, we have to take care of that security gap we have between the Passkey and staying on the old approach. There's no discussion about that. The only thing is we should not underestimate the challenge of enrolling it. We should not just say, oh, it's all superior.
Therefore, let's move forward without thinking about it. No, we have to take it seriously. It's a project where we should apply things we also do for other larger changes and implementations. For instance, a huge priority on the user experience testing. You don't have to have a dedicated team for that.
Typically, it's easy to find a couple of friendly users from different territories, different demographics that can help you to get a good feedback if your processes are working as expected. And then, of course, also if you have the possibility working with this kind of A-B test to figure out that you really start with a perfectly shaped user experience here.
Last point to mention here, whenever you enroll something, if you can prevent doing it in a big bang but having a phased rollout, you should really do that because you don't want to end up in a situation in which your helpdesk and processes can't scale because all users are somehow struggling with that. These are, I think, very generic recommendations, but they apply especially when it comes to the enrollment of past keys.
With that, I say thank you for paying attention and happy to take questions. Thank you so much. Do we have any questions in the audience?
Okay, there's one. Let me grab the microphone. There you go. Can you just describe how the password manager passkey works?
Yeah, so the password manager, in that case, we are talking about that kind of third-party passkey provider scenario. Well, I have a password manager on my smartphone. Maybe it's a bit worn, and I have it also installed on my Windows notebook and on my Linux whatever system.
Typically, their mission is to share passwords over all my devices stored in the cloud, encrypted somehow, but at the end of the day, no hardware binding. With passkeys, that business of password manager goes away. So I would say all password managers nowadays are therefore also supporting passkeys. What they are doing is that they are going to store the key pair, including the private key in your vault in the cloud, at the same time also in your local device.
And whenever you are going to log into your 1Password Bitwarden account on a new device, you get your credentials installed there as well. So therefore, it's convenient. But then the question comes up, which of my passkey providers did I really use? Because there are more than just one. Whenever we give a choice to an end user that is not an IT security professional, guess what is happening? They are making the wrong choice.
All right, thank you. Any other questions in the room?
Okay, there's one more. There you go. So Google does a good job of presenting all the passkeys that I have registered and allowing me to manage them. Do you see any new enterprise requirements for making it easier for enterprises to manage, to let end users self-service manage the passkeys that they have?
Well, I think there are different perspectives on that. So one thing is the complete opposite thing. And that's not the thing letting users manage it by itself, but capabilities to provide a token with a passkey to the end user the same way we were doing it with smart cards. That's one perspective. But to your point, when it comes to how can enterprises support that kind of process to the end users, if I'm going for a kind of third party passkey provider, then I have a different level of control when it really comes to what we allow, when it comes to synchronization and what not.
Because what I don't want to end up is in a situation in which my employees are synchronizing their passkeys to devices that are not under my control, if I'm otherwise forcing to work with managed devices. So that kind of scenario is something what we see.
Great, thank you. I would have one more question. This is more of a real-life question and a problem that many organizations in the manufacturing space may face. The use case is being able to enable seamless access to your front line workers or blue collars working in a very noisy or perhaps different environment from your white collars. And often case you want to use passkeys or passwordless or FIDO2 type of authentication methods to facilitate that. So what's your experience on that? And have you seen that solution actually work in such environments?
To your point where you don't necessarily control the device they may use, i.e. BYOD kind of situation. Do we have time to answer that question? Ask Sebastian. So we have one OT scenario in a manufacturing area and they are moving on with passkeys. But honestly there's one drawback. Passkeys are always two factors. Something what you have combined with a pin or with biometrics, right? Having a helmet on, gloves on your hands, that's not working very well. So there's always a kind of discussion. Are we going with passkeys into these kind of scenarios?
Paying the price of inconvenience but at the same time getting a very high level of security or are we going for some more convenient, much less secure RFID-based contactless authentication stuff? So unfortunately that's often the way from our experience. Enterprises moving forward to really have that kind of very, very good user experience even if they pay a high price on the security for these kind of scenarios as they are partially air-gapped that might be an acceptable risk for some organizations. Great. Thank you so much.
We are running out of time but if there are any other questions feel free to link up with André. Thank you so much. Thank you.
See All Locations
See All Locations