Skip to main content

Passwordless Authentication


Passwordless authentication is a verification process where a user confirms his or her identity without the requirement of manually entering a string of characters. Authentication methods include biometrics, security tokens and piggybacking off of another application, service or device which has already authenticated the user.

Passwordless authentication is commonly used on mobile devices such as smartphones, tablets or laptops and applications such as Slack or WhatsApp. The benefits of using passwordless authentication include:
  • Improved user experience (UX).
  • Faster login times into applications or devices.
  • Less maintenance of passwords required for IT staff.
  • Reduced chance of phishing attacks, password re-use or password leaks.

Types of passwordless authentication

With passwordless authentication, users are presented with one or multiple methods of signing into an application or device without the need to enter a password. Common types of passwordless authentication include email-based, SMS-based, multi-factor, biometrics or passwordless authentication for logged-in users.

Authentication through email includes verifying a user with a magic link or one-time code. With a magic link, the user first enters their email and a unique token is created for the user and sent to them by email. The user clicks the link and the service being used will identify the token and exchange it for a live token, logging the user in. With a one-time code, a user will enter their email address and an email will then be sent to them with a unique one-time code. The user then enters the code into the service, which will verify the user and log them in.

Authentication through SMS will begin with the user entering their phone number, prompting a one-time code to be sent to their phone. The user will input the code into the service, where the service will verify the code and phone number, and log in the user. However, SMS passwordless authentication may be less secure than other methods of passwordless authentication as SMS authentications have recorded multiple attacks in the past. SMS and email-based passwordless authentication can also log into a service through a second device through push confirmations, using the first connected device as a communication channel.

Multi-factor authentication uses any (typically) three authentication factors to log in a user such as security questions, PIN codes and contact information. What these factors are depends on the device/service.

Biometrics is another common form of passwordless authentication. Biometrics focuses on technology such as fingerprint scanners or face scans. This form of authentication is commonly found on mobile devices such as smartphones. Android devices will commonly use fingerprint scanners (normally located on the power button, back of the device or even under the front display), while Apple devices (which used to use this authentication format) now use face authentication.


Comments

Popular posts from this blog

A Graphics Processing Unit (GPU)

A graphics processing unit (GPU) is a computer chip that performs rapid mathematical calculations, primarily for the purpose of rendering images. A GPU may be found integrated with a central processing unit (CPU) on the same circuit, on a graphics card or in the motherboard of a personal computer or server. In the early days of computing, the CPU performed these calculations. As more graphics-intensive applications such as AutoCAD were developed; however, their demands put strain on the CPU and degraded performance. GPUs came about as a way to offload those tasks from CPUs, freeing up their processing power. NVIDIA, AMD, Intel and ARM are some of the major players in the GPU market. GPU vs. CPU A graphics processing unit is able to render images more quickly than a central processing unit because of its parallel processing architecture, which allows it to perform multiple calculations at the same time. A single CPU does not have this capability, although multi...

What's the difference between two-step verification and 2FA?

  The two terms, two-step verification, and two-factor authentication are synonymous, though the former is now being used more widely by the likes of Google, Microsoft, and Apple as it better conveys how the actual authentication process works. In the past, two-step verification was used to describe processes that used the same authentication factors, while two-factor authentication described processes that involved different factors, such as entering a password on a website and receiving a numerical code on a mobile device. Today, the two terms are both used to describe authentication that involves a secondary factor that is different from the first. Authentication is a vital element of access control and data security because users can be assigned access rights and be authorized to perform certain actions only after successful authentication is performed. The ways in which someone can be authenticated fall into three categories based on what is known ...

Ghosting

Ghosting is to cease communications without notification. The use of the word "ghost" as a verb originated in social media in reference to dating, but the term is now used by employers to describe employees and potential employees who suddenly disappear. Typically, ghosting is used to describe: Job candidates who suddenly stop responding to messages. New hires who fail to show up for their first day of work. Employees who do not show up for a shift. Employees who leave work in the middle of the day and never come back. Some analysts blame ghosting on millennial entitlement. The reasoning is that members of the millennial generation have been brought up to feel they are special -- so special, in fact, that they do not need to follow conventional rules of behavior. Other analysts, however, maintain that ghosting behavior stems from changes in the job market and the phenomenon is simply a reflection of the laws of supply and demand in a healthy jo...