LOGO

Duo Passwordless Authentication

March 30, 2021
Duo Passwordless Authentication

Cisco Duo Announces New Passwordless Authentication Service

Duo, the authentication provider acquired by Cisco for $2.35 billion in 2018, has revealed its upcoming launch of a passwordless authentication solution. This new service will enable users to access their Duo-protected applications utilizing security keys or biometric verification methods.

Public Preview and Key Features

The service, designed to be compatible with various infrastructures, is scheduled to enter public preview during the summer months. It aims to provide a more secure and streamlined login experience for users.

Gee Rittenhouse, SVP and GM of Cisco’s Security Business Group, stated that Cisco’s goal is to deliver passwordless authentication that caters to the needs of a modern, diverse workforce. This allows a wide range of organizations to move towards a passwordless future, irrespective of their existing IT infrastructure.

The Problem with Passwords

Currently, many users of Duo and similar authentication products employ both passwords and a secondary authentication factor. However, user password practices are often weak, and password forgetfulness remains a persistent challenge for IT departments.

How Passwordless Authentication Works

Traditional two-factor authentication adds an extra layer of security to passwords. Passwordless authentication represents an evolution of this concept. Instead of passwords, it leverages cryptographic key pairs, utilizing either hardware security keys or biometric authentication methods.

Security and Standards

Duo’s passwordless service is built upon the Web Authentication standard. This ensures that user data is stored locally, rather than on a centralized server, enhancing data privacy and security.

Readiness for Passwordless Adoption

Data from Duo indicates that the necessary hardware infrastructure is now sufficiently mature for widespread passwordless adoption. Currently, 80% of mobile devices support biometric authentication capabilities.

A Gradual Transition

“Passwordless implementation is a process that requires phased changes within both user habits and IT environments,” explained Wolfgang Goerlich, advisory chief information security officer at Duo Security at Cisco. “Duo is positioned to assist organizations in securely transitioning their systems and workforce, minimizing disruption for users while simultaneously bolstering confidence in every authentication attempt.”

The service aims to make the most secure access path also the easiest for users.

#duo#passwordless#authentication#security#multi-factor authentication