Sunday, December 15, 2024
HomeCyber Security News"Password Era is Ending," Microsoft to Delete 1 Billion Passwords

“Password Era is Ending,” Microsoft to Delete 1 Billion Passwords

Published on

SIEM as a Service

Microsoft has announced that it is currently blocking an astounding 7,000 password attacks every second, nearly double the rate from just a year ago.

This surge in cyber threats underscores the urgent need for more robust authentication methods, with passkeys emerging as a promising solution.

The tech giant has also reported a 146% year-over-year increase in adversary-in-the-middle phishing attacks, highlighting the evolving sophistication of cybercriminals.

- Advertisement - SIEM as a Service

These alarming statistics come as part of Microsoft’s broader efforts to transition away from traditional passwords towards more secure authentication methods.

Passkeys, a cutting-edge alternative to passwords, are gaining traction as a potential game-changer in the fight against cyber attacks.

2024 MITRE ATT&CK Evaluation Results for SMEs & MSPs -> Download Free Guide

Unlike passwords, passkeys leverage biometric data or PINs to unlock a private key stored on the user’s device, making them significantly more resistant to phishing and other common attack vectors.

Microsoft’s commitment to passkeys is evident in its recent initiatives. In May 2024, the company announced passkey support for popular services like Xbox, Microsoft 365, and Microsoft Copilot.

The results have been encouraging, with passkey sign-ins proving to be three times faster than traditional passwords and eight times faster than passwords combined with multifactor authentication.

User adoption has also been promising. Microsoft reports that users are three times more successful in signing in with passkeys compared to passwords, with a 98% success rate versus 32% for passwords.

Furthermore, 99% of users who begin the passkey registration process complete it, indicating high user acceptance.

To drive adoption, Microsoft has implemented a proactive approach, nudging users to enroll in passkeys at key moments, such as account creation or password resets.

This strategy has yielded impressive results, with a 987% increase in passkey use following the implementation of a new sign-in design.

Looking ahead, Microsoft projects that hundreds of millions of new users will create and use passkeys in the coming months.

The company’s ultimate goal is to completely eliminate passwords, transitioning to accounts that only support phishing-resistant credentials.

As the digital landscape continues to evolve, the shift towards passkeys represents a significant step in enhancing cybersecurity.

With major tech players like Microsoft leading the charge, the era of traditional passwords may indeed be coming to an end, ushering in a new age of more secure and user-friendly authentication methods.

Investigate Real-World Malicious Links, Malware & Phishing Attacks With ANY.RUN – Try for Free

Gurubaran
Gurubaran
Gurubaran is a co-founder of Cyber Security News and GBHackers On Security. He has 10+ years of experience as a Security Consultant, Editor, and Analyst in cybersecurity, technology, and communications.

Latest articles

Over 300,000 Prometheus Servers Vulnerable to DoS Attacks Due to RepoJacking Exploit

The research identified vulnerabilities in Prometheus, including information disclosure from exposed servers, DoS risks...

Reyee OS IoT Devices Compromised: Over-The-Air Attack Bypasses Wi-Fi Logins

Researchers discovered multiple vulnerabilities in Ruijie Networks' cloud-connected devices. By exploiting these vulnerabilities, attackers...

New Android Banking Malware Attacking Indian Banks To Steal Login Credentials

Researchers have discovered a new Android banking trojan targeting Indian users, and this malware...

New Research Uncovered Dark Internet Service Providers Used For Hacking

Bulletproof hosting services, a type of dark internet service provider, offer infrastructure to cybercriminals,...

API Security Webinar

72 Hours to Audit-Ready API Security

APIs present a unique challenge in this landscape, as risk assessment and mitigation are often hindered by incomplete API inventories and insufficient documentation.

Join Vivek Gopalan, VP of Products at Indusface, in this insightful webinar as he unveils a practical framework for discovering, assessing, and addressing open API vulnerabilities within just 72 hours.

Discussion points

API Discovery: Techniques to identify and map your public APIs comprehensively.
Vulnerability Scanning: Best practices for API vulnerability analysis and penetration testing.
Clean Reporting: Steps to generate a clean, audit-ready vulnerability report within 72 hours.

More like this

Over 300,000 Prometheus Servers Vulnerable to DoS Attacks Due to RepoJacking Exploit

The research identified vulnerabilities in Prometheus, including information disclosure from exposed servers, DoS risks...

Reyee OS IoT Devices Compromised: Over-The-Air Attack Bypasses Wi-Fi Logins

Researchers discovered multiple vulnerabilities in Ruijie Networks' cloud-connected devices. By exploiting these vulnerabilities, attackers...

New Android Banking Malware Attacking Indian Banks To Steal Login Credentials

Researchers have discovered a new Android banking trojan targeting Indian users, and this malware...