64. We Are Long Past Passwords – Tech Field Day Podcast
Passwords have served their use in the enterprise. We need to start moving away from simple passwords as an authentication mechanism. In this episode of the Tech Field Day podcast, Tom Hollingsworth is joined by Tony Efantis, Karen Lopez, and Fernando Montenegro as they discuss the premise that we are long past passwords, exploring the complexities and frustrations of relying on them for myriad online accounts. The conversation highlights the concept of economic externalities, where developers easily implement simple passwords, but the burden of managing hundreds of unique credentials falls on the individual user. While passwords were initially designed for basic authentication, there has been a shift towards alternative mechanisms like one-time codes sent to email or passkeys because of user laziness and the security risks associated with password reuse and compromised credentials. Ultimately, what is needed a balanced, risk-based authentication approach is necessary, tailoring security levels to the sensitivity of the data being protected, and leveraging technologies like biometrics and background risk assessments to create a more convenient and secure user experience, even as attackers continue to evolve their methods.
Transcript
Welcome to the Tech Field Day podcast, where each episode we bring together a group of IT experts from across the enterprise IT landscape to discuss a topic, a premise, if you will, related to any one of a number of IT disciplines. Tech Field Day is a part of the Futurum Group, and this podcast is often recorded in association with one of our tech Field day events. We're here today at Security Field Day, but before we jump into the premise for today's episode, I'd like to take a moment for our guests to introduce themselves, starting with Fernando.
Um, I am Fernando Montenegro. I lead, uh, Futurum, uh, uh, research practice as part of, uh, futu research. And, uh, I am still in the clouds here about what a joy it is.
It was to be here at Security Field Day, Tony. Very good. I'm Tony ais, uh, networking.
Networking Security is my focus. And Karen, I'm Karen Lopez. I'm data check everywhere.
And, um, I'm a data security person, but I'm more of a data person. And my name is Tom Hollingsworth. I'm the event lead for security events here at Tech Field Day.
Let's jump into the premise for this episode of the Tech Field Day podcast. No doubt, when you got up this morning, you had to log onto a website in order to access your favorite news feed, or perhaps, uh, buy a ticket to take a vacation. But did you think about your password before you typed it in?
Is it saved on your laptop somewhere? Or maybe you're one of those people that has one of those fancy pass keys. Do you have two-factor authentication enabled everywhere?
How do you know that people aren't stealing your information when they log into your account? The world of passwords has become a lot more complicated in the last few years, but the premise for this episode is that we are long past passwords. So let's kind of introduce this because yes, one of the things that we've kind of just accepted in our lifetime is that we are going to have to remember tons and tons of passwords.
It used to be a time where we didn't even have to worry about that. The idea of typing something on a keyboard to be able to do anything was kind of weird. And now, you know, my Netflix account has a password.
My email account has a password. Uh, no matter what I do, I like, I have a pen code on my coffee maker. So why do we have to protect everything?
Why, why do we need so many passwords, folks? Those, the, there's a concept in economics called an externality, right? Which is that the, you somebody doesn't pay the full cost of a transaction.
What I mean by this is that it, uh, you don't bear the cost of something, right? That's, that, that's the, the, the, the way to think about this in the context of passwords is that, uh, individually it's easier for a developer to say, you know what? I'll just throw a password here for this little application.
It's just a simple password, right? They are not for them, it's just, we'll just implement this password. But as you very well said, we now live in a world where we have 853, uh, different systems that we access at different times.
So that's 850 passwords, right? The burden of managing all that falls on us. It doesn't fall on that, on that individual developer.
So the reason we have this is because it's easier for, it's very easy to implement, but it's, it's kind like the, the we, we, we chatted about some other time, like free as in a puppy, right? It's a, it's, it's something that just grows on you. What, what I think passwords, right?
That fundamentally, in my opinion, passwords are used for authentication, at least initially. That was the design. Um, we need to give multiple users access to a single computer system.
How do we make sure someone can't just walk up and access it? We need them to type in a password. Mm-hmm.
Simplistically, it was for authentication purposes. I tell you what, I, I love password managers, but I, I don't like the concept of having passwords for everything. I like a, a lot of the alternative authentication mechanisms, such as like someone, I think you said when you logged into Netflix or when you logged into Netflix, I just type in my email address and then it emails me a code and it assumes that I have access to that email.
I, I find that much easier, you know, than having to manage unique passwords, unique accounts in a password manager and everything else. I like the alternatives to Passwords. Yeah.
I think passwords need to die. Um, because of that, the number of them, like if you have a password manager like I do, you realize how many passwords you have. Um, and that just has gotten, and now I can have, like, I don't know what my passwords are.
Mm-hmm. Yes. I might, if my password manager dies, I might be outta luck and I need some way to recover it, but I'm lazy.
I hate typing long, complex passwords. I always get it wrong. So I think these pass, whether it's pass keys or the emailing, the only thing I have the issue, the fear I have with the it, you email me something, of course your email probably relies on a password.
Mm-hmm. And now everything is available because someone, because you've given your password to someone. 'cause that's what happens to people or people do to themselves.
But, but in, in, in defense of the AU authentication mechanism Yep. That I spoke of. Yep.
Normally when it's a, a, not a password transaction, I put in my email address on a website, they email me. Yep. A onetime code.
Exactly. So even if someone gets access to my email mm-hmm. In your example mm-hmm.
Doesn't mean they get access to all my other accounts. 'cause that onetime code can be used only once and for a, a very short window. Yeah.
It's just like, keep control. So I'm favor of it. I want what you said more than password.
It's, it's, It's better. It's, it's just an alternative. But fundamentally, when I think about what passwords are for, it's for authentication.
Yep. And I think it was a great first step, but here we are in 2025, you know, authentication Has been around for 45 years. Mm-hmm.
Uh, let, let's move beyond passwords. Yeah. I, I think that there is a, that every mechanism there is a, there's a gradient of options.
We have options for things. Right? I think that passwords have their uses as a, as a, there's some characteristics to them that I think they're helpful for resiliency.
Right. You know, it's easier to remember a password, a single or mm-hmm. Password.
Right. A break glass scenario that people talk about. Yeah.
Fine. I, I, I get that. I think that's where, where things blew up is what, what I mentioned that, hey, I want the pass.
So one side gives me a password, another side gives me another password, and pretty soon I have 853, and they don't say it 8 53 by number. I, I had to port my passwords from password management. Another, it wasn't the 800 range, But, but were there really 850 passwords or were there 10?
No, no, there were, okay. There were not 850, but there may have well been 600 and something. But this is one of the problems that we've run into.
And part of the reason why we've started looking beyond using just simple pass codes for system access. And I will, I will tell on my good old coworker, pat from IBM 25 years ago, um, one of the things we had a problem with is that we had passwords that were set to expire at certain times. Right.
So we had a password that was gonna last three months, we had a password was gonna last six months. And one of the systems that Pat was logging into had a password that lasted 30 days. So Pat made all of his passwords the same mm-hmm.
So that he only had to remember one password to log into everything. But the problem was is that with the different expiration dates, the only way that he could keep things consistent was whatever the, the youngest password was, the 30 day password every 30 days he had to go change his passwords. Yeah.
So in a way, he had created more security by frequent credential rotation, but in a way that the way he chose to implement it was bad because he used the same password. Yep. And that's what we're seeing now Yep.
Is with things like, have I been pod Yep. We can tell you if your passwords were leaked and if their passwords are consistent tied to those email addresses, we're starting to see people that are using that as a way to, to impact systems. Right?
Yep. And as more and more of our information, whether it be, uh, PII or payment information are stored by these systems, we have problems where now those systems can be, um, hacked or, you know, honestly, you're just logging into a system with the correct username and password, but I can't verify your identity. And that's why we've seen the rise of two factor authentication.
And, and to your point, Tony, getting a onetime use PIN code is a two factor because you have to know the password and email to the system, and you have to have control of the account in order to get that email. So this is creating a barrier to entry and honestly, a compliance and liability boundary for the company. Well, we sent the password to the account that was on file.
If it wasn't you that was in control of it, we have nothing that's to do with that. So is the, is the moving away from passwords something that we're doing to make people's lives easier? Or are we doing it to protect our, our businesses from being sued for exposing things that they shouldn't?
The, the, the moving away from passwords is because people are in the equation, are bad password managers themselves. I Won't deny that, that, That's why is because if you give a person an opportunity to create the same password for every account because it's easy to remember and it's quick to type, then they will, because we're, we're animals and we need to find the, the, the most efficient way to do something. That's what we seek.
That's bad for security. So, so it's, it's, yeah. It's great to be maturing beyond that.
I don't think it's, uh, uh, industry companies or vendors trying to pass the buck of responsibility. I don't think so. I Love your optimism.
I, I, I think it's a, I think it's a, a wonderful step in the maturity. There's a line that I, I'm going to butcher it a little bit, but, um, I think it was Edward Wilson sociologist or biologist. He has the, the problem with mankind is that we have paralytic emotions, medieval institutions, and God-like technology.
That's good. That's fair. Right?
And the, the, the, the exactly I think he nailed it, is that the idea is that we are bad at this. Our brains, were not built for this. Right.
And, and we need to, we need to account for that. Now, that brings into the picture an entire other discipline of do we have the right user experience, uh, uh, tools available to make it easy for people to migrate to password live and, and multifactor authentication and, and all those other things. And I would argue that we as security professionals, uh, and IT professionals, we are actually failing a non-trivial part of this popul of, of our human population when we create these systems that make assumptions about how people are with technology, right.
In the context that Oh yeah. It's just, just use a password manager. Mm-hmm.
Guess what? There is a cost, there is a cognitive cost to that password manager. I, I, I'll, I'll go on record as saying I am a huge fan of those little password books that you see on, on the, the printed ones.
Right. Oops. Disrupted because they account for it.
They are actually excellent for a threat model of password leaks off of, uh, have I been pound or, or something. Anyway, I can, I can go on a rant. I can go on A rant.
It's hard to steal a password out of a, a book that's offline Exactly. Until you leave it on a bus. Is It air gap?
Yeah. Because there's error around, But, and, and that's a good point. We used to decry, you know, the little password books that you could buy at every Walgreens back in the early two thousands.
You know, why are you writing your passwords down? Well, if it's too complex for me to remember and there's different permutations for different systems, I would rather have it put somewhere where I have to go reference it every time. Because kind of to your point, I don't know what the passwords are for some of my sites, and I want it that way because then I have to be forced through a specific authentication mechanisms, you know, how to do that.
And, and a lot of it comes back to, yes, we are investing a lot of faith in the way that people access systems mm-hmm. Because we're also investing a lot of faith in their ability to do their job. Yeah.
This isn't a situation of like, oh, somebody's on my Netflix account and they're watching things without my permission. It's if I get Fernando's password to the exchange server, I can delete everyone's email because he has admin rights. So I wanna restrict that capability to people that I can trust aren't going to abuse it.
But the only way to do that is to ensure that I know who's logging in with which user IDs. Yeah. Funny you should mention just the, the, the, the exchange, uh, example.
Like we just published research, like the, the, um, the decision maker survey we just did. One of the critical use cases for on the identity management side was, uh, that came up on, on, on the survey was exactly how do we control privileged access mm-hmm. Or, or privileged accounts, right?
So it's one of those things to, it's all about balancing the, our exposure. What is it that we are concerned about? Am I concerned about my Netflix account?
Fine. We'll, we'll, we'll use one mechanism. Am I concerned about my exchange server with it?
Okay, then I'll, then I'll do something else. But it's about balancing. Right?
And you've brought up a good point about the human side of it. So we all know that if there weren't humans involved in this, we'd probably be easier to secure things. So like, so a story I have is like, so we started doing multifactor pain in the butt.
Every business user hated it. It was another step. And I'd be on a meeting where we're on like a teams meeting and there's someone showing something, and all of a sudden I'd see this pop up, you know, on their screen to enter an SMS code or something like that.
And the person would be like, hold on. And they're entering in the ss you know, the code and off they go. And I'm like, were you logging into something?
I don't know. I just put the code in there. Well, that multi, that's a multi-factor fail because they don't understand what they just did.
Yeah. And then you go forward. So then they made it easier.
So what I loved about my Apple watch the first time was that with Microsoft Authenticator, it would just pop up. Was that you? And I'd go, yep.
Two seconds. They got rid of that because it was too easy for people to go. Yep.
Now you have to go on your phone and type in these two numbers from your screen. I get that. But I also have these things.
I had a CIO come to me as I was a database administrator, go and set every customer's password to the same password. We're spending too much money resetting passwords. And I said, then we might as well not have passwords.
But to, to this point, and I think this is something that people need to understand, is when you think about the history of multi-factor, multi-user authentication, it didn't come from a world of business, it didn't come from a world of technology, it came from military applications. The original multi-user authentication is nuclear missiles. It's two keys on opposite sides of a room that can only be turned by two different individuals.
And the reason why it exists is concept that I think a lot of people might be familiar with is friction. We want it to be hard to launch a nuclear missile. Mm-hmm.
So that we do not do it on accident. Because if we do Stanislav Petra off, you are my hero. Um, we could literally kill everyone in the world because of an accident.
Mm-hmm. So we have introduced friction, we've introduced, you have to pull out your RSA token and look at the, the key code. We want you to stop and think about it.
But now it's a whole lot easier to do that. And people are counting on it because look at the way that phishing emails are, are formatted now look at, they're, they're counting on you not reading things before you go to click on a box and log in somewhere, not knowing that that is the moment where you have been compromised. I, I, I agree completely.
And this is where I think that the onus is on us as security professionals, as, uh, uh, it admins to design systems and mechanisms that take this human behavior into account, right? Mm-hmm. We are not robots.
That's right. Most of us, most of us are not robots. Right.
So I I I like to say that if your entire company, if you have a massive security breach, that was because a user failed a phishing. Yes. Usually that, that is your, that that is not on the user.
Right. That is on the architecture that led to that problem. Right.
Because you have to account for human failure. Yeah. Or, or, i, I shouldn't say failure.
You have to account for human behavior. Yep. Humans are going to get wrong with the passwords.
They're, I love your example, by the way. The, the, the ai, it just happened. Boom.
Keep going. Yeah. I see it all the time.
All the time. But sometimes we create friction where we don't intend to because we're trying to be too secure. Personal example, when I migrated my iPhone last year, I needed to log into all my new accounts.
So I went through, and of course, you know, some of them automatically logged me in 'cause they had cash credentials and things like that, until I went to log into my Google account and my Google account said, oh, um, you're logging in from a new device. You need to, uh, answer the challenge. And there were options.
It was authenticated on a device or be in, uh, be sent a one time code. Well, the device that I was trying to use, like, I'm like, well, I turned it off, so I don't, I don't want to do that, so I'll just have a one time code. So I hit the button and hit go, and it goes, mm-hmm.
There is a more secure method available. You can't use this. And so I ended up, after 10 minutes, starting my old phone, logging into Google from there, and then shutting it back down so that I could erase it later.
We create these stumbling blocks and then work ourselves into a corner. I mean, I can remember when moving from one phone to another on signal was one of the hardest tech challenges that you could possibly imagine, because signal by its very design is to prevent those things to prevent impersonations. So we think of all these crazy scenarios where things could possibly happen, and we build these protections into them, and then we're left with situations where people are gonna, like Karen said, just do whatever they need to do to circumvent the control.
It's no different than propping open the smoker door at a building and you've circumvented physical security controls. No, no identity cards or, or, um, you know, security guard checks or things like that if someone can slip through right at the back door. So how can we prevent users from circumventing security controls that we put in place?
Because I feel like that, like Tony said, the the, the lizard brain just wants to go, like, it doesn't, it doesn't care. Like they don't think of the, it doesn't say, oh, well yeah, if someone gets a hold of my Apple ID password, they could charge $9,000 worth of in-app purchases in Fortnite. And I'd never know And log Into my bank account as Well.
Well, I, I, I think, um, I think it's important to look at the whole spectrum and, and, uh, the spectrum of, uh, why do we need the authentication? Because we want to protect access to data. Okay.
What is that data? Okay. Like I said, the example I gave of, of logging into a Netflix account and having it just send you an email code and you just type it in.
Okay. That's for access to a streaming platform. I wouldn't recommend that for the admin credentials in my enterprise is active directory.
Right. It's not the same thing. We're protecting access to different kinds of data.
Yeah. And so I don't think there's a silver bullet. We're gonna replace passwords with this thing.
I, I don't think that's ever going to exist. We're an entire population, you know, of however many billions or trillions of people on the earth, forgive me for not knowing. Um, we have 8 billion give or time, and we're not all IT professionals or IT or security professionals.
We don't need, and we're not all protecting nuclear secrets. So we don't need the most secure thing. It should be based on, um, security and convenience.
You know, and what is the data we're trying to protect Access? Well, what is the data you're trying to protect on your Netflix account? Uh, actually nothing.
It's just mandatory. No, No. They can mess with your algorithm.
That would be painful. No, there, there, I Bet you I'm choosing shows for me to watch. Yeah, You're Violating.
There's one reason why you won't tell me your Netflix password right now. Well, I would tell you the reason is because I don't know it. But the reason why is because you pay for Netflix, don't you?
I do. So if I had access to your Netflix account, I could get your credit card info. You can't because they don't store that info available to the user.
But it Doesn't matter. And, and that's a, a thing that we have done because of regulation to say, I will not store this information in the event of a data breach that I, I can't be penalized for it. And that's one of the things that we've started to work around is we know what sensitive data is important.
Let's be fair, if there was, if there's no credit card data stored in Netflix, nobody cares. What they care about is back, oh, you can watch Netflix for free. Going back to, to Fernando's, you know, you are not bearing the full cost of this.
Like my, my kids, I don't mind that they're not bearing the full cost 'cause they don't have jobs. But I don't want anybody else watching my Netflix, because if you have a Netflix account, you can do it. But to your point about, um, we need to create, we can't create one solution that solves everybody's problems because there's different classifications of security we are actually approaching that You haven't noticed there are, uh, multiple popups on websites now to log in using your Google account.
Mm. Um, you can create a passkey in most accounts now, which requires the use of an authenticated device. And when you think about it, for example, my LinkedIn account has a two factor authentication code on it, but I never see it because I only ever logged into LinkedIn on my laptop, which is a trusted device.
And so it creates a pass through of my identity to get in there. So I removed the need for a password through other authentication mechanisms that I didn't have access to 20 years ago. One of the most.
So one of the, my most rewarding professional experiences, whether I worked for a few years in anti-fraud, right. It's a phenomenal space. And amongst the many things, uh, I learned there was, uh, first of all this notion of, of a, a, a better sense of, of the risk management of which solutions gets chosen.
But there is the notion of, uh, above the line fraud controls and below the line fraud controls. Right? The below the line fraud controls is the stuff that is happening, quote unquote in real time.
You just don't see, to your point about LinkedIn, what LinkedIn is actually doing is that, look, we are checking the IP address where, where he's logging from, we're checking the browser fi uh, fingerprint that is logging from, it looks consistent with what he, what he's doing. Let's not ask him to re-authenticate, but I can guarantee you that he open up a new, uh, open up a new session that looks just different enough. Mm-hmm.
And yeah, it'll ask you to do. So designing systems that can do this kind of, of more, uh, aligned, uh, risk-based authentication right. Is useful, But that puts the onus on the companies creating the system when all I have to do is tell you to type in a password and now it's your problem, not mine.
Which Goes back to my very first point about economic externalities. Mm-hmm. So I have a question for you then.
Why, why has credit card fraud gone down in the last two years in the us? Uh, I, I, I have two reasons, but tell us. Well, you, you probably know one of them, we changed the way that we do credit card transactions, chip and pin versus magstripe.
Yeah. Do, do you know why credit card fraud has fallen significantly and it has everything to do with technology, but it's actually a policy, the least secure portion of that transaction chain is the responsible party should fraud or theft occur. Mm-hmm.
And that's one of the reasons why you're seeing that why it seemed to happen overnight was a regulation was passed. That said, if your point of sale terminal doesn't take chips and somebody fraudulently uses a card, you are responsible for paying the merchant, the, the, the transaction fees. Suddenly every terminal within a week was replaced with a chip and pin terminal, and now you're starting to see, oh, and, and they're getting more and more creative.
If you ever used a virtual credit card number like an an Apple wallet, um, that idea is even if my card number is stolen, it can be instantly regenerated. And that that particular piece of PII can be eliminated forever so that I know that if somebody's using it, I, I know where the data breach came from. We are creating more and more things technologically to solve these problems, but we're only doing it because we're shifting the boundaries of where the fraud could happen.
So for example, maybe a corporation says we're totally fine changing everybody's username to be the same. Awesome. If all of the financial information for our customers get deleted, then the CEO gets fired and arrested.
Suddenly the CEO wants to make absolutely certain that everybody has the most secure password possible, that nobody could possibly ever do this. And it seems like a harsh mechanism, but that's sometimes what we have to do. And I quote my good, uh, friend and database professor, Dr.
Tracy cart, if you can't motivate people by greed, you have to do it by fear. And I think that passwords have become a fear institution of, if you forget your password, if you don't use this secure authentication mechanism, it's your fault if something bad happens. So is that why we feel like users are trying to do everything they can to avoid using them, is because they're afraid it's gonna be their fault if they screw up?
You know, I, I don't think they know. I, I forget, I I'm gonna misquote it. I, I wish I, I wish I had my computer to look it up, but I think it was the NIST standard a few years ago.
They redacted. Mm-hmm. It was last year actually, The need of doing a six month password rotation, whatever the, whatever the recommendation was, don't rotate.
Because when you rotate, again, we are humans. We are trying to find the easiest increment number, the increment and number or a season or whatever the month, and they actually found that passwords become simpler Yep. And predictable.
Yep. It, it's better to have and harder, it's better to have a very secure password that lasts a long time than have insecure passwords that change frequently. Yep.
I loved when that happened, by the way. Yeah. Everyone did.
Yeah. I've worked at companies where it was every 14 days, Actually, I think we did a tech field day roundtable about that right after it happened. And all of the security people were like, that was awesome.
Thank you for making that change. I think, I think we've, so there's one other thing when I talk about like, you're basically saying cost benefit and risk of how much, how hard we make passwords or identity happen. The one exception to that is like almost every home user is like, no one's gonna attack my pc.
There's nothing on it except that we know that our smart devices, our PCs are now being hacked not to get to the data, not to get to your bank account, but to turn them into zombie bots Yep. To do criminal things. Very awful criminal things.
And right now, I've never heard of a case where home users whose devices got com or even a company's devices got compromised that way where they ever had to suffer any consequences of it. But, but they, that comes back to we can prove that it wasn't us that did this. Right?
Yet when the webcams got hacked because of a hardcoded backdoor password, you are still responsible for sending that traffic. And I'm pretty sure that your is SP is still gonna want you to pay the traffic bill. So it, it kind of, I'm worried about what's in the traffic that's going.
Right. Right. And, and it, it's a challenge, right?
Mm-hmm. Because we, we know we need to make sure that there are simple controls in place, but we also need to make sure that we've limited our liability as much as possible. That's a good point.
Because at the end of the day, we still have, there has to be, someone has to be responsible for it. Right. And that, that's like the credit card transaction.
It, the least responsible person is responsible for covering the fraud. The fraud still happened. We're, you know, this is not the Star Trek utopia of, you know, we don't need money anymore.
However, I will point out that the enterprise d had two factor authentication for the self-destruct code. You had to have your own personal authentication code, and it was a voice print match, which is why Commander Data had to impersonate Captain Picard in order to lock out the computer. Yep.
Speaking of voice match, let's not ignore biometrics. Yep. But I, I know that probably all of our foot people in here have modern phones with some sort of fingerprint unlocked mechanism or face.
Face we're, uh, that people aren't even using pins anymore. Mm-hmm. You know, for that.
And, uh, I, I guess I'm, I guess a lot of modern computers probably do have a fingerprint sensor, but not all do. Mm-hmm. I would love to see that being more used and it would be okay if it was used in conjunction with something else.
That's okay. Mm-hmm. But, but it's so simple and fast.
Yeah. But Tony, use one finger to log into something. It takes one second than it does to, But Tony, everybody tells me that it's super insecure because I can't change my finger or my face that That's why you need something else.
Yeah. Something else, right? That's why you need something else who, yeah.
It go, it goes back to the multi-factor part of it. Yeah. It's not that who I am is important.
It's that that particular piece of information in conjunction with other things creates a situation where I am safer. Mm-hmm. I think it's one of the things I, I go that, that fraud, uh, so I, I have this, this running, uh, joke, not joke, but I, I have this, this, uh, line that I said that go back to high school calculus, right?
I think that the limit for cybersecurity as time approaches infinity, as time goes to infinity, the limit of cybersecurity isn't Afra. Right. And what in the context that as technology gets abstracted away, we focus more on the business problems.
Right? And one of the beautiful things about one of the things that, that in, in fraud teams understand better than security teams is that we just have to lower the risk enough or the residual risk. Enough balance.
Yeah. It's a balance, right? Sec security teams, we tend to be much more absolutest about this.
And I think that in this conversation, uh, uh, we, we, we've all been touching the, the topic, the idea that it has to be just enough for what we're trying to do. So the, the the fingerprint, the, the, the, the face, is it perfect? No, but you know what?
It reduces enough of the problem. No matter what we do in our modern world, we have information that we want to protect and be, let's be honest, even a simple password is better than not having any passwords at all. However, there are better solutions out there.
There are more secure solutions that create less friction with your users and it works better with what they're doing. And we're never gonna get away from the days of somebody guessing a simple password or having you text them the login code that your phone just got as a way to, uh, backdoor into your account. But we're creating environments where it is less likely for those things to happen, which of course means that the people who are trying to do them are going to have to get better at stealing those things.
Just like every computer now runs a form of antivirus, whether we like it or not, realistically speaking, everything we do is gonna be relying on passwords whether we want to or not. It's just the way that those passwords look to the end user will change in the future. That will just about do it for this episode of the Tech Field Day podcast.
Before we go, I'd like to ask our guests to let you know where they can find more information about anything that they create, Fernando. Uh, so as part of the, the, the Tuum Group, um, some, uh, significant portion of our contents available. com, I'm also relatively active on social media, primarily LinkedIn and Blue Sky.
So Fernando Montenegro, you can find me on any of those. Tony. Yep.
I'm Tony Infantis. Uh, you can find me on my personal blog blog. com.
com. And also as Data Chick most places. And Karen Lopez is all 10,000 of them on LinkedIn.
com/podcast for the latest episode. You can also follow us on social media. We're active on LinkedIn, blue Sky and X.
Just look for Tech Field Day. We'll be back next week with another great episode. com for information about our upcoming, uh, research projects and other great things that we do in conjunction with the RUM group, as well as, uh, Textron tv.
We'll be back with the next week with another great episode. Until then, stay safe and don't forget that password.