76. Pass Keys are the Future – Tech Field Day Podcast
Passwords create friction and therefore users find ways around them. New technology such as secure enclaves and PKI allow us to create better solutions like passkeys. In this episode of the Tech Field Day Podcast. Alan Shimmel and Kate Scarcella join Tom Hollingsworth to discuss the problems with traditional passwords and how passkeys overcome them. They also talk about why it has taken so long to adopt passkeys and what barriers remain to full implementation. The wrap up with a look at what might lay ahead on the horizon for the future of user security.
Transcript
I'm sure that you have every one of your passwords memorized and you can recite them. Add infinitum whenever people ask. Or is it that you're using a password manager to remember them all for you?
Is there a better way to make sure that we're more secure in incorporating things like public-private keys and multifactor authentication? In this episode of the Tech Field Day podcast, Passkey are the future. Welcome to the Tech Field Day podcast, where we bring together a group of IT technical experts to discuss a single idea about key concepts in the enterprise IT industry.
This podcast features a variety of perspectives from members of the Tech Field Day delegate community, and it's often recorded in association with one of our events. Tech Field Day is a part of the Futureum Group, and this podcast is also published on our sister company site Techstrong tv. In this episode, as we're heading into security field day, we will be discussing pass keys and how they make security much easier.
Before we do that though, let's have our guests introduce themselves. Hey, Tom, thanks. I'm Alan Shimel, the founder and CEO of Techron Group, the people behind DevOps dotcom, security Boulevard, cloud native, now, Techron tv, Techron ai, techron it digital, CXO, I don't know.
And we're part of the Futur group, which makes us a sister company with our forensic tech Field day. Tom. Thanks.
My name is Kate Scar. I've been a part of cybersecurity for a very, very long time. I don't have all those exciting things that Alan does.
I'm actually coming back from a sabbatical that I took off, and, uh, I'm happy to be back. And I am part of, uh, the CD foundation, the chair of, um, cybersecurity Sig, and I'm very much into everything secure. Awesome.
And of course, I'm Tom Hollingsworth, an event lead here at Tech Field Day. Let's jump into the premise for today's episode ahead of Security Field Day. No doubt that when you woke up this morning, you had to type a password into your device somewhere, whether it was a pin code into your phone or something alphanumeric into your device of choice.
And wouldn't it just be better if we could get rid of that? Because I know that I have way too many of those and I'd just like to have less than I need to worry about. That's the promise of something called a passkey, which is a type of security that will allow you to do, use things that you have and authenticate to that device, as opposed to having to remember the various passwords that I have for everything.
I happen to like them, and I know that at least one of our guests does. So the premise for this episode is that passkey are the future. So Alan, you, you were an outspoken proponent for passkey.
I was wondering if you could tell our audience very quickly, what is it about passkey technology that's better than a password in your mind? Well, you know, Tom, I'll tell you, I didn't type in a pin or a, uh, or a password this morning when I got on my phone, my iPad or my iMac, or even looked at my watch because I do use pass keys. And so a quick facial scan, a fingerprint on the keyboard, or I am actually full disclosure a customer of one password.
And I use that for pass keys as well. And, and, uh, I log into, well, I don't wanna give out too much security info because I've been in the security game a long time too, but I do use one password PAs keys to log to various applications that I use. And, um, it makes life easier.
You know, there was a time, there was another password manager I used for a number of years that unfortunately was the victim through perhaps no fault of their own, of several data breaches. And as a result of that, I, it finally the, I said, I have to move through, you know, whether it's their fault or not. My, there's, there's big hash balls of my passwords that are waiting for, uh, quantum computing for someone to crack and take everything I own.
So I, I moved to one password a couple years ago, and, um, the whole, at that time, I remember looking how many passwords I had. And granted, I'm a, I'm a freak. I'm a tech geek, you know, and I get all that.
But if I told you I had over 350 passwords stored in one password, right? 350 passwords, I don't know if people out there, if you have more or less about the same, that's a lot of passwords to remember. And so if you don't have a password manager, you are reusing passwords.
You're not using hard passwords, you're just, uh, uh, you're an accident waiting to happen. You're the zebra waiting saying, I hope the lion doesn't get me today. Yeah.
And, and Alan, I want you to change those passwords every 90 days. Exactly. Every quarter.
Exactly. It's, come on, dad. That's crazy that no one's doing.
We all know no one's doing this. We all know. Yeah.
But, and so pass keys to me are a way around this, right? Whether it's biometrics or, or what have you, that it's using the fact that I don't have to remember 350 passwords that I change every 90 days is a God sent, right? This is, you know, I, I can't see why anybody would say no.
And, and I agree with you that, that the com that what passkey offer is a combination of a bunch of different things that we've been trying to get people to use over the years, right? You know, you, you have a password, but you also have some kind of a physical token, in which case a lot of times it's a, a, you know, maybe it's a, a trusted device like a phone or some other kind of token that you hold onto. And that provides that second factor because we still have a lot of people out there who don't use two-factor authentication, or they use the bare minimum, right?
Like, oh, well, I'll just have it text me whenever I, I need to log in. Or I, which authenticator app am I using again? You know what, I'll just store all of my authentication tokens in the cloud.
'cause those will never get compromised. Right? Right.
Exactly. Yeah. So I, Kate, I was wondering maybe you could kind of tell us, you know, your perspective on pass keys as far as, you know, what is the value to an enterprise that maybe is considering, uh, deploying them at, at scale?
Because I know for personal use, it's great, but personal use past about three or four people kind of starts to be problematic. Yeah. Um, well, from a cybersecurity point of view, you're gonna have stronger security, less phishing risk, right?
Um, no weak and reused, you know, passwords. So that's, you know, number two. Number three, just you want the experience to be seamless, and that's what one password would, you know, a password manager should do.
It should be seamless. And so there's just this better user experience, uh, which is very important. And at the end of the day, there is a cost savings here, you know, and operational improvements.
Um, so cost savings from the, you know, reduction in a support load, you know, oh, I forgot my password. I mean, you know, gosh, we've been dealing with that I think for 25 years, right? Um, so that, so having a, a password manager is, you know, would help in an overall cost saving savings.
And I think we're seeing that with a lot of companies where they're trying to create a frictionless environment. Like how many times have we gone to log into something recently and, you know, we put in a username or an email and it said, Hey, we just mailed you a magic link to verify that you are who you say you are. And, and that way we don't have to deal with this anymore and just click the box that says this is a trusted device unless it's on a public computer.
Uh, is it, what, what's the value that a company gets out of reducing friction with the user base by implementing things like pass keys or magic links? So from, from my point of view, it is just, um, it's not, cybersecurity's always seen, especially with passwords, has always been a security bump, right? We, we are, we are making something difficult that should be easy.
And so what I, what I see is just people adapting more to something that will help in the, in the future that's a, a good for them. Like, like, this is good for you to do. And so the more seamless that we make this, the more frictionless, the more adoption that people will take.
I think there's two things I add to that. Number one, as, as we've highlighted, we're kidding ourselves. If people, if we think people who have lots of passwords are changing them every 90 days, are not reusing passwords are are following good password hygiene.
And so we're creating. And so if they're not, we're creating risks to our organization. Secondly, I will tell you the amount of time that I used to spend, and some days unfortunately I still do hitting the forgot my password, reset my password, use a, a, an auth from Facebook, LinkedIn, or the Facebook, Google or, or Apple.
The amount of time sunk into doing that is, is, is really disgusting to tell you the truth. Another thing though that I like about, you know, using the password manager and pass keys is from an organizational point of view, Tom, let's say I need you to log into an asset, a corporate asset. I'm gonna give you access, right?
But I wanna be able to control that access. Like, you can only come in for today or for the next week. You can't change the password.
Here's, here's the unique token, if you will. Here's the unique username and password I'm giving you to use on this asset for the next week. 'cause you're a contractor maybe.
And then after that, it doesn't work anymore. That is such an inherently more powerful tool at my disposal to help secure my corporate assets, my ip, my, my crown jewels than just saying, oh, let me give you a pass, you know, a password and username or having you go off and create one on your own that I have no control over. And, and again, another reason, that's not a passkey per se, but it, it's another reason why password managers are, are for me, a uh, indispensable, you know, if you're not using them, you're not serious about security.
And I think you're right. And I think while you said that it's not a a passkey necessarily, it's a component of pass keys and, and there's more to the passkey phenomenon that makes it a valuable implementation of modern technology. One of the things that I think that cannot be understated is the fact that most pass keys rely on things like secure enclaves.
Yeah. Which we really haven't had up until just a few years ago. You know, there's a secure enclave on a mobile device or on most, uh, devices now that have a TPM because most devices that we use do have that.
And it's never been an option before because we've never really focused on advanced cryptography and things like that. But like you said, if I create those, those key pairs, and I know that something happens, like let's just say, Alan, that your, your identity gets leaked or someone is able to, to grab that information, I can invalidate that fairly quickly and ensure that nobody's able to use it to log in anywhere else and make you regenerate that and, and kind of start over. Like that is kind of one of the things that security people have been asking about for years is how can in, in the event of a disaster, in the event of a breach, how can I walk things down so that I know that I'm not fighting my attackers while I'm trying to triage the problem?
Yeah. Yep. Or at least limit right in, in, you know, we're gonna freeze it right there.
Here's the funny thing. Everyone I know in security, and I've been in security 30 years, everyone knows the passwords is a failed technology for all of the reasons we stated. And I've met so many entrepreneurs, really bright, smart entrepreneurs who have tackled big problems, who said, I'm tackling this problem, I'm gonna put an end to passwords.
And yet it's still the default. It's still the default. I, I don't know.
I mean, we could talk here about passkey till the, the cows come home. I don't know what it takes to get people off the password. I, I think what it's gonna take is people who are supporting them, just deprecating them.
Like we've seen that with Microsoft, right? Where they're removing support for passwords in their authenticator app, but they're gonna leave passkey support enabled. And, and we've, we've brought people along in degrees because you know, now it's not just password, it's password and two factor.
Like for example, when you join an organization and they want you to log into Slack. Now, it could be that the default is that you have to create a two-factor authentication, you know, the the infamous print this paper out and just in case you ever get something happens because we want to get people thinking in that method. And the more we do that, you know, it, to me it's, it's no different than unsecured wifi or, you know, making your password Cisco 1, 2, 3.
Like, we, we've gotta get people away from that idea that I can just do something quick about this. And I, I know it's gonna be hard for a lot of older folks. I'm not throwing shade on anybody, but my father-in-law has his Windows 10 box set to automatically log itself in every time he starts it, because I don't wanna have to type a password in whenever I get up in the morning.
Whereas me, I get nervous if there's a computer that's just sitting there not at a login prompt when I'm not sitting in front of it. But I, that could also be my IBM training kind of leaking through where it's like, you know, unsecured device is just an opportunity for chaos. Um, do you know, do we think that the, the upcoming generation, gen z gen alpha just kind of assume that pass keys and more advanced multifactor authentication are what is the standard?
And as more people kind of move on with their technology, they just don't think about it because they, this is all they've ever known. So I, I do, you know, so I'm the dad of two boys, 26 and 24. And I will tell you that my, my two sons, and I've raised them, you know, their dad was a cyber dude.
So they've been raised, uh, in this enriched in this culture. They all use multifactor when they can in past keys when they can, they find it much more convenient to just text stuff back and do stuff like that. You know, speaking of my sons, I I will tell you, when he was in eighth grade, we did a science project where we made up a fishing letter, sent it to his classmates and their parents and his teacher, uh, telling them, you know, that the, the, the class roster got, I don't know, something happened, but you had to go in and change your password.
And we sent them to a lookalike page with a closely resembling URLI got 40% of the class parents to give me their passwords. We sent them back and said, Hey, this was a science project, literally. And I was working with a company out of, uh, out of Carnegie Mellon password, uh, class password training program.
And they were nice enough to give me the training program for his class and their parents and their teachers. And I went in and taught them little password haji. But this is, you know, Tom, you know what the most popular password manager in the world is?
Noted. Mm-hmm. Your father-in-law probably keeps all his passwords in his notepad or notes app or, or something like that.
Or on a sticky note underneath his computer. I, I can neither confirm nor deny for, for, Um, no, we, not for the album here or doc some or anything, but yeah. Yeah.
That, that's the most popular password manager in the world. And until we get past that, we got issues. We do.
And, but the the good news is, is that the technology has come a long way. Yes. Even in the past five years to allow that kind of thing.
'cause like you said, most of the time, unless your laptop or your, your tablet's been sitting for more than 24 hours, you can just use your face, use your thumbprint, use some kind of biometrics to, to be able to get into it. I don't, I, I imagine coming soon that a lot of this is just going to be passed. You know, it's gonna be seamless pass through security.
Oh, well, we can identify who you are based on these things and you know, you're good. And, and we've even seen crazy like you future tech stuff. Like if anybody's seen, uh, mission Impossible, uh, was it Rogue Nation where it's like gate analysis.
Like we, we can verify that you're not trying to impersonate somebody that's a little bit further down the road, but I promise you that whatever that gate hash value is is gonna be stored in a secure enclave and the guards are probably gonna have to log into that workstation. No, I, I, I remember a, a company out of MIT biometrically that they would, you know, everyone types uniquely, like you write you type top TOM, you have a, a certain cadence that you use when you type that and, and they were able to, to see if it's really you by just the way you type your name. And, and so, but, but here's the, here's the rub.
We've had technology for this for a long time. It's 2025, we're going to 2026. What percentage of users are using PAs keys or biometrics, right?
So Kate, I think Alan brings up some really good points. We've had all these technologies that exist for a long time. I mean, if you really wanna get down to it, the, the, the heart of a pass key is really just a public private key pair.
You know, Alice is sending Bob more email like we've always done. What is it about passkey that makes it more, I don't know, consumable for people? What, why do you think that now is the time that we've finally gotten momentum to get people off of it?
I think you're seeing the technology as, as Alan spoke about, it's actually, it's easier. We've come a long way. I mean, it wasn't this easy, I don't know, maybe even two years.
It's, it has changed a lot in two years. So that is, I, I think ease of use will always be the key. Um, sort of say this, um, I think that's the, the biggest deal.
I think, um, when, when we don't see cybersecurity as a roadblock, when we see that we're able to do something without it costing us a headache, a time, um, trying to figure things out and, and the old way being more time consuming, more of a, you know, more of this, you know, I have to, I forgot my password to I don't know, Instagram, and you get all the back and forth, that's a headache, you know, that becomes a pain. So I think as, as we see the, this other new technology that is seamless, I, I love that word. Frictionless is another word I love.
Um, I think it will be more adopted by us and, and by companies as well. Kate, I think you're absolutely right. The real value in passwords for the longest time has been the fact that we have spent so much time getting them as frictionless as possible.
Yeah. You know, there's, the eight characters are more special character capital letter that has increased the friction that we've had. But it's just forced people to become more familiar with ways to make themselves more secure without realizing it.
And passkey take it one step further by building in all of the good password hygiene and good security hygiene that we've been trying to teach people for years. You know, un passwords that you don't even know or multifactor authentication. And in doing so, we've moved people to the point where the friction is as reduced as possible for the things that they need to use.
And that means that people are more willing to adopt these new ideas. If, if you remember how hard it is to get people to develop multifactor authentication, if you just tell them, you know, click on your phone and authenticate this. Or if you've ever had them use some kind of a, an online payment system where they can use their, uh, you know, smartwatch or smartphone to authenticate a credit card transaction.
They see the value in what it provides. And that is why passkey have a very bright future. I wanna thank everyone for joining us for this episode of the Tech Field Day podcast.
If you enjoyed this discussion, please make sure that you subscribe on our YouTube channel or in your favorite podcast application so you don't miss any of our episodes. We'd love it if you'd give us a rating and a review because that really does help people find this content and let's them know what we're all about here. This podcast is brought to you by Tech Field Day, which is the home for IT experts from across the enterprise Tech Field Day is a part of the Future Room group.
com/podcast or check us out on Techstrong TV and the Techstrong TV app. Thank you very much for listening in. We'll see you next week.