
Passwords are Dead: Which Security Method Should You Trust with Adrian Clements
Playback failed. Open the audio file instead.
About this episode
Still relying on passwords to protect your business? In this punchy interview, Haree Patel sits down with Adrian Clements to unpack what’s truly safer for SMEs today, strong passwords with MFA, or going passwordless with biometrics, passkeys and FIDO2. You’ll hear the real-world pitfalls (password reuse, phishing, SIM-swap), why SSO reduces risk, where biometrics shine (and fail), and the practical, layered steps any team can take this week: enable MFA everywhere, ditch shared logins, use a password manager, and start trialling passkeys on Microsoft/Google. If you’re a founder, operations lead or IT manager who wants fewer breaches and simpler logins without adding friction, this episode gives you clear next actions and a balanced take on what to trust now, and what to watch next. Listen now to tighten your access security and cut your attack surface.
Transcript
Read along, or jump to any time
Haree Are you still relying on passwords to protect your business? What if I told you they're putting you at risk? In this episode, we're diving into the real truth about passwords versus biometrics and what it means for your business. Trust me, you won't want to miss this. Hey everyone. Welcome to the cyber CEO. I'm Harry, and today we're diving into a topic that every business owner, entrepreneur, and IT manager should have on their radar passwords versus biometrics for authentication. Which one is more secure and what does the future hold? We're going to break it all down so you know exactly what to focus your efforts on when it comes to protecting your business.
Haree And joining me today is someone who knows a thing or two about this topic. Adrian Clements, regional director here at ICE Connect. So Adrian, Do you think traditional passwords still have a place in business security, or are they being phased out for good?
Adrian Hi Harry. Thanks for inviting me on. yeah, a place in, business security. Definitely for now. I think things are in transition. Things are changing. pre-internet, we had lots of other tools. Everything had its weakness and, and we're going through a phase now of partial internet adoption
Haree Hmm.
Adrian and passwords, then heading onto the full internet, everything in the cloud. What's going to be the way that, where that's gonna end up? It's hard to tell. Biometrics are definitely the next step, and we're gonna talk about that in a minute, it's a journey we're on and password managers and MFA and things like that, which, we'll, we'll look at their steps on this journey and, getting passwords away from people because people are the unreliable issue
Haree Yeah.
Adrian that's the journey we're on. We are taking the control. So the control is technical, not human.
Haree Do you know something you said at the start there was really interesting? We are moving everything to cloud. Previously everything sat in our offices, in the servers, in our server room and on local computers with little access to internet which meant the data never really escaped your physical premises And now it's all on cloud. Passwords are more important than ever because now you really do need to think about securing it. I say passwords, but some level of security. And I dunno if you remember, I certainly do back in the day, and it still happens. People share passwords across. Teams, oh, this person is off today. Let's share their password out. And that person's off, oh, what's their password? To access their computer. I understand when the data sat in your building and no one else had access to it.
Haree It wasn't such a major issue. Right now it's a major issue because it's in the cloud. You need to make sure you've got the best level of security.
Adrian Yeah, I completely agree with that. And that is the challenge, in the old days, lock the front door. Nobody's in the building. Your world is secure Now there's no front door to lock, so we need alternatives. And now the password, as you say, shared passwords. Bane of my life. Certainly working in an MSP, you know,
Haree yeah.
Adrian particular challenge for tech because you naturally have to deal with your client systems. So
Haree Yeah.
Adrian you log in as a client and work on their systems without knowing their passwords? Whole new technology has evolved to handle that one problem. it's a major issue for us within working teams. And the business, same as your, you know, applies. You've got five people accessing a website to do a particular function and they all use the same username and password.
Haree Yeah. And that's had to evolve obviously now. So we're at a point in time where everyone needs their own logins. Everyone needs their own level of access. You know, you might have Person A only needs access to, let's say they've got an e-commerce website, just to see the orders and make sure they're going through. Person B needs to process the orders and person C might work in finance and download all the financial data. Individual access gives you greater control over who's got access to what the level of security and. A bit of audit logging to see who did what, where, and when. Just in case something goes wrong, you can figure out who needs retraining or how to go back a few steps to fix that problem. Right. And
Adrian You,
Haree that
Adrian right. And the key to that is it's not so much, you know, having a particular password for
Haree mm-hmm.
Adrian It's saying who is it that is doing this? it's identifying the individual. this is Joe John's, whoever's password,
Haree Yeah.
Adrian their access, this is them doing it. And that can give them access to a whole raft of different systems, knowing it's them specifically that are doing it.
Haree Yeah.
Adrian We've got brilliant technology using, SSO single sign on where you sign on, in your Microsoft, environment. that gives you access rights to a whole set of non-Microsoft systems by virtue of knowing who you are and that you've signed on through secure mechanism.
Haree yeah,
Adrian that's a really powerful tool. it's about identifying the individual and knowing who it is. if you're sharing data or sharing access to systems, then it's still you doing it. the audit trail is key, who did this, who made that change? Who said
Haree yeah.
Adrian Who sent this email? You've got to know who it is that's responsible.
Haree And let's just go back to the password sides for a second. What's wrong with passwords at the moment? Because we've moved from shared passwords. Everyone has their own individual passwords, but it's still not foolproof. It's still not a perfect system. There are weaknesses within it.
Adrian so there's two issues of passwords. One is people and the
Haree Yeah.
Adrian So the people side of, it's quite straightforward. People are lazy,
Haree Yeah.
Adrian have, one password, which they use across multiple locations. it's obvious how that gets hacked and used.
Haree Yes.
Adrian reporting in covering that, If a password isn't complex enough and it's not always obvious to people.
Haree Yeah.
Adrian what complexity means then, you know, a machine can deal with that. Now you can stop a machine dealing with, I've got a presentation I do for clients sometimes on, password length. it's just a table. It may not be entirely accurate, but if you've got a four character password, it could be brute forced virtually instantly. you go up to a 15 character password on a decently poking machine, it takes about 12 years.
Haree Wow.
Adrian for those 12 years, hasn't anybody noticed this machine is sitting there trying to break into a system?
Haree If the machine lasts 12 years.
Adrian Exactly.
Haree so yeah.
Adrian my point is that the weakness here is yes, the people are lazy and use weak passwords and reuse them, system designers. System managers, us in our MSP,
Haree Yeah.
Adrian if we are not monitoring the password attempts and the failed attempts, then we are leaving a door open there as well. that's the other weakness of this system we should be monitoring this. in ICE Connect where we've got the tools to do it, we monitor it,
Haree Yes.
Adrian Not all systems have those facilities, so you can't monitor this stuff necessarily
Haree You mentioned, sharing passwords across multiple websites I've certainly been guilty of that in the past. when passwords were a thing of the norm in the early days, I had one password across every single website.
Adrian for shame.
Haree For someone who works in it. I get that. That very quickly changed to that one password with maybe a changed few characters representing the website I was dealing with. And that over the last five years has evolved into 20 character passwords, completely random, uppercase, lowercase characters, you name it. no chance I could remember any of it. And I dunno if you remember, there was a website, there still is a website. It's called have i been porn.com. P-A-W-N-E-D. You can go on there and see if any provider you are using has your password in there, which has been breached to some sort of public network or some sort of dark web and you can see which websites.
Haree Are affected. I, I know there were a few in the past. Adobe was certainly on this list. Dropbox was on this list. At some point, massive organizations are having this problem of passwords being exposed. Now, if one of those systems got hacked, your passwords exposed, if you've used that password anywhere else, that system is also exposed because chances are you've used the same email address across most of these. So your email and password has basically been put out in the wild for others to use. that takes you to a very weak perspective of shared passwords or passwords can be brute force like you suggested. So how do we protect against, this is the next question. What do we need to be doing to, let's start at the base level of, I've just got a username and password you mentioned.
Haree Silly character passwords. 15 characters you said takes 12 years, maybe use 20 characters, uppercase, lowercase, what have you. is that enough? Do we need to be doing more than that to get a better level of security And whose responsibility is that? The service provider, the website you're logging onto or you as the, service user. The one who's putting the password in?
Adrian Well, I think, there's a whole raft of things in there. the first thing is clearly you as an individual,
Haree Yeah.
Adrian to take responsibility for the systems that you access and doing it responsibly. A password manager clearly is a massively brilliant tool for helping with that, but that's part of the picture. People that design websites and implement systems that don't enforce a level of complexity and password length. Why on Earth not, you know, if somebody has a website out there, which
Haree Yes.
Adrian in, you know, a, a few characters and excludes numbers and symbols 'cause they haven't worked out how to deal with that yet, or for whatever their logical reason is,
Haree Yeah.
Adrian they have a massive responsibility for not being a responsible provider. It's clearly not a sensible approach.
Haree Just as you mentioned it's not sensible to have small numbers of characters, but the onus is on the person inputting the password, only 'cause I've just thought of this, is people always use a family member's name, a kid's name, they'll use a date of birth or a important date in their life. But these are common things, passwords 1, 2, 3, and I still think there's a large portion of people out there that still do that. Right.
Adrian correct. and for that reason, if you wanna brute force somebody's password,
Haree Yeah.
Adrian you don't just do it A, B, C, D, E sequentially, what you do is you pick the list of the published list of the 10,000 commonly used passwords and roll through them first. And that takes you a nanosecond or two.
Haree Yeah,
Adrian for a lot of people, a scary number of people,
Haree So we're saying the onus is definitely on the service provider to enforce something a little bit more secure. The user has to be a bit more mindful of the type of passwords they're choosing. but you've mentioned something most probably very important, especially when you're using these random passwords. Get a password manager, start throwing that in there, right?
Adrian It's the only way, and it serves two purposes for you. First thing it does is it lets you put in all the passwords you use and
Haree Mm-hmm.
Adrian you don't have to remember them, which is the first important battle. it generates passwords for you and you can, a lot of the password managers, you can adjust the rules. So you can say how many characters you want, whether you're gonna allow symbols or not whatever the rules are for the website you're working on. you generate the most secure password that it will accept.
Haree Yeah.
Adrian And the final point, with the password manager is that it can police what you're doing and it will tell you if you've reused. It will tell you if the password you've used has been breached. and it will prevent all of those, issues by analyzing your list of passwords and working out how secure you really are. It gives you a very good measure of whether you've done your job right.
Haree tell me a little bit more about SSO and MFA and how does that help secure your.
Adrian SSO single sign-on it's a technique that lets you use into somewhere that. Is secure and well protected,
Haree Mm-hmm.
Adrian So you sign into your Microsoft account and from that, because you're signed into your Microsoft account, you get access to, in our case, and knowledge base, help desk systems, whatever. They come in because you're signed into one, you get access to the other. And from a user perspective, it means you don't have to sign in twice.
Haree Right,
Adrian in once, and the once is secure. because it's secure and you don't do it twice, you actually reduce the risk dramatically. And, you simplify your world. And for the users, it makes it much easier because from their perspective, it's quick, it's easy, you just click the button and you're in.
Haree and in this scenario. Only Microsoft holds your password data in keeping it secure. That's never exposed to, let's say you are signing onto a internal company portal, using your Microsoft SSO Microsoft holds that password data, that password information never gets transferred to your company or the portal, right?
Adrian is a token,
Haree Mm-hmm.
Adrian is used. it's a time changing token usually so that it links the two sites together, and that gives you your access by virtue of the token that says, yeah, this guy's okay. You can go in. if the token is wrong expired, or, no longer live, then
Haree Yeah.
Adrian is blocked.
Haree And the benefit of doing this, I think is instead of having your company trying to hold all of these passwords, let's be fair. Microsoft has billions of pounds behind it all day, every day trying to better their security. And it's not just Microsoft, it's the likes of Google, the Apples and what have you. They've all got SSO, and the benefit here is they're managing the security. They're managing your passwords the way you log in. You don't have to, as an organization on your portals or, or the smaller companies building their portals, their websites, their their systems, that's no longer their responsibility. Let them build and focus on what they're good at. Not trying to also build and focus on a secure access system.
Adrian It's,
Haree Yeah.
Adrian trust, you trust Microsoft to do that job
Haree Mm-hmm.
Adrian honestly, if you put all your data in Microsoft or put it all into Google, you've given the trust already, so you might as well go the whole hog. There's no reason why you shouldn't do so.
Haree Yeah.
Adrian absolutely. the second reason for doing all this is the weakness in passwords, as I said earlier, is people, That's what the strength of SSO is, is that same weakness of people. People are inherently lazy, and SSO is a lazy man solution 'cause you just click the button you're in.
Haree Yes.
Adrian it could not be quicker or simpler. If you gave somebody a username and password they had to type in to get into that system, another one for that system, another one for that system is hard work. So SSO wins on that basis as well.
Haree Yeah.
Adrian Obviously you have opened a different door, so if somebody else sits down at your desk and you've left your machine logged
Haree Mm-hmm.
Adrian everything on SSO is available to them. you then need to think about, shutting down your machine, locking your machine
Haree Yeah.
Adrian when, somebody comes in and, you're going away for a cup of tea. you are exposed to risk in that sense, but you gotta look in proportion. It's much lower risk than the risk of, somebody out in the wild doing something to you.
Haree How does Microsoft SSO provide you better level of security than a website? we've built for internal operations with a standard username and password.
Adrian So Microsoft have locked their front door with lots of tech, and MFA is their current best solution for keeping the world out. multifactor authentication means that you authenticate two different ways. for example, your phone with Microsoft Authenticator is the standard way of doing it. So you're signing on your pc, it pops up with the alert on your phone, your key in the key number, and that's tied those two devices in. that technology, which is, being invested in is a key, part of the process. multifactor implication is, brilliant. something I am, something I know, something I have. that is the process of securing everything. I have to say, I think they've done it really well, when they first did it, they didn't have the key number,
Haree correct.
Adrian Now what they do is they present a number on the website saying, this number into your authenticator. And you go to your mobile and you type that number in, and that brings the whole loop closed. So you're
Haree Yes.
Adrian the fact that it's you doing it, you are on that website, you are on that mobile phone. Those devices must be in the same place and controlled by the same person. And the whole point is that because Microsoft have done genuinely a great job on that, it's security that I don't think, normal, business could emulate.
Haree There were multiple forms of MFA multifactor authentication. I know some banks, I logged onto my NatWest the other day and they've got, MFA where they send me a SMS message to my mobile. That's a form of MFA. There are arguments to say some people have been able to hack MFA, by getting into people's SMS and I guess they have to get onto your phone first. but you've got SMS as one, you've got these authenticator apps such as Google Authenticator, Microsoft Authenticator author is a personal favorite of mine. and they generate a code, which you have to then put onto the website. I have to say, Microsoft's really feels the most secure to me. they send a code on screen, which you then have to enter into your phone, that's where the security lies.
Haree you can't be. in a different country because you can't see that screen and then enter this code. that was one of the problems they had earlier. It got quite fatigued. They called it. You just kept on pressing. Yes. 'cause it kept on coming up so many times, but now you have to physically put in that code onto your phone to get in and through that you can secure a number of websites.
Adrian And if somebody were doing the brute force 12 years approach, it wouldn't take you long to realize that was going on.
Haree Because you keep seeing these popups on your phone to say
Adrian on your phone.
Haree someone's trying to get in.
Adrian we say to all our clients when we're teaching clients to use MFA and Authenticator on their
Haree Mm-hmm.
Adrian always think about, was it you that did it or not? if it appears on your phone and you've not triggered it for any reason, Say no and report it to us instantly. that's a standard message we give to all our clients. it doesn't happen often, but when it happens, it's been a lifesaver.
Haree I have to say this and it's really very controversial, but users are the weakest link in any form of security, You could lock everything down to the best of your abilities. With all the latest technology, it just takes one user to mess everything up. They click the wrong link on an email, on a phishing scam, download the wrong file, and that's exposed everything. I can't think of a scenario where a company has been breached, where a user hasn't been involved it just goes to show the focus on how important something like password is to security and how it's so dependent on the user being a little bit more intelligent, a little bit more wiser about their security and the security measures around them.
Haree Passwords being one big part of that whole user plan of security,
Adrian I think in this day and age, people need to start to build their lives around the concept of keeping themselves protected.
Haree Yes.
Adrian you mentioned using, SMS as a form of authentication for MFA and that's great, but it comes with risks and it's, being phased out because of sim hacking where, or sim swapping, where, it's been too
Haree Mm-hmm.
Adrian somebody to, Substitute their sim for your sim on your line for a period of time they have access to your code. the interesting thing is, it doesn't, the way we work MFA,
Haree Yeah.
Adrian can have multiple MFA systems, multiple MFA devices, once you've got access, the first thing the hacker does is set up their own MFA. they might set up a separate authenticated device on their phone. They might set up, a separate mobile number to receive the SMS Then they put back the damage so you don't notice that they've done that. but they then have free access because they've got their own, their own, ability to answer the MFA question.
Haree Yes.
Adrian MMFA is not without problems, and it only takes one breach of that to expose the whole thing.
Haree And once we've gone and dust done and dusted with passwords, what's the next level of security? There's gotta be something which is better than passwords, which is moving on into the future. We always complain about passwords. I think the biggest gripe I have is not everyone has SSO and in the space of a day, I've probably logged onto 20, 30 different sites. New password each time, new remembering which one was access to this. Yes, the password manager definitely helps here, but there has to be an easier method of logging onto things. And I know there's some technology on, on, obviously on your mobiles. if you're an iPhone fan, you've got face id, which lets you log into the phone and all the banks are using that as their default security method.
Haree I can log onto my, mobile banking app using my face id.
Adrian to be honest,
Haree Why does it scare you?
Adrian Biometrics are
Haree Mm-hmm.
Adrian and they work tolerably well a lot of the time. Facial recognition. I personally don't, I'm not convinced by that. I think there's way too much, weakness in that system. It's very sloppy. So you are doing facial id, young people, old people, it's very unreliable for,
Haree Okay.
Adrian you've set yourself into a system, in a few years, you've aged a little bit, you've got a few more wrinkles, it no longer works for you. it's not a reliable system over time for anybody.
Haree Mm-hmm.
Adrian I have a concern. I mean, the, the way facial ID works, it works by mapping your face, the locations of key bits of you, your eyes and your mouth and your nose and. Creating a map, and then from the map comes a hash. And the hash is, stored and sent and is used.
Haree The hash is like an encryption key
Adrian Correct?
Haree Yeah,
Adrian it's the consolidation of all that data into a single, very long string.
Haree yeah.
Adrian but that information comes from of you.
Haree Can I put my phone up to a picture of me and let that unlock my phone?
Adrian the big question, isn't it? and the answer is no,
Haree Okay.
Adrian answer is almost, and I, I just have a doubt, a nagging doubt in back of my mind that it won't take long for somebody. You know, how many photographs of you are there on the internet? Each at a different angle, each from different perspective, a different lighting.
Haree Someone's gonna 3D print my face for unlocking my phone.
Adrian they, yes they could, but terrifying prospect. but more importantly, feed that lot into an AI system that is going to work out what the hash would be for your facial id.
Haree Wow.
Adrian And
Haree Yes.
Adrian So now, I'm not saying this is possible now, although it probably is, and then what they're gonna do with it, that suddenly becomes a tool which you could use if that is your only line of defense. If it's just one simple, I mean, let's be honest, facially, you, you have to do go some to deal, to do all that stuff
Haree Mm-hmm.
Adrian now. But if you're looking about the perfect solution for the future, I'm not convinced that, is right for everybody and for all time.
Haree So we've got things like, face ID What about fingerprint Id.
Adrian Fingerprint ID seems to be brilliant. the challenge is exactly the same though. So fingerprint ID is great. We've got fingerprint ID on our front door. You put your fingerprint on, it unlocks the door, and in you go. our MFA by the way, for anyone that wants to rob our office is we've also got an alarm system, which is totally separate. You need your four, but otherwise it don't work just to put that out there for everybody. but, assuming you're not gonna gonna be doing anything devious it, it works well because we've got a second area of defense
Haree Yes.
Adrian But now, where is that information? It's stored in the reader and that's where the data is stored.
Haree Mm-hmm.
Adrian I have no issue with that whatsoever. But what would happen if some bright Spark went along and said, here's this box that's got all the data to all of these people's fingerprints. I reverse engineer that?
Haree Yeah.
Adrian I get that data out, work out their fingerprints and re-encode it for somebody else's system so I can do fingerprint IDs for somebody else?
Haree So
Adrian for your laptop.
Haree you've got fingerprint ID on the front door. I've got fingerprint ID on my laptop. many people use it on their laptop. That fingerprint ID for all intents and purposes is local storage. It stays on my laptop. It stays on your box in the office. What if we have, and I've seen it, cloud systems, which allow you to use your fingerprint ID as opposed to a password to get into sites. Now, presumably that fingerprint id, that hash code it generates by scanning your fingerprint ID is stored in the cloud, which means they don't need physical access to your premises or your laptop or your box to get that hash code or even reverse engineer it
Adrian This is the Emperor's New Clothes. this is
Haree Yeah.
Adrian the problem. So all the biometrics are brilliant. They genuinely are brilliant, convenience, fabulous. You know, put my finger on my laptop, it unlocks. sitting there of an evening, you don't want to kind of work out where the buttons are. Your back lighting's not working in your keyboard, typing out a complicated password. That's a thing of the past. It all just works. It's genius. But the problem is underlying that is a hash code. It's an encryption key.
Haree Yeah,
Adrian and yes, if it's not quite as simple as saying that hash is enough to unlock your well, because there's also, the certificates and the codes, the tokens, the pass between devices, I think this takes us neatly to Fido as a point, because this is the absolute case in point of this A problem, and B, the solutions to it. I dunno if Fido's a familiar term to
Haree I was about to ask you, what is fighter.
Adrian So Fi Fido is a technology, it's now Fido two because they've improved it. it's principally used for, it's a standard for securing biometric and other, data. a Fido two key is basically something you plug into, the USB of your laptop.
Haree Right.
Adrian it's maybe got a fingerprint scanner on it. if you've got a Fido enabled machine, then your mobile might be Fido enabled. that technology is used directly on the fingerprint scanner of the mobile and for your facial id. the encryption is significantly more, secure than. a normal process. you generate data stored locally, generate a cryptographic key, and that's what's used to, to log in, but it's a hardware device and you walk away from a computer, you take your hardware key with you, that means nobody else can log into that machine because they don't have the key.
Haree How does that compare to something like these newbie keys? I know a lot of people use those in cryptocurrency, and people have got thousands, tens of thousands, millions of pounds stored away in cryptocurrency. There's gotta be a good level of security behind that, right?
Adrian Yeah, absolutely. and that is part of the same technology. the, standard hardware security keys are for unlocking. Websites and, local devices. So you've got your Fido key in your machine that will sign you into websites that are on that program as well as into devices. that's fine as far as crypto is concerned. Then the game is slightly different because the value of the contents is the keys that are stored on the device as well.
Haree Right.
Adrian your biometrics or whatever solution you choose to use gives you access to that device, and that gives you access to your account, your crypto key, which gives you access to your money the two are, one is an extension of the other, all this tech blends into the same thing. with Fido it's a set of standards. this is how you do it, this is how you run the process. And that 'cause you've got a standard way of doing things. It means that you can have a key in your computer authenticates you into a website. That's absolutely got nothing to do with manufacturer of the key. just use the same standards. if that whole
Haree Yeah.
Adrian then that's great. and I suspect that is where the future's heading. Although, embedded rather than separate keys seems more sensible. 'cause you can lose keys.
Haree Is that similar to pass keys?
Adrian it's identical.
Haree Yeah.
Adrian the past keys work that way as well. past keys are, an amalgam of different biometric. Authentications into one
Haree Mm-hmm.
Adrian and that allows you access to whichever site or system you gain access to. so you sign into your Amazon account using a pass key, and that's a full authentication from your biometrics straight in to that account.
Haree Yeah.
Adrian And if all the steps on the way are secure, then that's a secure process. I don't think anyone's gonna have any issue with that as being the end game. The problem is where are the weaknesses in that? who are you trusting with? pass keys a great concept falls down a bit for me when you, I mean, the Google approach is, is interesting. So Google say use pass keys, it's commute secure and the data's all stored locally on your device.
Haree I've seen all of this pop up on a web browser. I have to admit, I've rarely used that. I don't think I've set up any of it yet.
Adrian it's interesting how some people set that
Haree Mm-hmm.
Adrian Because they think that all they're doing is entering the identifier, the pin code for their local computer,
Haree Right.
Adrian then they set up a pass key for the website that's signing into an Amazon account Google account or whatever it might be. And you do it by accident, even realizing you've done it. it's very easily done the dialogue is, not misleading exactly, but if you don't understand what it's asking, give the answer to the question and then you are, down a path.
Haree Yes.
Adrian Google's approach to me, it worries me because Google say this is all stored locally and that's fine. We don't retain any of your data. That's fine as well. And then they say, but we replicate it to all your devices. And that's where it all falls apart from my perspective.
Haree It's gotta be stored somewhere, right?
Adrian Yeah, absolutely. They replicated it to all of your devices. Now, what would happen? Imagine you are, you know, your malicious intent.
Haree Yes.
Adrian if you could get another device into that, replication network, then your device has got the masking on it, then what?
Haree In this scenario where you're a dependent on someone like Google to store your pass keys or any kind of biometric data, whose responsibility is it? If something was to get breached, and let's just say for example, you've got your, e-commerce store and Google stores, the PAs key because you're using that SSO PAs key in the scenario, but someone manages to get into the account in order a whole load of stuff and get it shipped to themselves and you're stung with a bill.
Adrian Welcome to our can of worms.
Haree Big problems, aren't they?
Adrian Yeah, I genuinely, think, a lot of this stuff is very much work in progress
Haree Yeah.
Adrian I don't think anyone has all of the answers that we're heading towards them. And I haven't actually read Google's ts and ts for pass keys, but I can imagine them, themselves from any liability because it's all your fault, not theirs. and that will doubt, let's get tested at some point in the courts 'cause it is absolutely bound to happen.
Haree Yes,
Adrian self-defense is obviously the best thing, but you know, you've also got to look at it in relative terms this may have weaknesses. There may be ways that the data could escape. There may be ways that a problem could occur that you could be breached. But is it more likely to be okay than our current setup of using a password where you foolish, untrustworthy user, have messed up by reusing a weak password? and without doubt, this new way of doing stuff is more secure.
Haree yes.
Adrian is it secure enough? Does it shift the liability to somebody else or does it shift the control to somebody else and leave the liability with you? And I think those are the kinds of things that we have to worry about because Google will not take responsibility for this. apple will not take responsibility for a, misconfigured face id. It will be your issue. It's bound to be because it's your face.
Haree Is it fair to call those technologies a bit more of a gimmick at the moment and the stop gap between passwords to biometrics, which is measurably where we're at at the moment. Moving onto PAs keys?
Adrian And like I said earlier, it's a, the world's in transition. We're on a journey.
Haree Yeah.
Adrian where is the end point? there are people that think that the end endpoint is a, a ID number for each individual person stick it in a chip under their skin. And you always know who it is. it all depends on what your end game is, doesn't it
Haree Yeah,
Adrian who can tell? retinal scans are supposed to be a hundred percent foolproof.
Haree not according to the Matrix
Adrian absolutely. it's surprising. go back to your Star Trek and think about how communicators suddenly turned into mobile phones. this stuff does come back to haunt us. You know, people have bright ideas
Haree I'm going to be very honest with you I've never watched Star Trek. I haven't a clue.
Adrian I am showing my age, but if you imagine a device which you could stick on your wrist or holding your
Haree Yeah.
Adrian where you could flip open the flappy bit and talk in it, and somebody a long way away could talk to you.
Haree Well, we've already got that with the, apple Watch. I use it to make calls a lot of the time.
Adrian But then think this was something that arrived in science fiction.
Haree Yes.
Adrian How many, I don't even know how many years ago. But, a lot.
Haree I'm gonna say 30 to 40 years, mate.
Adrian Thank
Haree Yeah.
Adrian Thank
Haree Yeah.
Adrian that.
Haree And if we do the mathematics, you would normally be around in your twenties. I'm joking.
Adrian Uh, dear. it was gonna come down to this eventually with this conversation. it is interesting 'cause it is a progression. and what we're doing right now, what everybody's doing right now is they're sitting down saying, we have the tech, we could do this anyway. We have the ability to do this anyway. And what we're trying to say is, what is the way that gives us the best chance of identifying
Haree Mm-hmm.
Adrian you are preventing somebody from doing that maliciously and wrongly. people come up with different solutions and Microsoft's invention of MFA plus addition of the numbers into MFA,
Haree Yes.
Adrian authenticator app. But where's it gonna end? who's Blue Sky thinking is gonna come up with a better way of doing it.
Haree I mean, you've touched on a very important point there. If you are a business at the moment, think about startups, for example. You are developing a new app. You're developing the next greatest product in the world. How are you going to work on the security of authenticating users? You're saying biometrics is maybe not completely where we want it to be. You're saying pass keys are great things like face id you're not so confident in, but you are with fingerprint. Is it a waste of time and money? Sticking to the outdated passwords management systems and just scrap all of that and go straight to the best product on the market at the moment.
Adrian That's a challenging question I think. Companies are naturally lazy in just the same way that people are. So you're developing this brilliant product. You focus on the product, you don't focus on how it's
Haree Mm-hmm.
Adrian and secure by design is, absolutely a critical part of the process, developing your product, and it's expensive and there's no return.
Haree No.
Adrian succeed in making something secure, nobody's ever gonna know that you've put that effort in. the only time it's found out is when it's not secure. And at that point you'll pay the price. security in the design of products is a big challenge. there's no immediate obvious quantifiable benefit to it. how do you do it? the answer is if it's your area of expertise, happy days crack on. But for most people, for businesses, if you are putting something out there that's a web tool, for example,
Haree Yeah,
Adrian most people don't have the knowledge, the experience to build the security, and getting somebody with expertise, getting somebody that's got that tech buy in as a package.
Haree and there are third party companies which do that, right?
Adrian Yeah. No,
Haree once your development team are finished building an app, for example. Use the third party organization to security test those apps for you.
Adrian Well, isn't this what we said earlier about using S-S-O-S-S-O is genius for that because Microsoft spent
Haree Yeah.
Adrian apple has spent millions, Google has spent millions make use of it,
Haree Yeah.
Adrian to their SSO. There's a, there's a documented path for doing that.
Haree And they've got biometrics built into their SSO?
Adrian completely,
Haree Yeah.
Adrian yeah, because what it's about is about saying sign in security to Microsoft, sign in security to Google, so pass key Google, you're signing in using your face id, whether we like it or not. That's happening. once you have signed in. And are secure, you take their word for it, that, that has worked and is okay.
Haree Yes.
Adrian And at that point you can then say, SSO, I trust you because it's you, because Google say
Haree Yeah.
Adrian And that genuinely works. And the other thing that you can do when designing your products, it's you layer things. I remember back in the day we used to build e-commerce systems for websites, and you'd build a payment gateway.
Haree Mm-hmm.
Adrian That's very much a thing of the past because gateways, the banks do all that stuff. So what happens is you, and some third party organizations, PayPal or whoever, When you take a payment on your website, hand that over to a third party. So you hand it over to the bank, the bank sends you the text, it asks you for a code, it
Haree Yes.
Adrian does whatever the bank is gonna do. They secure the money flow, and you just get a confirmation that it's been done. by removing from your world the need to design a payment, you don't need to handle credit card numbers and protect them. You don't need to protect people's names and addresses. All of that is handled by a third party.
Haree And in a scenario where we're dealing with passwords, we're dealing with security. It'd be strange not to include GDPR in the conversation, especially here in the uk.
Adrian Sure,
Haree What GDPR implications do companies have when it comes to these passwords, these biometric storage and everything around it? Because that is personal information, which even if you're employing somebody, they leave, they move to another company. You're still storing their biometric data for a given amount of time, I guess, aren't you?
Adrian I think this comes back to, the answer is yes, and it's really difficult to handle that because yes, you're storing the data, but do you even have access to it? If I said to you, extract your fingerprint from your laptop, you'd look at me blankly and say, what?
Haree It's true.
Adrian if somebody leaves a company, their account gets deleted. The account is no longer on the laptop, the biometrics have gone.
Haree Yeah.
Adrian it sort of doesn't matter. But there's gonna come a day. when the day arrives that some brightspark manages to, reverse engineer, fingerprint data, reverse engineer face ID, or all of that stuff, if somebody can extract that data from a system at that point, it becomes the responsibility and the liability of the person that holds the data to stop 'em doing it.
Haree Yeah.
Adrian kicks in full force. it's hard to overemphasize the seriousness of what happens if you start off and you've got, a password and somebody hacks your password, your solution's simple, just change your password and you're off and running.
Haree Yes.
Adrian If somebody has compromised your fingerprint, what are you supposed to do?
Haree Yeah.
Adrian and that the whole thing, the way where that goes, I don't know the answer. I don't think anyone knows the answer because, you know, If the fingerprint is translated into a hash and the hash is compromised, you're sunk. I don't think there's any way of getting back from that because you can't change your fingerprints, you can't change your retina scan, you can't change, your face Id. I mean, you can grow a beard and change your hair and whatever, but
Haree Still not gonna change it enough?
Adrian No.
Haree No. What about multi-layered security. you need your password. your MFA code and you need some sort of level of biometrics. and there's three layers of security. I'm not saying no one can get your password or, or, or you know, try and brute force and hack your password. I'm not saying people can't get onto your device and get access to your MFA code 'cause potentially at some point they can. And the same with the biometrics, but a three layered security, that's exactly what SSO is, isn't it? And, and that gives you enough reassurance that someone's gotta get through all three to be able to get through to your system and, and that access what you have access to, right?
Adrian A hundred percent. The peak of our security right now is layered.
Haree Yes.
Adrian I said to you about our front
Haree Mm-hmm.
Adrian Fingerprint, but there's the alarm behind it. So get through one. You still have to get through the other.
Haree Not to mention the steel gates, the barbed wires, the
Adrian the
Haree snipers,
Adrian that's right.
Haree fences. Just in case anyone's listening, it's fully secure. It's military grade security around this office.
Adrian that's absolutely right.
Haree Yeah.
Adrian putting those layers in place, is key to it. And, I, the, the, the of security fine. But on top of that, there's the one thing we do routinely as part of the service we give our clients is to monitor. What's going
Haree Mm-hmm.
Adrian so that when somebody, you know, if somebody tries to break into your password, the MFA clicks up on your phone, you can spot that and you can deal with it. we would monitor, for example, take a 3 6 5 login. somebody logs in to your UK business account from Central Moscow. We get an alert, says that's a bit odd, what's going on?
Haree Yes.
Adrian we would contact a client and say, are you in Moscow at the moment? this has genuinely happened, by the way, and the
Haree I believe it has.
Adrian they're in Turkey. using a Russian mobile sim, which is an interesting scenario, but,
Haree Yeah.
Adrian those conversations happen on a daily basis here. the fact that we then take action immediately. We lock accounts, we block accounts, we question, we monitor. That's the other layer of security. It's the fourth layer. to me that's critical. Monitoring what's going on makes sense. And it's the best we've got right now where it's heading. I genuinely, I don't know, it's an arms race, as soon as the tech companies invent a new solution, the hackers invent some new way around it. when MFA came out, they invented the, reverse proxy and everyone can then break into MFA.
Haree No
Adrian If you're targeting an individual person, it's really hard, to defend yourself. So you just have to do the best you can. If you're talking about a general attempt on the infrastructure of the world or a system, multi-layer works, and at the moment that's the best we've got.
Haree AI is going to make things a lot quicker and easier to do in terms of hacking, isn't it?
Adrian I lose track of the number of genuinely brilliant emails that are phishing emails that get through a lot of the spam filters because what comes through looks so good.
Haree Yeah.
Adrian gone are the days when you could tell it was, a hacking attempt because it's written in pigeon English, to coin a phrase. it's a gibberish email, spelling mistakes and punctuation mistakes and things that wouldn't happen. They haven't got the right logos, whatever it might be. Now you receive a phishing email that looks and feels completely genuine,
Haree Yes.
Adrian that's a bit scary. That's AI hard at work. the facial ID thing, if somebody can do. Which they can now an ai, which fools people on a Zoom meeting to think they're talking to a person they're not talking to. can do that in real time on video and it's convincing.
Haree It's crazy scary, isn't it?
Adrian It is crazy scary when you're relying on that same image to unlock your phone.
Haree It goes back to what you said earlier, we are not far away from some AI piecemealing all of your photos together and giving it to a 3D printer to say, right here, go and print this. And, you've got a, almost instant replica of your face without ever having stood still to pose for somebody to get it done.
Adrian it's a demonstration. It's been done many times when the banks first released, telephone banking before your time. they did it with voice recognition. It's perfectly secure.
Haree Yeah.
Adrian brilliantly until it didn't and it was easily demonstrated, that this was a stupid idea but nowadays, can you imagine how simply it is to have AI replicate your voice and you can do it? anyone that's got 10, 15 minutes of their, okay, how long have we been on this cast? Right?
Haree Yeah.
Adrian or 15 minutes of their voice on the internet. You can produce a completely lifelike. Replication of that
Haree Wow.
Adrian So if you can do that with voice, you can do it with video, you can do it with face. You've got to accept that all of those things are gonna happen and there's nothing you can do to turn, you
Haree Yeah,
Adrian AI will do this stuff.
Haree Now let's, try and summarize with some practical tips we can give to organizations on how to better their security. Managing their internal staff as well as how they're accessing websites, how they are logging onto things in the cloud. You've got your Microsoft platforms, your Microsoft three, six fives or, or your Google workspaces. Those are the big key ones which most organizations are using. What levels of security can they implement here today to better that?
Adrian wherever you are in the security journey, you can always go a step further. There's some really simple stuff. If you haven't turned on MFA, turn it on because MFA is absolutely a requirement. There are very few services. Don't use it.
Haree I was about to say it's by default, the most common thing to do now, right?
Adrian C correct, but you'd be astonished how many systems still don't have that enabled.
Haree Yes.
Adrian it's not helped by some services not mentioning,
Haree I.
Adrian large social media concerns, removing the MFA facility, unless you pay for it, which was, not necessarily a positive move.
Haree No,
Adrian but yeah, implement MFA instantly. Immediately.
Haree that's across all platforms.
Adrian If it's an option, turn it on.
Haree yes.
Adrian And if it's not there as an option, demand that it be
Haree Yeah.
Adrian there's absolutely no excuse in this day and age. remove all forms of password sharing. Password sharing should not ever happen you, if you need to share access to a service, use a password manager so the sharing can be done without people. Actually knowing or sharing the password itself, it's being done cloaked by a positive manager, but you shouldn't need it. you should be able to get around that a different way. So get rid of all forms of password sharing. Now somebody goes on holiday so somebody else logs in as them. No, absolutely not. Give that person access to that person's account or the bits of it they need while in a holiday. Fair enough. But don't make them pretend to be that person. That's ridiculous.
Haree agree.
Adrian adopting biometrics everywhere. every laptop you buy hasn't got a fingerprint scanner on it. It's the wrong kind of laptop. That's just ridiculous in this day and age. if you've got a mobile phone that hasn't got a PIN code on it or face ID to go through on the biometrics, then, that's foolish. Frankly. It's stupid. You've got to have some form of self-defense.
Haree Yes.
Adrian I like the fingerprint reader on mobile because you can't shoulder surf it. Nobody can see your code. the code is always there if you need to go, back or the pattern Once again, people can watch them
Haree Yes,
Adrian you have to be really good at entering a pattern so nobody can see it. I'm not that good. maybe you are.
Haree yes.
Adrian I like the fingerprint because you just put your finger on it.
Haree It is funny you mentioned that I was in the car with my kids the other day and I've managed to get my 8-year-old to the age of eight without giving him my password to my phone. I always use face id and the other day, face Id wasn't working for whatever reason and I had to put in the password. I could see him peering over my shoulder trying to figure out my password or the pin code to get into the phone. 'cause the face ID wasn't working. And I was like, I, I just had one eye out of the corner of my eye looking at him and I was like, right, this needs to go under my hood and coat jacket, then bring it out. But it just goes to show you don't know who's looking over your shoulder to see you entering any of this stuff in, which is where things like face ID and fingerprint really come in. And that's the level of MFA you want to have on your device to, ensure it's secure.
Adrian and you can add users these days, you can add other users into your device. So you can say, if you want your kids to have access to your mobile phone, you can give them an
Haree Please don't suggest that.
Adrian didn't say that. Nobody said no, there was nothing was said, but you can control it. the whole point of the exercise is control everything, but
Haree Yeah.
Adrian biometrics everywhere you can, that's absolute requirement. start to educating people or in every organization should have some form of security awareness training. They
Haree Yes.
Adrian They should be shown because people, it's, it's hard. I mean, we, we work in it, I work for an MSP ice connectors does this day in, day out. And you know this stuff instinctively because it's what you do all the time. Normal people, don't get a sense of how bad things can be when you mess up. it's really important to show people the consequences are of their actions.
Haree Yes.
Adrian a good thing is the Twitter hack of a few years ago when the president of the United States starts sending out tweets, for, crypto, crypto scam.
Haree Yeah,
Adrian the underlying cause of that problem was password sharing.
Haree we see that a lot in the, social media space, don't we? People getting hacked, especially on Instagram. People get hacked and suddenly they don't have access to their old accounts. Someone started messaging out all of their contacts and stuff. I've noticed it and heard about it on Twitter a few times as well.
Adrian WhatsApp as well. it's a common thing for, a WhatsApp scam.
Haree Hmm.
Adrian the process is comparatively straightforward. It's just social engineering and at the end of it, you've
Haree Yes.
Adrian account and it can take so long to get your stuff back and sometimes, because can't always get a response from a large social media company, not mentioning Facebook by name obviously, um, but you know, try and phone up their help desk and get some assistance with an issue. You get the sound of silence It's just impossible. They've got some great automated systems, don't get me wrong, but you need to talk to a person and say, this is how I got here. Can you please get me out of it?
Haree Yeah.
Adrian and it's very hard.
Haree There's one other practical idea, which I thought was very useful, you mentioned earlier, which was password managers. the purpose of having a password manager is it allows you to have those stupidly long passwords with random characters and punctuation all over the place, and ultimately, no two sites should share the same password. If you've got a thousand sites, the password manager is exactly where it should be stored. They're secure enough to keep your passwords there. And if you have little faith in those levels of security on a password manager, don't forget you've got that MFA level of security, multi-layered security already. So it's just one step in the chain of being secure.
Adrian people say, well, what happens if the parcel manager gets had? And that has happened to
Haree Yes.
Adrian But the answer is that. It's still much safer than the alternative of trying to do it insecure
Haree Yeah.
Adrian my password manager says to me every time I sign into it, there are, I think it's 75 duplicate passwords in my system. The reason, by the way, is because, some websites have multiple URLs, so I've entered them several times to cover the different URLs. It's actually the same site and the same password
Haree Yes.
Adrian that's the
Haree I.
Adrian So you've got, you can play the game and, work out which one to duplicate and deal with the problem.
Haree Yeah.
Adrian it's very cool and it's not perfect, but it's part of the stages to go through while we have passwords. That is a hundred percent the app, oddly sane approach.
Haree Yeah,
Adrian So let's say you were ill or heaven forend, you had an accident and weren't there anymore. What happens to all of your world that's in your brain locked up in all these passwords? a password manager enables you to offer emergency access to a trusted third party.
Haree Yeah.
Adrian in the event that I'm not able to deal with stuff for a bit, gives you access to everything that I've got so that you can sort out my world while I'm not able to.
Haree Or in the essence of a business, if someone has left, but they managed to create all the passwords in the accounts. It manages the owners or, or senior team leaders to access those accounts after that employee has left, right?
Adrian Completely. And, it, it's about keeping your, uh, the value of your business to you. It's, it is the same thing about mobile phone numbers. You know, do you, do you give all your clients your staff's personal mobile phone number? If you do that, then when they leave, they take the clients with them.
Haree Yes.
Adrian If you give them a business number the clients stay with the business
Haree Yes.
Adrian it's sort of common sense. businesses evolve over time and they don't always know that stuff. I spend my life around different businesses and saying. Okay. What you're doing is really great. I can see how you've got here. The next steps for you are this, this, and this. one of them, is dealing with phone systems and getting the phone numbers sorted out. Exactly. As I said, personal mobiles are a particular risk. Keeping the value of your business internally, as you
Haree Yeah,
Adrian that's really important. Absolutely. Because you then retain access and you can't be held to ransom. somebody leaves under a cloud, let's say, if they refuse to give up the goods, what are you gonna do?
Haree yeah, very true. Adrian, thank you very much for joining me on this podcast today. It's been very insightful talking to you and, a lot of information to, absorb in just one session I have to be honest, but the tips at the end. Fantastic. Thank you very much.
Adrian Thank you Harry. Appreciate the invite and it's been a delight talking to you.
Haree Alright. That brings us to the end of today's episode on passwords and biometrics. A huge thanks to Adrian for joining me in this great discussion. Remember, whether you're considering PAs, keys, biometrics, or both, the key takeaway is to stay ahead of the curve when it comes to security. If you want more advice or have any questions, feel free to reach out to me@thecyberceo.com. We're always happy to help.