惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
Jina AI
Jina AI
博客园 - Franky
Apple Machine Learning Research
Apple Machine Learning Research
酷 壳 – CoolShell
酷 壳 – CoolShell
阮一峰的网络日志
阮一峰的网络日志
量子位
雷峰网
雷峰网
宝玉的分享
宝玉的分享
V
Visual Studio Blog
博客园_首页
小众软件
小众软件
The Cloudflare Blog
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
博客园 - 聂微东
S
SegmentFault 最新的问题
博客园 - 【当耐特】
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
博客园 - 叶小钗
月光博客
月光博客
博客园 - 三生石上(FineUI控件)
人人都是产品经理
人人都是产品经理
WordPress大学
WordPress大学

Latest from TechRadar in Pro

VodafoneThree gets Ofcom approval to bring satellite connectivity to your smartphone Is this the tipping point for AI at work? New Gallup survey finds half of all US employees now use it in some way 'Every Apple user needs to know about this nasty scam': Fake warnings tell users their iCloud data will be… 'Makes it even more disappointing': Microsoft backs fossil fuel big time with $7 billion deal in race for AI… 'Maybe it’s not science fiction': Solar panels are causing rainwater to fall in one of the driest places… Maine becomes first US state to pass data centre construction ban Dozens of WordPress plugins hijacked to target thousands of sites Drone-killing laser weapons greenlit for use in US airspace – FAA and Defense Department say high-energy weapons are ‘ready to protect all air travelers from illicit drone use’ despite airspace restrictions and friendly-fire incidents 'We are currently being extorted' — crypto giant Kraken says it is facing extortion attack, here's… I tried 7 free MTD software – now I've ranked my top picks as a freelancer Jackery McGraw Hill becomes latest to see its Salesforce data hacked Looking for a new PC? Now might be great time to upgrade, as Gartner figures claim shipments are rising — while… The new engineering playbook: how AI design copilots are reshaping product development Farewell Surface Hub — Microsoft kills off its super-sized touchscreen displays, but you might still be able to get one if you act fast 'We have no interest in patient data in the UK': Palantir UK head defends record as criticisms rise Amazon’s new AI Bio Discovery tool can provide ‘every researcher’ with ‘lab-in-the-loop drug discovery’ – 40+ AI biology models can filter 300,000 novel antibody candidates down to the top results for testing in just weeks Over 100 Chrome Web Store extensions found stealing user data from thousands of accounts Europe wants tech sovereignty but is this realistic? Enterprise AI governance cannot live in a prompt. So where is the safety net? Why 2026 is the year of flexibility without friction: solving the multi-platform crisis OpenAI reveals its Mythos rival designed for cybersecurity pros When cyberattacks are inevitable, recovery becomes the strategy Closing the cloud complexity gap LaLiga uses AI to fight illegal streaming that costs its clubs $800m a year Intel and Google expand long-term chip partnership to power AI systems 'Chatbots respond not just to what you ask, but how you ask it': Report finds AI agents might be sucking up to… 'Smartphones have physical limitations': Report explains why AI is kickstarting a billion-dollar hardware arms… 'I’m pretty sure actually we really do not need to work for five days' Zoom CEO calls for end of traditional work schedules — says 3-day working week should become the norm 'It's more common than you think': Experts reveal how hackers are trying to hijack your inbox with these…
The downfall of the login is redefining security
Paul Inglis · 2026-05-14 · via Latest from TechRadar in Pro

Traditional passwords have long been treated as a frontline defense against malicious activity.

However, as cybercriminal networks grow in sophistication and attack methods become increasingly driven by AI tools, these legacy controls are failing to stop modern threats.

Senior Vice President & General Manager, EMEA at Ping Identity.

We have reached a point where usernames and passwords are a systemic liability; they represent a single point of failure that is easily exploited by automated, high-velocity attacks.

To remain resilient, organizations must move beyond the "point-in-time" login and embrace a model based on continuous, decentralized identity.

Weak controls are no match against modern threats

While poor cyber hygiene - such as password reuse and guessable sequences - is a contributing factor, the primary vulnerability lies in the nature of the credential itself.

In the UK, 85% of businesses report experiencing phishing attacks, which have evolved from simple social engineering to sophisticated Adversary-in-the-Middle (AitM) operations capable of intercepting session tokens in real-time.

When an attacker gains access through stolen credentials, they leverage the fact that most systems treat a successful login as a permanent grant of trust for the duration of a session.

Sign up to the TechRadar Pro newsletter to get all the top news, opinion, features and guidance your business needs to succeed!

Furthermore, the industrialization of fraud means that brute force and credential stuffing are no longer manual processes. AI-driven automation allows threat actors to test stolen data across thousands of platforms at record speed, turning a single compromised password into a gateway for lateral movement across multiple enterprise systems.

Passwordless authentication, biometrics and advanced alternatives

To mitigate these risks, organizations are transitioning to passwordless options that eliminate the reliance on shared secrets.

Passkeys, based on the FIDO2 standard, offer a more robust verification method by using asymmetric cryptography. Because the private key is stored securely on the user's hardware and never transmitted to a server, the primary vectors for phishing and credential stuffing are effectively removed.

Zero-knowledge biometric authentication provides a further layer of security without the privacy risks associated with traditional biometric databases. These systems are designed to verify a user’s identity locally on the device or via encrypted templates that cannot be reversed to recreate the original biometric data.

By ensuring that sensitive biological information is never centrally stored or transmitted, businesses can achieve high-assurance verification while maintaining a privacy-first posture.

Decentralized credentials represent the next evolution in this space. By using cryptographically signed data stored in mobile digital wallets, individuals gain full ownership of their identity.

This architecture allows users to share only the specific information required for a transaction - verified by a trusted issuer - without exposing unnecessary PII.

For the enterprise, this reduces the data liability associated with managing large pools of sensitive user information, which are frequently the primary targets for large-scale breaches.

A new era of passwordless security

The downfall of the traditional login is forcing a move toward runtime security and continuous verification. In a landscape where AI agents may act on behalf of users, security can no longer be a one-time event at the start of a session.

Modern architecture requires real-time bot detection and behavioral signals to monitor the context of every interaction. If an authenticated session exhibits anomalous behavior, the system must be capable of triggering frictionless re-verification to confirm the user’s identity and intent.

The transition from legacy authentication to these advanced alternatives is no longer a matter of convenience; it is a requirement for maintaining integrity in a sophisticated threat environment.

While moving away from passwords presents implementation challenges, the cost of maintaining a vulnerable, credential-based perimeter is far higher. Embracing passkeys, decentralized credentials, and continuous biometric verification is essential for protecting identities and securing the digital workforce of today and the future.

We've featured the Best Password Managers: Expert Recommendations for Your Credential Security.

This article was produced as part of TechRadar Pro Perspectives, our channel to feature the best and brightest minds in the technology industry today.

The views expressed here are those of the author and are not necessarily those of TechRadarPro or Future plc. If you are interested in contributing find out more here: https://www.techradar.com/pro/perspectives-how-to-submit