Aloaha Software

Smartcard and PDF Applications

Menu...
  • Home
    • Free Aloaha Tools and Applications
      • CodeB SMS for Android
      • CodeB Signator for Android
      • CodeB Authenticator for Android
      • SMS SMPP Client
      • Aloaha PDF Suite FREE
      • PDF or DOCX to PDF/A Conversion Tool
      • ZUGFeRD Reader
      • Aloaha PDF Editor and digital Signator
      • Free PFX Self-Signed Certificate Generator
      • Aloaha Remote Desktop (RDP) Manager and Launcher
    • Public Key Infrastructure (PKI) consultancy
    • ZUGFeRD Beratung und Implementierung
      • Was ist das ZUGFeRD-Format?
      • Wie unterstützt Aloaha das ZUGFeRD-Format?
      • Aloaha ZUGFeRD Homepage
      • ZUGFeRD Leser
  • Aloaha Security Solutions
    • CodeB TOTP SMS
      • Unlock Premium Security for Free with CodeB!
      • WordPress Security: Passwordless Authentication with CodeB
      • Passwordless Authentication Meets Nextcloud
      • CodeB SMS now with TOTP Authenticator
      • Digital Signatures Now Part of “CodeB TOTP SMS”
      • Your Phone, Your Identity: Unveiling CodeB’s Next-Gen Authentication Solution
    • Aloaha Timestamping Server (TSS/TSA)
    • Aloaha Reverse SSL Security Proxy
    • Aloaha USB Endpoint Security
    • Windows Credential Provider V2
      • Windows Authentication with Authenticator App (TOTP)
    • Aloaha Smart Login
      • Aloaha Smart Logon FAQ
    • Aloaha PDF Crypter
    • Aloaha Crypt Disk
    • Aloaha Crypt, Sign and ZIP
      • Aloaha PKCS #7 Crypter
      • Certificate encrypted ZIP
      • Aloaha CMS Signer
    • Aloaha Certificate Generator
  • Smart Card Applications
    • CodeB Demo Server
    • CodeB Authenticator for Android
      • Qualifiziert Signieren mit dem Heilberufsausweis (HBA)
      • How do I sign PDF with Maltese ID Card
      • Sign any Document
      • Sign Testdocument
    • Windows Credential Provider V2
      • Comprehensive Guide to Multi-Faceted Logon Methods
      • Unlock Premium Security for Free with CodeB!
      • Windows Authentication with Authenticator App (TOTP)
    • Aloaha Smartlogin
      • Windows Authentication with Authenticator App (TOTP)
        • Unlock Premium Security for Free with CodeB!
      • Logon via KeyCards such as NFC/Mifare/Desfire
      • Smartcard based Logon with any Certificate
      • Logon via USB Memory Stick
      • Aloaha Remote Desktop (RDP) Manager and Launcher
      • Aloaha Smart Logon FAQ
      • Smart Login Posts
  • PDF Applications
    • Aloaha PDF Suite
      • Aloaha PDF Suite FAQ
      • Aloaha PDF Suite FREE
      • Aloaha PDF Suite LIGHT
        • Render PDF on Stationary / Letterhead
        • Aloaha PDF Automation Commands (Desktop Mode)
        • PDF Automailer
        • Features (light)
      • Aloaha PDF Suite PRO
        • Aloaha PDF Automation Commands (Desktop Mode)
        • PDF Automailer
        • Render PDF on Stationary / Letterhead
        • Features
        • Aloaha Timestamping Server
        • Aloaha Certificate Generator
      • Aloaha PDF Suite SERVER
        • PDF Autoprint Folder
        • Signature Hotfolder
        • Aloaha Image 2 PDF Hotfolder
      • PDF Suite SDK
        • PAdES – PDF Advanced Electronic Signatures
    • Aloaha PDF Signator
      • Free CodeB Signature Server
      • CodeB Signator for Android
      • Easy Signing with CodeB Mobile Document Signer
      • Mobile Identities / eIDAS Token and Aloaha eForms Server
      • Elevating Digital Document Signing: Introducing Integrated PDF Signator in CodeB Apps
      • Digital Signatures Now Part of “CodeB TOTP SMS”
      • Welcoming eIDAS – eIDAS comes into effect across 28 EU Member States today
      • PAdES Digital Signatures with included Aloaha PDF Editor
      • PDF-Dokumente digital signieren
      • Programmatically fill PDF Forms and digitally sign them
      • PDF Formulare ausfuellen und digital signieren
      • Aloaha Certificate Generator
      • Aloaha Timestamping Server
    • Aloaha PDF batch Signer
      • Aloaha PDF Batch Signer settings
    • Aloaha PDF Editor and digital Signator
      • Free CodeB Signature Server
      • Elevating Digital Document Signing: Introducing Integrated PDF Signator in CodeB Apps
      • Render text on signature image
      • Aloaha PDF Reader to Safeguard your PDF Security
      • Aloaha PDF Viewer Cloud integration
      • Aloaha PDF Form Workflow
      • PAdES Digital Signatures
        • Welcoming eIDAS – eIDAS comes into effect across 28 EU Member States today
    • Aloaha PDF Crypter
    • Aloaha PDF Formsaver
      • Programmatically fill and sign PDF Forms
      • Online PDF Form Filler
      • Aloaha PDF Form Workflow
    • ZUGFeRD
      • Aloaha ZUGFeRD Invoice
      • Was ist das ZUGFeRD-Format?
      • Wie unterstützt Aloaha das ZUGFeRD-Format?
    • PDF Command Line Tools
      • Convert DOCX directly to PDF/A
      • Autoprint DOCX
  • Server Solutions
    • CodeB Identity Server
    • Free CodeB Signature Server
    • CodeB Nextcloud Demo Server
    • CodeB Signature Server
      • Vertrauen in digitale Transaktionen mit dem CodeB Signatur Server
    • Passwordless Identity Broker
      • CodeB Signator
        • Mobile Identities / eIDAS Token and Aloaha eForms Server
        • Elevating Digital Document Signing: Introducing Integrated PDF Signator in CodeB Apps
      • CodeB Authenticator
      • CodeB SMS
    • Aloaha eForms
    • Online PDF Form Designer
      • Aloaha ZUGFeRD Invoice
      • eGovernment / eForms and #Blockchain
    • Aloaha PDF Form Server
      • Elevating Digital Document Signing: Introducing Integrated PDF Signator in CodeB Apps
      • Mobile Identities / eIDAS Token and Aloaha eForms Server
      • Online PDF Form Filler
      • Aloaha PDF Form Workflow
    • Aloaha Timestamping Server (TSS/TSA)
  • Impressum/Contact
    • Identity and Access Homepage
    • Software maintenance agreement
    • Terms and Conditions
    • Refund Policy
    • Aloaha Privacy Policy
    • News
Home / Smartlogon / Embracing a Passwordless Future at CodeB

Embracing a Passwordless Future at CodeB

2nd February 2023
 |  No Comments

For the past decade, we’ve observed World Password Day, an annual reminder for individuals to update their passwords. This tradition underscores a fundamental flaw of passwords: for them to remain effective, they must be changed frequently. However, people often struggle to remember these constantly changing passwords, leading to insecure practices such as pattern-based changes or even storing passwords in plain text files on their desktops.

Over the years, the landscape of login security has become increasingly complex. Security threats have evolved, with phishing attacks becoming more prevalent and sophisticated. Simultaneously, password rules have become more stringent, with fluctuating requirements around special characters, capitalization, and length. Understandably, many users report feeling frustrated by the complicated rules around passwords and overwhelmed by the sheer number of usernames and passwords they have to manage.

Despite significant advancements in authentication technologies, we find ourselves in 2023 still grappling with passwords. Given their security and usability limitations, why do passwords persist? What could a future without them look like?

At CodeB, we’ve observed the stubborn resilience of passwords, even as more of our workforce users adopt high-assurance and phishing-resistant solutions. Our customers have offered a few explanations:

  • Passwords represent an accepted risk. Despite their flaws, passwords are a known entity. IT teams understand how to implement and manage them, and end users know how to create, recover, and reset them. The familiarity of passwords can outweigh their risks for businesses aiming to meet their customers and users where they are.
  • Alternatives may seem unclear. Organizations might be unfamiliar with other approaches to authentication. The concept of going passwordless might seem more like a futuristic ideal than a viable option today. They may also lack the knowledge on how to embark on a new path.
  • Transformation is challenging. Change always involves some friction. Transitioning from a password-based authentication approach to something else would require time, engineering effort, and an evolution of user behavior. For some decision-makers, the resistance to change is too strong.

Despite these considerations, we at CodeB decided to embark on our own passwordless journey more than three years ago. While we’re not 100% there yet, we’ve certainly learned some valuable lessons along the way.

Phishing resistance has business value. Passwords, with their susceptibility to phishing attacks, present a constant security challenge. This can be costly for businesses like ours, which have to spend significant time and money just discovering and handling these phishing threats. In contrast, passwordless flows are inherently phishing resistant, because by definition there are no passwords for bad actors to intercept. Businesses can reclaim all the time and money they might otherwise have to spend mitigating phishing attacks. In other words, going passwordless can deliver real business value.

The conventional wisdom that more secure authentication comes at the expense of the user experience is a false dichotomy. By going passwordless, we’re providing a better experience for our CodeB employees and customers. By removing passwords from the authentication process, we can save users time, reduce frustration, and lower login failure rates.

Based on our own data and experience, we’ve observed that when people use the CodeB SSI, CodeB Smartlogin/Credential Provider, and our CodeB Authenticator — our phishing-resistant passwordless authenticator — to log in without a password, they can do it in less than a third of the time it would take with a password. Password-based logins at work also fail approximately 10% of the time, compared to just 1% for logins with CodeB — a significant improvement!

We’ve made great progress on our journey to passwordless at CodeB, a journey that involves updating all of the apps and services we use to be consistent with phishing-resistant policies. These policies require end users to use at least one phishing-resistant factor, such as CodeB Authenticator or CodeB Credential Provider, to log in to their resources. We keep close track of our progress but there is always space to improve.

One major step we’ve taken to improve is to align with our Product and Engineering teams and our Customers to highlight any current platform gaps that might hinder us from getting to 100% passwordless, phishing-resistant login flows.

Ultimately, we aim to enable both our CodeB workforce and our customers to go completely passwordless. We’re doing that with new products and solutions like CodeB Authenticator. The platform improvements we’re making on our own journey to passwordless should make the path forward much easier for our customers to navigate.

Internally, I’ve received overwhelmingly positive feedback from our employees about our passwordless approach. They find it far more convenient, for example, to use their mobile CodeB Authenticator App to access their apps and accounts, particularly when traveling.

Despite the growing number of innovations like these, most Identity and Access Management solutions today are still at least partially dependent on passwords. Embracing passwordless will get easier as platform vendors and device manufacturers align on standardized flows for recovery, issuance, and non-proliferation. And consumer-centric technologies like OpenID Connect (OIDC) will help further democratize the use of passwordless credentials, much like how Touch ID and Windows Hello democratized biometric authentication.

As IT leaders, we can’t be stagnant or fearful of a world without passwords. Instead, we must move on from the past, adopt new practices, and evolve. By doing so, our organizations can start enjoying the benefits of passwordless systems: better user experiences, higher productivity, lower support costs, and of course, enhanced security.

Source: https://blog.codeb.io/embracing-a-passwordless-future-at-codeb/

Tweet
Categories: Smart Login, Smartlogin, Smartlogon
 |  Tags: aloaha, auth0, authenticator, CodeB, connect, Credential Provider, OAuth, OAuth2, oidc, openid, passwordless, Smartlogin, Smartlogon, Winlogin

Post navigation

← Multi-Factor Authentication for Windows Login & RDP
TOTP 2FA Anmeldung für Windows: Eine technische Perspektive →

Recent Posts

  • Spannende Neuigkeiten von Aloaha!
  • Mandatory e-invoicing for companies starts from 2025
  • E-Rechnungspflicht für Firmen kommt ab 2025​
  • Vertrauen in digitale Transaktionen mit dem CodeB Signatur Server
  • Exciting News: CodeB Mobile Signer is Now CodeB NFC Sign!
  • How to Sign PDFs with Your National Identity Card: A Complete Guide
  • Easy Signing with CodeB Mobile Document Signer
  • Mobile Identities / eIDAS Token and Aloaha eForms Server
  • Die Elektronische Gesundheitskarte: Ihr digitaler Schlüssel nicht nur für das deutsche Gesundheitssystem
  • Erweiterte digitale Signatur mit der Gesundheitskarte (eGK)

Categories

  • Aloaha
    • Azure
    • News
    • ZUGFeRD
  • Aloaha IoT
    • config
    • SMTP
  • Aloaha PDF Form Server
  • Aloaha PDF Suite
    • embedded commands
      • epara
      • exec
  • APIs
    • add_bookmark
    • DOC2PDFA
    • export_page
    • export2FAX
    • export2TIFF
    • get_default_printer
    • get_page_text
    • get_pagesize_s
    • img2pdf
    • is_pdf_signed
    • Licensed
    • load_pdf_to_mem
    • merge_A_and_B
    • print_pdf
    • ReaderExists
    • ReaderID
    • ReaderName
    • save_pdf_to_file
    • SetupPrinter
    • Sign_PDF
    • sign_pdf_file
  • Blockchain
  • CAMARA
  • CodeB Authenticator
  • CodeB TOTP SMS
  • DQR (Do your Qualified Research)
  • FAQ
  • PDF
    • Batch PDF Signer
    • Features
      • Digital Signature
    • Features (light)
    • PAdES
    • PDF Forms
    • PDF Reader
    • PDF Signator
    • PDF Stationary
    • SDK
  • Smart Cards
    • Smart Login
  • Smartlogin
    • Bluetooth
  • Smartlogon
  • Technology
    • Blockchain
    • CAdES
    • Digital Certificate
    • PKCS #7
    • RFC 3161
    • ZIP compression

Recent Posts

  • Spannende Neuigkeiten von Aloaha!
  • Mandatory e-invoicing for companies starts from 2025
  • E-Rechnungspflicht für Firmen kommt ab 2025​
  • Vertrauen in digitale Transaktionen mit dem CodeB Signatur Server
  • Exciting News: CodeB Mobile Signer is Now CodeB NFC Sign!
  • How to Sign PDFs with Your National Identity Card: A Complete Guide
  • Easy Signing with CodeB Mobile Document Signer
  • Mobile Identities / eIDAS Token and Aloaha eForms Server
  • Die Elektronische Gesundheitskarte: Ihr digitaler Schlüssel nicht nur für das deutsche Gesundheitssystem
  • Erweiterte digitale Signatur mit der Gesundheitskarte (eGK)

Tags

2FA aloaha Android Anmeldung app authentication authenticator azure B2C blockchain Card CodeB connect credential digital eforms egk gesundheitskarte hba heilberufsausweis letterhead login logon Malta Mobile NFC oidc openid PAdES passwordless PDF PDF/A PDF SDK provider QES rfc 3161 sdk signature sign_pdf_file smart Smartlogin Smartlogon SMS TOTP ZUGFeRD

Meta

  • Log in
  • Entries feed
  • Comments feed
  • WordPress.org

Aloaha Limited

Helgoland
45, Triq Gio Felice Inglott
Phone: +49 541 3859 4554
Fax: +49 541 3859 4554

Email: info@aloaha.com
Website: www.aloaha.com

  • Aloaha Smart Login
  • Aloaha PDF Suite
  • Aloaha PDF Crypter
  • Aloaha PDF Signator
  • ZUGFeRD Beratung und Implementierung
  • CodeB TOTP SMS