Driven by AI tools, phishing scams are on the rise. Still, many do not use additional safety measures to protect their online accounts. A FIDO Alliance report published on Monday found that manually entering passwords without any additional authentication is the most common way people access their accounts.
The 2023 Online Authentication Barometer report also found that many people favor biometrics over other authentication methods, viewing it as the “most secure.” According to FIDO, it appears “consumers want to use biometrics more but don’t currently have the opportunity.”
Despite a preference for biometric authentication, password usage without two-factor authentication (2FA) remains dominant. Consumers enter passwords manually almost 1,280 times annually. And the shortcomings of this method are evident: 59% have stopped accessing an online service, and 43% abandoned a purchase in the past 60 days due to authentication hassles, marking a 15% increase compared to the previous year.
“This year’s Barometer data showed promising signs of shifting consumer attitudes and desire to use stronger authentication methods, with biometrics especially proving popular. That said, high password usage without 2FA worryingly reflects how little consumers are still being offered alternatives like biometrics, resulting in lingering usage,” Executive Director and CMO at FIDO Alliance Andrew Shikiar said in a press release.
The Rise of AI-Enabled Scams
The report highlighted a rise in sophisticated online scams, with 54% of users noting more suspicious messages and scams, mainly via email, social media, SMS, and fake phone calls or voicemails.
Buoyed by new AI tools specifically designed for cybercrime — like FraudGPT and WormGPT — criminals have upped the intricacy of these scams. These tools, coupled with deepfake voice and video techniques, have heightened the believability of social engineering attacks.
“Phishing is still by far the most used and effective cyberattack technique, which means passwords are vulnerable regardless of their complexity,” Shikiar said.
“With highly accessible generative AI tools now offering bad actors the ability to launch convincing and scalable attacks, it’s imperative consumers and service providers listen to consumers and start to look at non-phishable and frictionless solutions like passkeys and on-device biometrics more readily available, rather than iterating on ultimately flawed legacy authentication like passwords and OTPs,” he added.
The Future of Authentication
While passwords continue to dominate, biometric authentication stands out as the most popular choice for security and preference. Financial services observed biometrics (33%) marginally surpassing passwords (31%) for sign-ins.
Awareness and adoption of passkeys, a cutting-edge passwordless sign-in method, have also increased. Companies like Google, Apple, and PayPal have endorsed passkeys. From 2022 to now, consumer awareness about passkeys catapulted from 39% to 52%.
For improved safety online, we recommend shifting from the traditional and vulnerable password-only authentication to more secure, phishing-resistant, and user-friendly methods like biometrics and passkey.
For more news, follow us on X (Twitter), Threads, and Mastodon!
