- Tecnoacquisti.com
- PrestaShop Blog and Ecommerce Tutorial

Among the most exciting future challenges that the IT sector will face, a special mention certainly goes to the overcoming of passwords and captchas. Just think that recently, a well-established IT multinational like Microsoft has tried with Windows 11 to bypass the use of passwords to allow users to authenticate. As things stand, the main obstacle is that users are daily required to perform numerous logins: between different email accounts, use of social networks, access to bank accounts or other financial tools, online services, and so on, there are numerous passwords to remember. The problem is that memory is fragile, and people tend to choose relatively simple passwords, and consequently, not very secure ones. At other times, however, a single password is used to access multiple services, in order to avoid wasting too much time on each login.
Two-factor authentication
Two-factor authentication, unfortunately, has not had the desired effect: theoretically, it was supposed to increase the overall level of security, but in practice, it has led to various difficulties during the login process. The result? Longer times to access the services in question. For this reason, in the coming years, access to the relevant services will need to be even simpler: passwordless systems will, in fact, need to make access even more secure.
Overcoming the password: between past failed attempts and future challenges.
The intention to move beyond the concept of passwords has been evident for several years, as there have been multiple attempts in this direction: such as sending emails with authentication links, which proved to be unreliable, as many emails are effectively blocked by providers and do not reach their destination. This has contributed to delaying the advent of a passwordless system, which, however, should not rely on external services for its operation. For the protection of the privacy of those browsing the web, at the moment, resorting to a strong password, made up of characters (both uppercase and lowercase), numbers, and special symbols represents the wisest choice, even though the main drawback lies in the fact that it is difficult to remember. However, it is possible to go beyond this. Passwordless solutions, which are not exactly recent technologies, provide a particularly fitting example in this regard.
Passwordless authentication: here’s a brief explanation of how it works.
As for the logic behind passwordless authentication, it is important to start from the assumption that there are two key elements for the successful outcome of the process: on one hand, there is a public component, focused on systems that allow access to the service where one wants to authenticate. The password in this case is provided during registration, usually along with a username; on the other hand, there is the private element, where a physical device that is delivered to the user is strictly required to complete the authentication process.
A classic example is that of a hardware token, capable of generating temporary codes, or the fingerprint reader of the user. The same applies to voice recognition or retina scanning via smartphone. The identification of the user is, in fact, carried out by taking into account unique traits. In the coming years, the user will be able to authenticate by entering the public component within the web page of the service they wish to access. Only afterwards will they be able to complete the operations by providing the private component to the remote service. A classic example will revolve around the use of the smartphone, to which a notification message will be sent with a confirmation request, necessary for authentication. Similarly, another example will be the use of specific mobile apps to generate a temporary code to be entered on the relevant web page.
What are the real advantages of a passwordless system?
Opting for a passwordless system means being able to take advantage of various benefits. First of all, the access credentials of the various users of a service do not end up in the hands of malicious actors, in the event of possible system breaches.
Another positive aspect for the individual concerned is that they are not required to remember passwords. Organizations also benefit significantly when they decide to adopt a passwordless system: the problem of theft and loss of sensitive data is drastically reduced. The workload on this issue tends to decrease significantly. In this way, productivity increases.
The Microsoft case
As already mentioned, even a multinational like Microsoft is continuing to invest more and more in the passwordless world. The underlying intent is to provide users with greater opportunities to log in, even with just a smartphone, a device that, among other things, allows for personal identification.
With Windows 10, the Redmond giant began integrating new technologies to support password solutions, providing users with a range of apps that they simply had to install on their devices. In this way, all the opportunities offered by TMP, a valid platform capable of effectively managing encryption to protect sensitive information and data, were fully utilized. Therefore, thanks to passwordless technologies, access proves to be more secure and simplified. In the case of businesses, there are reliable partners capable of providing particularly efficient themed software.
What to say regarding CAPTCHAs?
A very important aspect is closely related to the universe of CAPTCHA, that is, those mechanisms that are essential to verify that the person accessing a given service is not a bot, but a real person. Based on solving a quiz, recognizing photos, or entering numbers, CAPTCHA is increasingly in use today. However, many of those who browse online consider them a real nuisance, as they waste time in accessing a service.
How to bypass CAPTCHAs? Cloudflare offers a valid solution.
Industry experts highlight how solving CAPTCHAs is not easy at all, to the point that to bypass them, one would need to spend an amount of time equivalent to 500 years every day. Naturally, this takes into account the totality of users who encounter them.
To bypass the problem, Cloudflare had a brilliant idea: to replace them with FIDO2 keys, essential for allowing individuals to not be bots. The great thing is that the privacy of these users is protected, as they are not required to reveal their identity. Inside the FIDO2 key is a special security module, containing a unique secret, signed by the device manufacturer.
The purpose of this module is to prove that a specific user is the holder of that particular secret, without revealing it. As an alternative to CAPTCHAs, the system developed by Cloudflare will still take some time to be brought to market. However, the foundations for bypassing CAPTCHAs are beginning to take solid root. In a few years, the fruits of this work will be harvested.
Author: Loris Modena

SENIOR DEVELOPER
Per Ind Loris Modena, owner of Arte e Informatica, started working in the IT sector in 1989 as a system administrator responsible for the maintenance and installation of computer systems. He began programming for the web in 1997, focusing on CGI programming in PERL and later transitioning to programming in PHP and JavaScript. During this time, he became familiar with the Open Source world and the management of Linux servers.