A new study suggests that cloud professionals should reconsider their reliance on passwords to strengthen the security of their systems.
See also: Proton announces password manager Proton Pass

Recently, a survey by Beyond Identity showed that over 80% of people are confident in the security and effectiveness of passwords, with around 33% saying they are very confident.
Beyond Identity believes that reliance on passwords is misplaced, due to the security vulnerabilities that passwords have, their value as targets for malicious actors, and widespread frustrations with password requirements.
The company says a study found that bad password habits are frequently used by threat actors, with 80% of breaches occurring when credentials that have already been compromised are used.
Despite their confidence, the survey found that cloud professionals expressed concerns about maintaining password hygiene in systems . The frustration was due to having to remember too many passwords (60%), changing them frequently (52%), and choosing difficult and long strings (52%).
See also: Many employees use personal devices at work and store company passwords

A quarter of people use between 4-5 passwords a day, while a tenth use 10 or more. Around a third of organisations recommend changing passwords every three months, while less than a third recommend changing them monthly and 6% recommend changing them daily or weekly. And despite the effort, Beyond Identity claims that such practices result in “minimal security benefits”.
While using a password manager and creating better passwords can significantly improve security, the real problem with passwords is their vulnerability to phishing. More than a third of cloud professionals said they had received between one and three phishing emails. Additionally, 18% of professionals had received between four and six phishing emails, and nearly a quarter reported receiving seven or more.
Our concern is that 11% of people do not report receiving suspicious phishing emails and a fifth are unsure whether they have clicked on a malicious link in an email. A fifth said they knew of colleagues who had clicked, while a quarter said they had clicked themselves – some of whom did so regularly.
Most cloud companies (82%) use MFA for multi-factor authentication. The most popular method is using a mobile. More than 50% of people were fairly confident about MFA as a security measure.
See also: New MacStealer malware steals data and passwords from macOS systems
To avoid phishing, you can use systems that do not require passwords, such as credential-. To grant access to the user, their cryptographic key must be combined with the service's public key. The cryptographic key is stored on the user's device and no one, not even the user, has access to it.
