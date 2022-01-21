It's not hard to understand why passwordless authentication continues to gain traction. Passwords are a major security vulnerability and a leading cause of data breaches. In fact, Verizon's "2021 Data Breach Investigations Report" found 89% of web application breaches involved credential abuse.

Completely eliminating passwords isn't feasible yet, but there are passwordless authentication methods companies can deploy today that can help reduce reliance on risky passwords and thus reduce the use of credentials as an attack vector.

Current passwordless authentication options Companies can consider the following available passwordless authentication methods: Email-based. Users receive a temporary one-time passcode via email to log in to their account. A URL with the embedded code or token can be included to speed up the process and make it more convenient for users.

WebAuthn-based. The WebAuthn API relies on something users own instead of what they know for authentication. Using public key cryptography, a trusted device -- such as a smartphone, laptop or security key -- serves as the authentication factor.

Biometrics-based. Biometric authentication relies on users' physical or behavioral characteristics to verify identity. Devices with advanced cameras, high-quality microphones or fingerprint scanners determine users are who they say they are.

Biometric authentication relies on users' physical or behavioral characteristics to verify identity. Devices with advanced cameras, high-quality microphones or fingerprint scanners determine users are who they say they are. A combination of methods. Use WebAuthn and biometrics, for example, to enable a layered authentication approach. Biometric scans authenticate users to a device, and then WebAuthn token generation provides further authentication.