Why legacy authentication methods are failing today’s digital identity needs

In a world where online fraud is exploding, costing the industry over $10 trillion annually, new solutions are needed urgently. But, as online security requirements have increased, the additional complexity has been pushed onto the user. The result is a poor user experience without delivering a trusted identity.
The legacy authentication methods
We have all grown up with the high-friction (but low security), user-dependent model that dominates today’s online world – Email, Password + SMS OTP (One Time Password).
Consumers have grown tired of all the complexity and, at the same time, businesses urgently need a solution to the widespread fraud and spiraling costs. The current authentication approach was created in a desktop world with low fraud. That model has failed.
We now live in a mobile-first world where fraud has been industrialized. Cybercrime is soaring, users have had enough of the increasing hassle and complexity, and businesses can no longer afford the costs and resource demands of this inefficient model. It is about to get even worse as criminals adopt AI.
Email as an Identity Credential
Email is the foundation for online identity and has been around for 50 years. The email + password security paradigm was developed at a time where online workers were entirely office-based and where passwords were considered safe. Neither is true today, and enterprises not only need identities for employees, but for online customers as well.

As a digital credential, email is very weak. The only “attribute” it has is the “Inbox” – and authentication of access to the Inbox can only be proved by using a knowledge factor or easily shareable credential sent to that Inbox in an email. The information transmitted to the Inbox can be forwarded (for example, to a fraudster by a victim who has been tricked through social engineering).
Email accounts can themselves be subject to account takeover, and desktop malware may get access to the content of emails. Therein lies one of the two fundamental issues with using email as a credential for digital identity. It was not designed to be a strong identity and is vulnerable.
The second issue with email, as the world moves away from passwords to device-based possession or biometric factors, is that an email address has no direct linkage to a physical device (mobile phone or computer). Consequently it has to rely on knowledge factors for device binding (e.g., using an SMS OTP sent to a mobile device) which are phishable and deliver poor UX.
As businesses increasingly move to mobile first, a new security paradigm is needed. One that is frictionless, secure and mobile native.
Learn more about how mobile identity can address the problems with legacy authentication methods in our white paper.
