HomeCyber BalkansBastionZero unveils SplitCert for passwordless authentication and access

BastionZero unveils SplitCert for passwordless authentication and access

Published on

spot_img

BastionZero, a company that specializes in zero-trust database security solutions has launched SplitCert, a new platform that provides password-free authentication access to databases. The platform uses Mutual TLS (mTLS) and cryptographic multi-party computation (MPC) to provide certificate-based authentication for popular, self-hosted Postgres and MongoDB databases.

SplitCert generates one-time mTLS client certificates from two key “shards” stored in two independent locations. Cryptographic MPC is then used to create one-time mTLS client certificates from the two independently stored shards. By storing the shards in separate locations, SplitCert eliminates the single point of compromise associated with the storage and maintenance of database passwords.

The platform is invisible to end-users and supports database access via popular existing database clients and workflows. Additionally, BastionZero’s new desktop app includes passwordless access support for Google Cloud Platform (GCP) cloud SQL and Amazon Web Services (AWS) RDS, along with password-free support for Microsoft Windows servers with Remote Desktop Protocol (RDP).

Passwords are a major security headache for businesses with weak and reused passwords often prevalent among employees who struggle to maintain and remember unique logins across vast numbers of accounts. Passwords are involved in 81% of all hacking breaches, and inherent usability problems make passwords difficult for users to manage safely.

With SplitCert, BastionZero leverages modern cryptographic techniques to ensure that businesses do not need to trust anyone with their database credentials, not even the vendor itself. According to Sharon Goldberg, PhD, CEO and co-founder of BastionZero, SplitCert eliminates single points of compromise associated with the storage and maintenance of database passwords, making it a healthy alternative to traditional passwords.

Passkeys are a kind of passwordless authentication that is seeing increasing attention and adoption by organizations and the technology sector seeking more secure, reliable sign-in alternatives. According to a report by CSO, Google is rolling out support for passkeys across Google accounts on all major platforms. Last month, the FIDO Alliance also released new user experience guidelines to help accelerate the deployment and adoption of passkeys.

The launch of SplitCert by BastionZero is a move in the right direction for businesses hoping to secure their database access without relying on passwords. In an era where cybersecurity remains a serious concern for businesses around the world, BastionZero’s platform could help improve data protection while eliminating multiple points of compromise associated with insecure passwords.

Source link

Latest articles

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...

Fortinet Warns of Active Exploitation of FortiOS SSL VPN 2FA Bypass Vulnerability

 Fortinet on Wednesday said it observed "recent abuse" of a five-year-old security flaw in FortiOS...

More like this

MuddyWater Launches RustyWater RAT via Spear-Phishing Across Middle East Sectors

 The Iranian threat actor known as MuddyWater has been attributed to a spear-phishing campaign targeting...

Meta denies viral claims about data breach affecting 17.5 million Instagram users, but change your password anyway

 Millions of Instagram users panicked over sudden password reset emails and claims that...

E-commerce platform breach exposes nearly 34 million customers’ data

 South Korea's largest online retailer, Coupang, has apologised for a massive data breach...