This paper is from the SANS Institute Reading Room site. Reposting is not permitted without express written permission. Passwords are DEAD! (Long live passwords?) In this modern world, there are several viable alternatives to passwords for authentication into computer systems with important functions or containing sensitive data. Passwords are ubiquitous. Removing passwords from all proprietary computer operating systems would be a slow, costly process. Passwords, if used appropriately, provide a low risk, cost effective, and familiar interface to authenticate into systems of low functional importance, or that don't contain sensitive data. The strength of passwords, or an altern... Copyright SANS Institut