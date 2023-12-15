Dashlane, a leading password manager maker, has announced a new feature that allows users to have a completely passwordless experience. With this update, new users will no longer have to set up and remember a master password when creating an account. Dashlane plans to extend the passwordless option to existing users by 2024.

According to Dashlane CTO Frederic Rivain, this move makes Dashlane the first credential manager to eliminate the master password as the foundation of their passwordless accounts. Instead, users can create an account and login without ever needing a master password. Rivain emphasizes that Dashlane’s passwordless approach differs from WebAuthn-based passkeys. While Dashlane supports passkeys which allow users to create, save, and sign into various websites, these passkeys are not used to encrypt the data in Dashlane’s app vault. The app’s data is decrypted locally on the user’s device for secure access.

Karen Walsh, CEO of Allegro Solutions, a cybersecurity consulting company, highlights the significance of Dashlane’s approach. She notes that Dashlane combines two strategies to mitigate identity and access risks. Firstly, by removing passwords and relying on biometrics, Dashlane combines the “something you own” and “something you are” factors of multifactor authentication. Additionally, Dashlane incorporates zero-knowledge encryption, ensuring that user data remains encrypted even if a data breach occurs. By blending these technologies, Dashlane aims to minimize risks to both itself and its customers.

However, Craig Harber, a security evangelist at Open Systems, advises caution. While Dashlane’s passwordless architecture is marketed as “phishing resistant,” Harber warns that it is not a foolproof solution against threat actors. He raises concerns about the advancements in AI-generated deepfakes, which may potentially bypass biometric authentication technologies. Despite this, Dashlane’s passwordless experience represents a significant step forward in improving security and convenience for its users.