Initial release of SplitCert supports password-less, certificate-based access to popular databases Postgres and MongoDB. Credit: Gerd Altmann BastionZero has announced the release of SplitCert to provide password-free authentication access to databases. It uses Mutual TLS (mTLS) and cryptographic multi-party computation (MPC) to provide certificate-based authentication for popular, self-hosted Postgres and MongoDB databases, according to the vendor. Other new BastionZero platform features include passwordless access support for GCP cloud SQL and AWS RDS via a new desktop app, along with password-free support for Microsoft Windows servers with Remote Desktop Protocol (RDP), BastionZero said.Passwords can be a major security headache for businesses, with weak and reused passwords often rife among employees who struggle to maintain and remember unique logins across vast numbers of accounts. Passwords are a principal weakness involved in 81% of all hacking breaches, while inherent useability problems make passwords difficult for users to manage safely.SplitCert generates mTLS certificates from two “shards” stored in two locationsSplitCert generates one-time mTLS client certificates from two key “shards” that are stored in two independent locations, BastionZero said in a press release. Cryptographic MPC is then used to generate one-time mTLS client certificates from the two independently stored shards, it added. By storing the shards in independent locations, SplitCert eliminates the single point of compromise associated with the storage and maintenance of database passwords. It is invisible to end users and supports database access via popular existing database clients and workflows, BastionZero said. “With SplitCert, we’ve leveraged modern cryptographic techniques to ensure that our customers don’t need to trust anyone with their database credentials, not even us,” commented Sharon Goldberg, PhD, CEO and co-founder, BastionZero. In addition to the SplitCert release, BastionZero’s new desktop app creates a simple point-and-click path for users to access Windows, Linux, database, and Kubernetes targets, the firm said. The release includes a feature that supports locking down Windows infrastructure access with RDP, it added.Support for password-less authentication continues to growSupport for password-less authentication and access has been growing in recent years as organizations and the technology sector seek more secure, reliable sign-in alternatives that help limit the risks of password reliance. Passkeys are a kind of passwordless authentication seeing increasing focus and adoption, with Google now rolling out support for passkeys across Google Accounts on all major platforms. Last month, the FIDO Alliance released new user experience guidelines to help accelerate the deployment and adoption of passkeys. Related content news CISA, FBI urge developers to patch path traversal bugs before shipping The advisory highlights how developers can follow best practices to fix these vulnerabilities during production. By Shweta Sharma May 03, 2024 3 mins Vulnerabilities news Microsoft continues to add, shuffle security execs in the wake of security incidents The company has appointed new product security chiefs as well as a customer-facing CISO as it continues to respond to high-profile attacks on its products and own network. By Elizabeth Montalbano May 03, 2024 4 mins CSO and CISO feature Malware explained: How to prevent, detect and recover from it What are the types of malware? How does malware spread? How do you know if you’re infected? We've got answers. By Josh Fruhlinger May 03, 2024 18 mins Ransomware Phishing Malware brandpost Sponsored by Cyber NewsWire LayerX Security Raises $26M for its Browser Security Platform, Enabling Employees to Work Securely from Any Browser, Anywhere Early adoption by Fortune 100 companies worldwide, LayerX already secures more users than any other browser security solution and enables unmatched security, performance and experience By Cyber NewsWire May 02, 2024 4 mins Cyberattacks Security PODCASTS VIDEOS RESOURCES EVENTS SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe