2015 is likely to be the first year when the password starts to be phased out in favour of a number of different multi-factor options. Next year may well be the first year of multi-factor by default," Digital Shadows, a cyber threat intelligence company, told CNBC. "The mechanisms for password recovery are flawed," John added. "The traditional method of password recovery is asking questions that only you, the real owner, should know. Unfortunately, answers to these questions often can be deduced based on information that can easily be found online -- especially given people's proclivity for "over-sharing" on social media sites.