Every business needs a secure way to collect, manage, and authenticate passwords. Unfortunately, no method is foolproof. Storing passwords in the browser and sending one-time access codes by SMS or authenticator apps can be bypassed by phishing. Password management products are more secure, but they have vulnerabilities as shown by the recent LastPass breach that exposed an encrypted backup of a database of saved passwords. For organizations with high security requirements, that leaves hardware-based login options such as FIDO devices.


More

CIO Insight: What New NIST Guidelines Mean for Passwords

FIDO Alliance Executive Director Brett McDowell breaks down the updated NIST guidance, looking at the…

Read More →

Wired: Google’s ‘Advanced Protection’ Locks Down Accounts Like Never Before

Wired reports that Google has rolled out its Advanced Protection service, where personal Google account…

Read More →

Wired: Google’s ‘Advanced Protection’ Locks Down Accounts Like Never Before

Wired reports that Google has rolled out its Advanced Protection service, where personal Google account…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.