Every business needs a secure way to collect, manage, and authenticate passwords. Unfortunately, no method is foolproof. Storing passwords in the browser and sending one-time access codes by SMS or authenticator apps can be bypassed by phishing. Password management products are more secure, but they have vulnerabilities as shown by the recent LastPass breach that exposed an encrypted backup of a database of saved passwords. For organizations with high security requirements, that leaves hardware-based login options such as FIDO devices.


More

Krebs on Security: Google: Security Keys Neutralized Employee Phishing

Well-known cybersecurity expert and influencer Brian Krebs breaks down how FIDO Authentication using Security Keys…

Read More →

Dark Reading: Beyond Passwords: Why Your Company Should Rethink Authentication

This article highlights the work the FIDO Alliance is doing to develop ubiquitous, technology-agnostic security…

Read More →

Planet Biometrics: Timehop breach ‘offers a teachable moment’ says FIDO Alliance

FIDO Alliance Executive Director Brett McDowell shares insights with Planet Biometrics on why organizations shouldn’t…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.