Multifactor authentication can bear weaknesses that render its efficacy moot. A common response and answer to the most problematic forms of MFA, though the details are limited at best, is phishing-resistant MFA.

The qualifier, phishing resistant, is broadly defined as modes of authentication that rely on cryptographic techniques, such as an asymmetric pair of private and public keys, the Web Authentication API (WebAuthn) specification, biometrics or the FIDO2 standard. 


More

CNET: A physical key is the secret to Google employees’ online security

CNET explains that the FIDO Security Key is the secret to Google’s employees’ online security.

Read More →

Krebs on Security: Google: Security Keys Neutralized Employee Phishing

Well-known cybersecurity expert and influencer Brian Krebs breaks down how FIDO Authentication using Security Keys…

Read More →

Dark Reading: Beyond Passwords: Why Your Company Should Rethink Authentication

This article highlights the work the FIDO Alliance is doing to develop ubiquitous, technology-agnostic security…

Read More →