Multifactor authentication can bear weaknesses that render its efficacy moot. A common response and answer to the most problematic forms of MFA, though the details are limited at best, is phishing-resistant MFA.

The qualifier, phishing resistant, is broadly defined as modes of authentication that rely on cryptographic techniques, such as an asymmetric pair of private and public keys, the Web Authentication API (WebAuthn) specification, biometrics or the FIDO2 standard. 


More

Biometric Update: It’s World Passkey Day, actually: trust, adoption grows for FIDO credential

World Password Day is no longer. The annual day to promote secure password practices has…

Read More →

PC Mag: RIP Passwords: Microsoft Moves to Passkeys as the Default on New Accounts

Anyone setting up a new Microsoft account will soon find they’re encouraged to use a passkey during…

Read More →

The Verge: Microsoft goes passwordless by default on new accounts

After supporting passwordless Windows logins for years and even allowing users to delete passwords from their accounts, Microsoft…

Read More →