Multifactor authentication can bear weaknesses that render its efficacy moot. A common response and answer to the most problematic forms of MFA, though the details are limited at best, is phishing-resistant MFA.

The qualifier, phishing resistant, is broadly defined as modes of authentication that rely on cryptographic techniques, such as an asymmetric pair of private and public keys, the Web Authentication API (WebAuthn) specification, biometrics or the FIDO2 standard. 


More

Krebs on Security: Google: Security Keys Neutralized Employee Phishing

Well-known cybersecurity expert and influencer Brian Krebs breaks down how FIDO Authentication using Security Keys…

Read More →

Dark Reading: Beyond Passwords: Why Your Company Should Rethink Authentication

This article highlights the work the FIDO Alliance is doing to develop ubiquitous, technology-agnostic security…

Read More →

Planet Biometrics: Timehop breach ‘offers a teachable moment’ says FIDO Alliance

FIDO Alliance Executive Director Brett McDowell shares insights with Planet Biometrics on why organizations shouldn’t…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.