Multifactor authentication can bear weaknesses that render its efficacy moot. A common response and answer to the most problematic forms of MFA, though the details are limited at best, is phishing-resistant MFA.

The qualifier, phishing resistant, is broadly defined as modes of authentication that rely on cryptographic techniques, such as an asymmetric pair of private and public keys, the Web Authentication API (WebAuthn) specification, biometrics or the FIDO2 standard. 


More

Biometric Update: NIST issues guidance to fit passkeys into digital identity recommendations

Andrew Shikiar, CEO of the FIDO Alliance, noted that the updated NIST guidance confirms passkeys’…

Read More →

TechCrunch: WhatsApp adds global support for passkeys on iOS

WhatsApp is launching passkey verification on iOS, eliminating the requirement for users to manage SMS…

Read More →

Tech Radar: Bitwarden now supports passkeys on iOS devices

Popular free password manager Bitwarden now supports passkeys on iOS devices. The news follows the…

Read More →