According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

HID Global Blog: Understanding FIDO Alliance: Backbone of Passwordless Authentication

In today’s digital-first world, passwords are no longer enough. As phishing attacks and credential theft…

Read More →

Corbado: Passkeys Japan: An Overview

In 2025, Japan accelerated passkey adoption in response to evolving security challenges. Following a rise in unauthorized…

Read More →

Hackster.io: LionKey Offers an Open Source Take on FIDO2-Compliant Two-Factor and Passwordless Authentication

Engineer and maker Aleksei Karavaev has designed a compact USB dongle specifically to host the…

Read More →


123306 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.