According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

Dark Reading: NIST Digital Identity Guidelines Evolve with Threat Landscape

In a bid to improve overall security of the identity ecosystem, the National Institute of…

Read More →

Research Snipers: Microsoft Authenticator Deletes All Stored Passwords, Pushes Users Toward Passkeys

As announced, Microsoft today deletes all stored passwords from his authenticator app. Users have to…

Read More →

Security.World: HID Unveils Next-Generation FIDO Hardware And Centralized Management At Scale

HID, a worldwide leader in trusted identity and access management solutions, has announced a new line of FIDO-certified credentials—now powered…

Read More →


123286 Next