According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

The Green Sheet: Fierce authentication for an omnichannel threatscape

The ability to transact across all channels has opened opportunities and threats, expanding retail and…

Read More →

Transaction Trends (US): ETA Expert Insights: FIDO Designs Faster Deployments

FIDO was founded in 2012 by PayPal, Lenovo, and Nok Labs. They are working to…

Read More →

SDxCentral (US): FIDO Pushes Password Replacement as MFA Bypass Attacks to Surge in 2023

The FIDO Alliance expects to see more high-profile cyberattacks targeting cloud service providers that bypass…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.