According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

Venturebeat: Firefox 66 brings Web Authentication API support for Windows Hello

WebAuthn support for Windows Hello means that with the next Windows 10 update, users will…

Read More →

PC World: WebAuthn: What you need to know about the future of the passwordless Web

In this feature article, PC World answers common questions about Web Authentication – what is…

Read More →

VentureBeat: W3C approves WebAuthn as the web standard for password-free logins

VentureBeat reports that the World Wide Web Consortium (W3C) today declared that the Web Authentication…

Read More →