According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

CNBC: Google wants to replace your password routine with a tiny device that plugs into your computer

The FIDO Security Key has helped to kill all successful account takeovers by phishing at…

Read More →

The Verge: Google announces its own security key for stronger logins

The Verge reports that Google has announced its new FIDO Certified Titan Security Key, providing…

Read More →

Fast Company: Google made its employees impervious to phishing using USB security keys

None of Google’s 85,000+ have fallen prey to phishing attacks on their work-related accounts since…

Read More →