According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

9to5Google: Samsung Galaxy S10 tidbits: Bixby button remapping, RIP notification LED, colors, more

9to5Google highlights that the new Samsung Galaxy S10 and S10+ phones feature FIDO Certified fingerprint…

Read More →

TechTarget: Google’s Mark Risher: New types of 2FA are ‘game changers’

Mark Risher, head of account security at Google, speaks to TechTarget about the benefits of…

Read More →

Google Blog: Beyond passwords: a roadmap for enhanced user security

FIDO Security Keys are easier to use and more secure than other forms of 2FA,…

Read More →