According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

RSA and the FIDO Alliance Champion the Enterprise Passkey Revolution

In this joint briefing, RSA Security’s Jim Taylor and the FIDO Alliance’s Andrew Shikiar detailed the global transition away from legacy…

Read More →

OpenAI Will Gate Its Most Capable Cyber Models Behind a Physical Security Key

Access to OpenAI’s most cyber-capable AI models will soon require something no phishing email can…

Read More →

Biometric Update: Microsoft and Google push passkeys deeper into workplace authentication

Microsoft and Google are pushing passkeys and hardware security keys deeper into workplace authentication, with…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.