According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

Expert Insights Podcast: #64 – Passwordless Authentication and the Rise of Passkeys

Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, joins us to discuss the…

Read More →

Ars Technica: Coming to Apple OSes: A seamless, secure way to import and export passkeys

Apple this week provided a glimpse into a feature that solves one of the biggest…

Read More →

MobileIDWorld: Apple Introduces Cross-Platform Passkey Import/Export Features Across Operating Systems

Apple has announced significant enhancements to its operating systems that will implement secure import and…

Read More →