According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

MSSP Alert: authID Integrates with Ping to Spread Passwordless Authentication

authID’s decision this month to integrate its biometric identity verification technology with Ping Identity’s PingOne…

Read More →

Ars Technica: Coming to Apple OSes: A seamless, secure way to import and export passkeys

Apple OSes will soon transfer passkeys seamlessly and securely across platforms. Apple this week provided…

Read More →

Passwordless Authentication and the Rise of Passkeys: Expert Insights Podcast with Andrew Shikiar

Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, joins us to discuss the…

Read More →