According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

International Security Journal: Passkeys set to become leading authentication method by 2027, HYPR reports

HYPR, an Identity Assurance Company, has released the fifth edition of its ‘State of Passwordless…

Read More →

Security Info Watch: iProov launches facial biometric MFA support targeting workforce identity theft

This device-independent, FIDO Alliance-certified biometric authentication solution helps organizations mitigate the risk of one of…

Read More →

Forbes: Microsoft Warns 1 Billion Windows Users—Do Not Use Password

All change for Microsoft. The company has suddenly confirmed a major update “for over 1…

Read More →