According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

ZDNET: Facebook’s new passkey support could soon let you ditch your password forever

For all of us who hate passwords, passkeys represent a simpler and safer way of authenticating online…

Read More →

Expert Insights Podcast: #64 – Passwordless Authentication and the Rise of Passkeys

Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, joins us to discuss the…

Read More →

Ars Technica: Coming to Apple OSes: A seamless, secure way to import and export passkeys

Apple this week provided a glimpse into a feature that solves one of the biggest…

Read More →