According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector.


More

Biometric Update: To build trust in biometrics, Vietnam banks should adopt FIDO passkeys: report

VinCSS has released an industry first report on the authentication experience in apps for Vietnamese banks,…

Read More →

Back End News: HID offers passwordless authentication to support BSP compliance

HID, a company that provides secure identity solutions, announced the availability of its updated FIDO-certified…

Read More →

Security Boulevard: Beyond Passwords: A Guide to Choosing the Right Passkey

For many market analysts, cybersecurity agencies and authentication experts, passkeys, based on FIDO2 standard protocol,…

Read More →