According to a PayPal notice of security incident dated January 18, attackers got unauthorized access to the accounts of thousands of users between December 6 and 8, 2022. The total number of accounts that were accessed by threat actors using a credential stuffing attack is reported as being 34,942. While accepting that PayPal is seemingly doing the best it can for the customers involved in this security incident by recommending password changes, Jasson Casey, chief technology officer at Beyond Identity insists that “passwords – whether unique or complex – are fundamentally flawed.” Instead, Casey says, organizations should be moving to phishing-resistant credentials such as the FIDO Alliance standard blueprints.


More

MobileIDWorld: Google Chrome Launches Automatic Passkey Generation for Android Users

Google Chrome has introduced a new automatic passkey implementation for Android that streamlines the user…

Read More →

Biometric Update: BixeLab joins FIDO Face Verification program, certifies Aware 

Aware has received FIDO Alliance Certification for Face Verification, gaining recognition for its identity verification tech including liveness…

Read More →

Biometric Update: HID upgrades passkey, FIDO authentication capabilities with IDmelon acquisition

Texas-based HID has reached an agreement to acquire Vancouver, Canada-based logical access control provider IDmelon to upgrade its portfolio…

Read More →


123294 Next