Generated by Rank Math SEO, this is an llms.txt file designed to help LLMs better understand and index this website. # FIDO Alliance: FIDO Alliance is focused on providing open and free authentication standards to help reduce the world’s reliance on passwords, using UAF, U2F and FIDO2. ## Sitemaps [XML Sitemap](https://fidoalliance.org/sitemap_index.xml): Includes all crawlable and indexable pages. ## Posts - [FIDO Alliance Supports Biden Administration EO on Cybersecurity](https://fidoalliance.org/fido-alliance-supports-biden-administration-eo-on-cybersecurity/): Federal agencies should choose FIDO as they seek to comply with the new Executive Order that requires the implementation of multi-factor authentication within the next 180 days. - [CISA Cites FIDO Authentication to Protect Political Campaigns](https://fidoalliance.org/cisa-cites-fido-authentication-to-protect-political-campaigns/): Andrew Shikiar, FIDO Alliance Executive Director & CMO  - [Financial Action Task Force Guidance Points to FIDO as Preferred Approach to Combat Authentication Vulnerabilities](https://fidoalliance.org/financial-action-task-force-guidance-points-to-fido-as-preferred-approach-to-combat-authentication-vulnerabilities/): This month, the Financial Action Task Force (FATF) released its final “Guidance on Digital Identity” for financial services regulators. FATF is a standards-making body composed of financial regulators from around the world who are charged with ensuring that the financial system is not used for money laundering, terrorist financing, or other illicit activities. Historically, FATF has focused on traditional banking, but as more and more financial services go digital, they have started focusing on digital identity as a key enabler of safe financial systems. - [Davos: World Economic Forum Points to FIDO as Viable Alternative to Passwords](https://fidoalliance.org/wef-points-to-fido-as-viable-alternative-to-passwords/): Andrew Shikiar, executive director and CMO, FIDO Alliance - [NTT DOCOMO introduces passwordless authentication for d ACCOUNT](https://fidoalliance.org/ntt-docomo-introduces-passwordless-authentication-for-d-account/): NTT DOCOMO, Japan’s largest mobile network operator with over 78 million subscriptions, has announced a new authentication option: d ACCOUNT® Passwordless Authentication. - [IoT News: WBA and FIDO test zero-touch IoT Wi-Fi onboarding](https://fidoalliance.org/iot-news-wba-and-fido-test-zero-touch-iot-wi-fi-onboarding/): Industrial operators can automate IoT onboarding across Wi-Fi networks through a joint specification from the Wireless Broadband Alliance (WBA) and FIDO Alliance. The framework pairs the WBA’s federated OpenRoaming architecture with FIDO Device Onboard protocols. - [Tech Times: Visa Payment Passkey Goes Live at Five India State Banks: OTP Attack Surface Eliminated](https://fidoalliance.org/tech-times-visa-payment-passkey-goes-live-at-five-india-state-banks-otp-attack-surface-eliminated/): India's five-decade-old authentication habit — waiting for a six-digit code on a phone — got its first major structural challenge at the country's public-sector banks last week, when Visa and Mumbai-based payment processor In-Solutions Global (ISG) jointly activated Visa Payment Passkey (VPP) for cardholders at Union Bank of India, Central Bank of India, Bank of Maharashtra, Indian Overseas Bank, and Indian Bank. The launch, announced at Global Fintech Fest 2026 on September 18 in Mumbai, makes these five government-owned lenders the first public-sector institutions globally to activate phishing-proof payment authentication through a shared issuer-processing platform — skipping the bank-by-bank integration grind that has slowed private-sector rollouts. - [FinTech Futures: Sibos 2026: Digital finance in an AI-driven economy – when the agent does the buying, who owns the customer?](https://fidoalliance.org/fintech-futures-sibos-2026-digital-finance-in-an-ai-driven-economy-when-the-agent-does-the-buying-who-owns-the-customer/): By shaping the standards of identity, control, and compliance today, financial institutions can ensure they remain the indispensable anchors of trust in the agentic economy of tomorrow. - [Payments Dive: FIDO wrestles with agentic trust](https://fidoalliance.org/payments-dive-fido-wrestles-with-agentic-trust/): The industry consortium and payments players are considering standards for agentic commerce, particularly for verifying identity. - [How OTP Bank Moldova Modernized Security & UX For Corporate Customers](https://fidoalliance.org/how-otp-bank-moldova-modernized-security-ux-for-corporate-customers/): OTP Bank SA (Moldova), a subsidiary of the Hungarian OTP Group, undertook a strategic security upgrade to modernize transaction authentication for its corporate customers. The bank replaced its legacy competitor hardware tokens with Wultra's Talisman FIDO2 hardware tokens, addressing both security and usability challenges while aligning with the evolving regulatory direction of the European payments framework. - [Biometric Update: Agents are going rogue, and it’s up to the identity sector to govern them](https://fidoalliance.org/biometric-update-agents-are-going-rogue-and-its-up-to-the-identity-sector-to-govern-them/): The AI apocalypse is trending. Warnings are flying that continuing to develop AI technology at the current pace will almost certainly lead to a catastrophe for humankind. - [WiredGov: How we made it easier for millions of users to sign into government services](https://fidoalliance.org/wiredgov-how-we-made-it-easier-for-millions-of-users-to-sign-into-government-services/): This month, the Government Digital Service (GDS) made it faster, easier and more secure to sign into government services. - [Biometric Update: UK rolls out passkeys for GOV.UK One Login](https://fidoalliance.org/biometric-update-uk-rolls-out-passkeys-for-gov-uk-one-login/): The UK government is expanding passkey sign-in for GOV.UK One Login after an initial trial. - [Biometric Update: Passkeys in the post-quantum era: Why FIDO needs more than new algorithms](https://fidoalliance.org/biometric-update-passkeys-in-the-post-quantum-era-why-fido-needs-more-than-new-algorithms/): By Johann-Philipp Thiers, Security Specialist at Swissbit. - [World Economic Forum: Why trust in AI agents requires open global standards](https://fidoalliance.org/world-economic-forum-why-trust-in-ai-agents-requires-open-global-standards/): Executive Director & Chief Executive Officer, FIDO Alliance - [Biometric Update: Singapore expands Singpass passkeys to Android users](https://fidoalliance.org/biometric-update-singapore-expands-singpass-passkeys-to-android-users/): Singapore’s digital identity system Singpass has added passkey login to Android devices, the Government Technology Agency (GovTech) announced Wednesday. - [Fintech Global: EMVCo drafts framework for agentic card payments](https://fidoalliance.org/fintech-global-emvco-drafts-framework-for-agentic-card-payments/): The EMV Agentic Payments – Framework for Specifications has been developed by EMVCo’s newly formed Agentic Payments Task Force, chaired by Clinton Allen. The organisation is now seeking feedback from industry stakeholders on the draft, with submissions open until 30 September 2026. - [FinAINews: Podcast | Mastercard focuses on ‘Verifiable Intent’ for agentic payments, CDO says](https://fidoalliance.org/finainews-podcast-mastercard-focuses-on-verifiable-intent-for-agentic-payments-cdo-says/): Nearly a year after launching Agent Pay, Mastercard is focused on developing trust to drive adoption.  - [Digital Journal: Forgot your password? Canadian retailers could be losing sales because of it](https://fidoalliance.org/digital-journal-forgot-your-password-canadian-retailers-could-be-losing-sales-because-of-it/): Online shopping has become an integral part of Canadian life. Whether purchasing groceries, booking travel, ordering electronics or browsing fashion brands, consumers increasingly expect quick and seamless digital experiences. Yet a surprisingly simple obstacle may be quietly costing online retailers significant revenue: forgotten passwords. - [SC Media: Why yesterday’s identity security standards no longer work for banks](https://fidoalliance.org/sc-media-why-yesterdays-identity-security-standards-no-longer-work-for-banks/): COMMENTARY: Banks are at a cybersecurity inflection point. Anthropic’s powerful Mythos model has prompted alarm throughout the industry. - [Digital Transactions: EMVCo’s Effort to Reinforce Trust in Card-Based Agentic Commerce](https://fidoalliance.org/digital-transactions-emvcos-effort-to-reinforce-trust-in-card-based-agentic-commerce/): The payments industry’s embrace of agentic commerce took a step forward early Tuesday with an announcement from EMVCo that the standards body has developed a framework for “secure, interoperable, and scalable” agentic transactions using cards. - [WebAuthn Level 3 Is Now a W3C Recommendation](https://fidoalliance.org/webauthn-level-3-is-now-a-w3c-recommendation/): On 25 August 2026, the W3C Web Authentication Working Group published Web Authentication: An API for accessing Public Key Credentials – Level 3 as a full W3C Recommendation. For those that may not know, Recommendation is the last stage of the W3C Process Recommendation Track, reached only after Working Draft and Candidate Recommendation phases have achieved wide review, interoperable implementations, and Advisory Committee support. This means WebAuthn L3 is now an endorsed and stable version of the WebAuthn specification. As you know, the WebAuthn specification and the FIDO CTAP specification together make up the FIDO2 standard that passkeys are built on. - [Biometric Update: From passkeys to digital trust with FIDO’s Andrew Shikiar](https://fidoalliance.org/biometric-update-from-passkeys-to-digital-trust-with-fidos-andrew-shikiar/): The Biometric Update Podcast explores the next phase of digital identity, from passkeys and digital wallets to continuous trust - [Forging the Path to Enterprise Passkeys: A Collaborative Discussion by FIDO Board Members](https://fidoalliance.org/forging-the-path-to-enterprise-passkeys-a-collaborative-discussion-by-fido-board-members/): On July 22nd, representatives from two FIDO Alliance board and FIDO Japan WG members, RSA and Mercari, met in Tokyo to discuss the next critical frontier: Enterprise passkey adoption. The hour-long conversation was organized to surface key challenges and opportunities in scaling passkeys across the enterprise, with a particular focus on phishing-resistant authentication and emerging AI-related use cases. - [Recap: FIDO Alliance India Working Group Member Meetup & Workshop 2026](https://fidoalliance.org/recap-fido-alliance-india-working-group-member-meetup-workshop-2026/): On Friday, August 7th, 2026, the FIDO Alliance India Working Group hosted its third annual in-person Member Meetup and Workshop at Google Ananta, Bengaluru, gathering approximately 170 security leaders, engineers, and public sector visionaries. Building on the momentum from previous editions (2024 Recap and 2025 Recap), this year’s workshop highlighted major breakthroughs in national digital identity integration, mass-scale passkey deployments, and enterprise security standards across India. - [FIDO Spanish Webinar: Buenas prácticas para implementar passkeys](https://fidoalliance.org/fido-spanish-webinar-buenas-practicas-para-implementar-passkeys/): https://youtu.be/FKTEPzOze7o - [GBFR: Beyond OTP: How Banks Can Build a Passkey Control Plane](https://fidoalliance.org/gbfr-beyond-otp-how-banks-can-build-a-passkey-control-plane/): Passkeys can reduce exposure to phishing and shared-secret theft, but the banking opportunity depends on disciplined enrolment, recovery, transaction controls and evidence. - [Biometric Update: Mexico’s new banking rules signal a new era for biometric identity verification](https://fidoalliance.org/biometric-update-mexicos-new-banking-rules-signal-a-new-era-for-biometric-identity-verification/): Opening a bank account today looks very different than it did a decade ago. Behind each transaction is a growing reliance on advanced identity verification technologies that help protect both customers and banks. - [SFWeekly: The End of Passwords? Preparing Your Company for Passkeys](https://fidoalliance.org/sfweekly-the-end-of-passwords-preparing-your-company-for-passkeys/): How many passwords did you reset last month? If you’re like most people, the answer is “too many.” Between work tools, internal dashboards, customer platforms, and security requirements that keep getting longer and stranger, passwords have quietly become one of the most frustrating parts of the modern workplace. - [OpenAI and Yubico Partner to Bring Custom Phishing-Resistant YubiKeys to OpenAI Users](https://fidoalliance.org/news-openai-and-yubico-partner-to-bring-custom-phishing-resistant-yubikeys-to-openai-users/): Beginning today, people can purchase a new 2-pack set of custom YubiKeys as part of OpenAI’s Advanced Account Security program - enabling them to secure their ChatGPT accounts with security keys, containing the strongest hardware-backed passkeys. - [Frontier Enterprise: Trust is an outcome, not a feature: FIDO CTO](https://fidoalliance.org/frontier-enterprise-trust-is-an-outcome-not-a-feature-fido-cto/): For the FIDO Alliance, the central constraint on digital identity is clear: Organisations and platforms must strengthen security without placing an additional burden on users. As digital services rapidly expand and become more sophisticated, online identity verification remains at a crossroads. - [FIDO Webinar | Enterprise Passkeys: What Works, What Doesn’t, and How to Roll Them Out](https://fidoalliance.org/fido-webinar-enterprise-passkeys-what-works-what-doesnt-and-how-to-roll-them-out/): Success depends on careful planning around enrollment, recovery, legacy applications, audit requirements, rollout strategy, and user adoption. - [Tech Times: YubiKey 5.8 Ships Hardware-Backed Authorization for AI Agent Workflows](https://fidoalliance.org/tech-times-yubikey-5-8-ships-hardware-backed-authorization-for-ai-agent-workflows/): Touch a YubiKey to log in, and you've proven who you are. Touch a YubiKey to approve a database schema change ordered by an autonomous AI agent, and you've proven something different: that a human consciously authorized that specific action, right now, with cryptographic proof that can be audited. Yubico shipped that second capability on July 21, when it released YubiKey 5.8 firmware — the most architecturally significant update to its hardware security key platform in years — and the distinction matters to any organization deploying agentic AI. - [RSA and the FIDO Alliance Champion the Enterprise Passkey Revolution](https://fidoalliance.org/rsa-and-the-fido-alliance-champion-the-enterprise-passkey-revolution/): In this joint briefing, RSA Security’s Jim Taylor and the FIDO Alliance’s Andrew Shikiar detailed the global transition away from legacy passwords toward robust, phishing-resistant authentication methods. Andrew highlighted the explosive growth of consumer passkeys, noting that over 5 billion passkeys are currently in active use across the globe since FIDO began its market-enablement mission in 2013. However, both experts agreed that consumer adoption is vastly outpacing enterprise deployment, revealing a massive market opportunity for channel partners and MSPs to guide corporate clients through the transition. To illustrate enterprise viability, Jim revealed that RSA has successfully migrated roughly 98% to 99% of its own corporate workforce to a completely passwordless architecture. He noted that common deployment hurdles stem from human behavioral factors and corporate change management rather than underlying technical limitations. - [OpenAI Will Gate Its Most Capable Cyber Models Behind a Physical Security Key](https://fidoalliance.org/openai-will-gate-its-most-capable-cyber-models-behind-a-physical-security-key/): Access to OpenAI’s most cyber-capable AI models will soon require something no phishing email can steal: a physical security key tapped against a phone or plugged into a laptop. - [Biometric Update: Microsoft and Google push passkeys deeper into workplace authentication](https://fidoalliance.org/biometric-update-microsoft-and-google-push-passkeys-deeper-into-workplace-authentication/): Microsoft and Google are pushing passkeys and hardware security keys deeper into workplace authentication, with Microsoft preparing to make passkeys the default authentication experience in Entra ID, and Google adding FIDO2-compliant security keys as a second factor in the Windows login process for Google Workspace users. - [FIDO Alliance Releases Authenticate U.S. 2026 Agenda](https://fidoalliance.org/fido-alliance-releases-authenticate-u-s-2026-agenda/): Carlsbad, Calif., July 9, 2026 – The FIDO Alliance has announced the agenda for Authenticate U.S. 2026, the only industry conference dedicated to digital identity and authentication. The event will take place October 19–21, 2026 at the Omni La Costa Resort and Spa in Carlsbad, California, with options for virtual participation available. - [Cyber Insider: ExpressVPN adds passkeys on password manager, passes security audit](https://fidoalliance.org/cyber-insider-expressvpn-adds-passkeys-on-password-manager-passes-security-audit/): ExpressVPN has announced a major update to its standalone ExpressKeys password manager, adding passkey support, secure credential sharing, and direct vault imports. - [Tech Radar Pro: Know your agent: building the foundation of autonomous commerce](https://fidoalliance.org/tech-radar-pro-know-your-agent-building-the-foundation-of-autonomous-commerce/): Artificial intelligence has officially entered its execution phase. After years of experimentation, businesses are rapidly deploying AI not just to analyze data, but to act on it. - [PaymentsJournal: EMVCo Proposes Standards for Stronger Payment Authentication](https://fidoalliance.org/paymentsjournal-emvco-proposes-standards-for-stronger-payment-authentication/): EMVCo has released a draft framework that could pave the way for a universal standard for verifiable digital credentials in card‑based payments, a move that could make online checkout both more secure and less cumbersome. - [FIDO Spanish Webinar: Introducción a passkeys](https://fidoalliance.org/introduccion-a-passkeys/): https://youtu.be/-yI5r03hEUQ - [Biometric Update: Yubico hackathon to preview YubiKey 5.8 support for next-generation passkeys](https://fidoalliance.org/biometric-update-yubico-hackathon-to-preview-yubikey-5-8-support-for-next-generation-passkeys/): Yubico will host a virtual developer hackathon for the FIDO Alliance developer community on August 5 to give developers an early look at the company’s upcoming YubiKey 5.8 firmware release and its support for CTAP 2.3 capabilities. - [PYMNTS: Mastercard Wants to Teach AI Agents How to Spend](https://fidoalliance.org/pymnts-mastercard-wants-to-teach-ai-agents-how-to-spend/): For nearly 60 years, Mastercard has answered one question over and over. How do you get two parties who’ve never met to trust each other enough to do business? The answer was a card, a network, a rulebook everyone agreed to follow. - [Biometric Update: EMVCo proposes global schema for verifiable digital payment credentials](https://fidoalliance.org/biometric-update-emvco-proposes-global-schema-for-verifiable-digital-payment-credentials/): EMVCo has put a draft framework out for consultation that aims to bring verifiable digital credentials into card‑based payment authentication. - [Identity Week: New FIDO Alliance and HID study reveals major gap between identity security confidence and reality](https://fidoalliance.org/identity-week-new-fido-alliance-and-hid-study-reveals-major-gap-between-identity-security-confidence-and-reality/): Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years - [Biometric Update: Passkey adoption stalls at scale despite strong interest, new study shows](https://fidoalliance.org/biometric-update-passkey-adoption-stalls-at-scale-despite-strong-interest-new-study-shows/): The FIDO Alliance and HID have released new research showing a widening gap between enterprise confidence in identity security and day‑to‑day operational performance. The State of Physical and Digital Identity in the Enterprise report surveyed 500 IT and cybersecurity decision makers across the U.S., Canada, the UK, France and Germany. - [Request for Proposal (RFP): ISO/IEC 17065 Accreditation Consultancy](https://fidoalliance.org/request-for-proposal-rfp-iso-iec-17065-accreditation-consultancy/): The FIDO Alliance is seeking a specialized consulting partner to guide us through the ISO/IEC 17065 accreditation process. Our objective is to be recognized as a Certification Body (CB) capable of evaluating and certifying wallet components, including authenticator sub-components, under the FIDO Alliance Wallet and Authenticator Certification Schemes. - [HRTECH EDGE: Most Enterprises Think Identity Access Is Secure. New Research Suggests Otherwise](https://fidoalliance.org/hrtech-edge-most-enterprises-think-identity-access-is-secure-new-research-suggests-otherwise/): Enterprises may be more confident about identity security than they should be. - [Carrier Management: Major Gap Between Identity Security Confidence and Reality: Study](https://fidoalliance.org/carrier-management-major-gap-between-identity-security-confidence-and-reality-study/): A new report uncovered a significant disconnect between enterprise confidence in identity security and operational reality, according to identity technology providers FIDO Alliance and HID. - [Crypto News: xMoney revolutionizes digital payments: first in the world to launch Mastercard Payment Passkey via app](https://fidoalliance.org/crypto-news-xmoney-revolutionizes-digital-payments-first-in-the-world-to-launch-mastercard-payment-passkey-via-app/): xMoney marks a key milestone in the evolution of digital payments, becoming the world’s first Mastercard issuer to launch the creation and enrollment of the Payment Passkey directly through its own mobile banking application. The announcement, made in Bucharest on June 11, 2026, positions xMoney as a pioneer in offering a solution that promises to redefine the security, simplicity, and speed of online transactions. - [Report: The State of Physical and Digital Identity in the Enterprise](https://fidoalliance.org/report-the-state-of-physical-and-digital-identity-in-the-enterprise/): FIDO Alliance and HID have launched The State of Physical and Digital Identity in the Enterprise, a new research report examining how organizations manage physical and logical access across their workforces. - [New FIDO Alliance and HID Study Reveals Major Gap Between Identity Security Confidence and Reality](https://fidoalliance.org/new-fido-alliance-and-hid-study-reveals-major-gap-between-identity-security-confidence-and-reality/): Research Reveals 94% of Enterprises Claim They Can Revoke Employee Access Within 24 Hours, Yet 35% experienced delays or failures in the past two years  - [ID Tech: FIDO Opens June Interoperability Testing Window for Certification Candidates](https://fidoalliance.org/id-tech-fido-opens-june-interoperability-testing-window-for-certification-candidates/): The FIDO Alliance has opened its June interoperability testing event, giving FIDO2 and FIDO UAF implementers a certification step for passwordless authentication products. - [Frontier Enterprise: CSA: More authentication does not mean better security](https://fidoalliance.org/frontier-enterprise-csa-more-authentication-does-not-mean-better-security/): Why do users still get hacked? In the past, it was often because of weak passwords or the absence of multi-factor authentication (MFA), and for a long time, authentication was treated mainly as a security control that sat quietly in the background of digital systems. Today, however, the real threat lies in authentication itself, which has become ground zero for attackers. - [Global Banking and Finance Review: The Growing Role of FIDO and Passkeys in Banking Authentication](https://fidoalliance.org/global-banking-and-finance-review-the-growing-role-of-fido-and-passkeys-in-banking-authentication/): Banks are no longer fighting simple password reuse. They’re facing real-time phishing kits, MFA fatigue, session hijacking, AI-powered social engineering, and more. - [ID Tech: RSA Extends Passwordless Authentication to Linux Environments](https://fidoalliance.org/id-tech-rsa-extends-passwordless-authentication-to-linux-environments/): RSA has extended its passwordless authentication platform to Linux, bringing FIDO-based, phishing-resistant sign-in to Linux servers, developer workstations, and critical infrastructure that have typically relied on passwords and other legacy credentials. - [Benchmark: HID adds governance layer to FIDO authenticators with Enterprise Attestation](https://fidoalliance.org/benchmark-hid-adds-governance-layer-to-fido-authenticators-with-enterprise-attestation/): The capability, built on the FIDO Alliance’s WebAuthn and CTAP specifications, works at the point of passkey registration. When a device attempts to enrol, the system checks for a certificate that ties it to a known, company-issued authenticator. If that certificate is absent or unrecognised, enrolment is blocked by policy. If it passes, the user sees no change to their login experience – the governance layer operates entirely in the background. - [CISO Tradecraft® Podcast: Passwordless Authentication](https://fidoalliance.org/ciso-tradecraft-podcast-passwordless-authentication/): In this discussion, G. Mark Hardy and Nishant Kaushik explore the necessity of moving beyond traditional passwords, which they define as the original sin of cybersecurity due to their vulnerability to credential stuffing and phishing attacks. Kaushik explains that the FIDO Alliance promotes a passwordless future by replacing shared secrets with asymmetric cryptography, utilizing private keys stored on smartphones or hardware tokens like YubiKeys to ensure phishing-resistant authentication. The conversation highlights that identity is the new perimeter, shifting the focus from human-memorized codes to biometric verification and device-bound passkeys that verify user presence. Ultimately, the experts warn that a secure transition must include robust account recovery flows, as failing to secure the "back door" renders even the most advanced cryptographic-based authentication vulnerable to exploitation. - [Semperis: Enforcing Phishing-Resistant Authentication at Scale with Passkeys](https://fidoalliance.org/semperis-enforcing-phishing-resistant-authentication-at-scale-with-passkeys/): Semperis is an identity security company founded in 2013 and headquartered in Hoboken, New Jersey, with approximately 600 employees across North America, Europe, APAC and Israel. The company's platform protects Active Directory, Okta and Entra ID environments for government agencies and Fortune 2000 enterprises, covering threat detection, incident response and directory recovery. - [Associated Press (syndicated from Business Wire): FIDO Alliance Announces Digital Identity and Authentication-Focused Agenda Themes for Authenticate APAC 2026 Conference](https://fidoalliance.org/associated-press-syndicated-from-business-wire-fido-alliance-announces-digital-identity-and-authentication-focused-agenda-themes-for-authenticate-apac-2026-conference/): The FIDO Alliance today announced agenda themes and program highlights for Authenticate APAC 2026, taking place June 2–3 at the Grand Hyatt Singapore. Bringing together global and regional leaders in authentication and digital identity, the event will explore how evolving standards, regulations, AI-driven capabilities and real-world deployments are shaping the future of trusted digital interactions across APAC and beyond. - [Banesco Banco Universal: Scaling Phishing-Resistant Authentication to 2.2 Million Users](https://fidoalliance.org/banesco-banco-universal-scaling-phishing-resistant-authentication-to-2-2-million-users/): Banesco Banco Universal is the leading private bank in Venezuela, with more than 2.4 million monthly active users across its mobile and web banking platforms. The bank provides digital services for peer-to-peer payments and high-value transfers. Banesco operates within a multinational banking group, and the group's global security strategy directly informed the bank's move toward phishing-resistant authentication. - [Building the Trust Layer for Agentic Payments with AP2 and Verifiable Intent](https://fidoalliance.org/building-the-trust-layer-for-agentic-payments-with-ap2-and-verifiable-intent/): Nishant Kaushik, CTO, FIDO Alliance - [FIDO Alliance Announces Agenda for Authenticate APAC 2026](https://fidoalliance.org/fido-alliance-announces-agenda-for-authenticate-apac-2026-2/): Global innovators from Adidas, Apple, Grab, OpenAI, Samsung Electronics and more to share expertise at Singapore authentication & identity event - [FIDO Case Study: DragonSoft Security Associates Inc.](https://fidoalliance.org/fido-case-study-dragonsoft-security-associates-inc/): Redefining Cybersecurity Governance: From Vulnerability Detection to Identity-Based Defense - [The AI Journal: Agentic Commerce: The $1.5 Trillion Infrastructure Race and Why Fintech Startups Must Move Now](https://fidoalliance.org/the-ai-journal-agentic-commerce-the-1-5-trillion-infrastructure-race-and-why-fintech-startups-must-move-now/): Commerce is undergoing its most fundamental transformation since the invention of the credit card. For thirty years, digital payments followed a simple logic: a human decides, a human clicks, a human pays. That model is ending. - [Identity Week: Amazon shares data on their customer passkey adoption](https://fidoalliance.org/https-fidoalliance-org-amazon-shares-data-on-their-customer-passkey-adoption/): Amazon is sharing new data to suggest passkeys are in favour with 465 million customers now, ensuring expedited, secure authentication six times quicker than traditional passwords. - [AI Invest Official: Singapore Passkey Adoption Hits 5 Billion Amid Rising Demand for Secure Authentication](https://fidoalliance.org/ai-invest-official-singapore-passkey-adoption-hits-5-billion-amid-rising-demand-for-secure-authentication/): Singapore has reached a milestone of 5 billion passkeys in use worldwide, as reported by the FIDO Alliance. The adoption of passkeys has been driven by a shift away from passwords, with 80% of people in Singapore aware of passkeys and 65% having enabled one on at least one account. The data also reveals the scale of the damage caused by passwords, with one in seven Singapore consumers experiencing an account compromise or breach notification in the past year. The industry is now addressing the challenges highlighted in the data at Authenticate APAC 2026 in Singapore. - [Across the Passkey Landscape: Expert AMA](https://fidoalliance.org/across-the-passkey-landscape-expert-ama/): https://youtu.be/Z4F8yJyT7p4 - [Five Billion Passkeys: A Milestone, Not a Finish Line](https://fidoalliance.org/five-billion-passkeys-a-milestone-not-a-finish-line/): Megan Shamas, CMO, FIDO Alliance - [FIDO Alliance Reports Accelerating Global Passkey Adoption on World Passkey Day 2026](https://fidoalliance.org/fido-alliance-reports-accelerating-global-passkey-adoption-on-world-passkey-day-2026/): Global research from the FIDO Alliance finds near-universal awareness of passkeys, with high adoption rates among consumers and enterprises - [The State of Passkeys 2026: Global Consumer and Workforce Report](https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/): Passkeys have reached global scale with 5 billion passkeys now in active use. Across both consumer and workforce environments, awareness is now near-universal and adoption has followed: 90% of consumers are familiar with passkeys, and 75% have enabled them on at least some accounts. In parallel, workforce deployment is approaching mainstream levels, with 68% of organizations deploying, piloting, or rolling out passkeys for employee authentication.​ - [PYMNTS: Google and Mastercard Contribute Agentic Commerce Standards to FIDO Alliance](https://fidoalliance.org/pymnts-google-and-mastercard-contribute-agentic-commerce-standards-to-fido-alliance/): The FIDO Alliance plans to develop standards for artificial intelligence (AI) agentic interactions and commerce that will define trusted mechanisms for how agents authenticate, act and transact on behalf of users. - [Wirecutter: Passkeys Are the New Passwords. You Should Start Using Them Now.](https://fidoalliance.org/wirecutter-passkeys-are-the-new-passwords-you-should-start-using-them-now/): Passkeys Are the New Passwords. You Should Start Using Them Now. - [The Payers: Google donates Agent Payments Protocol to FIDO Alliance](https://fidoalliance.org/google-donates-agent-payments-protocol-to-fido-alliance/): Google has donated its Agent Payments Protocol to the FIDO Alliance and released an updated version, including autonomous payment capabilities. - [FinTech Magazine: How FIDO Leads the Push for Trusted AI-Driven Transactions](https://fidoalliance.org/how-fido-leads-the-push-for-trusted-ai-driven-transactions/): FIDO Alliance launches new standards to secure AI agent interactions, enabling trusted authentication and payments in emerging agentic commerce ecosystems - [Wired: The Race Is on to Keep AI Agents From Running Wild With Your Credit Cards](https://fidoalliance.org/wired-the-race-is-on-to-keep-ai-agents-from-running-wild-with-your-credit-cards/): AI agents may soon be buying your stuff for you. The FIDO Alliance has teamed up with Google and Mastercard to try to ensure that shopping in the near future isn't a complete disaster. - [The Agentic Era Is Here. Now We Need to Make It Trustworthy.](https://fidoalliance.org/the-agentic-era-is-here-now-we-need-to-make-it-trustworthy/): Andrew Shikiar, CEO and Executive Director, FIDO Alliance - [FIDO Alliance to Develop Standards for Trusted AI Agent Interactions](https://fidoalliance.org/fido-alliance-to-develop-standards-for-trusted-ai-agent-interactions/): Formation of Agentic Authentication Working Group and development of agentic payment frameworks will support trusted, interoperable agentic workflows - [BBC: UK cyber chiefs say it’s time to ditch passwords for passkeys – what are they?](https://fidoalliance.org/uk-cyber-chiefs-say-its-time-to-ditch-passwords-for-passkeys/): It's time to ditch passwords for passkeys - [National Cyber Security Centre (NCSC): Passkeys are more secure than traditional ways to log in](https://fidoalliance.org/national-cyber-security-centre-ncsc-passkeys-are-more-secure-than-traditional-ways-to-log-in/): Passkeys are more secure than traditional ways to log in - [Security IT News: The State of Biometric Security in the Age of AI Fraud Report Released](https://fidoalliance.org/security-it-news-biometric-security-ai-fraud-report/): The State of Biometric Security in the Age of AI Fraud Report Released - [Mobile ID World: Mastercard and Google Put Passkeys at the Heart of AI Payments](https://fidoalliance.org/mastercard-ai-payments-passkeys-fido-alliance/): When an AI agent buys something on your behalf, how does the merchant know you actually authorized it? That question sits at the center of Verifiable Intent, an open-source cryptographic framework introduced by Mastercard and Google to bring biometric, passkey-grade trust to autonomous AI transactions. - [TechTarget Search Security: How to roll out an enterprise passkey deployment](https://fidoalliance.org/passkeys/): CISOs know that the human element can be the weakest link in an enterprise's cybersecurity defenses, often surfacing when end users create weak passwords that threat actors easily crack. Seeking a stronger alternative, security teams are increasingly turning to passkeys. - [Biometric Update: OpenAI joins FIDO Alliance to help AI agent authentication push](https://fidoalliance.org/openai-fido/): OpenAI is the newest member of the FIDO Alliance, joining the passwordless authentication group to contribute to its efforts to provide the secure and private digital identity frameworks that will be needed to ensure AI agents are trustworthy, verified and governed by user intent. - [GB Hackers: Top 10 Best Multi-Factor Authentication (MFA) Providers in 2026](https://fidoalliance.org/gb-hackers-top-10-best-multi-factor-authentication-mfa-providers-in-2026/): The landscape of Multi-Factor Authentication is dynamic, driven by new threats and technological advancements. - [Biometric Update: Digital identity research warns of ‘password debt’ as enterprises delay IAM rollouts](https://fidoalliance.org/biometric-update-digital-identity-research-warns-of-password-debt-as-enterprises-delay-iam-rollouts/): Enterprises may be sharpening their understanding of digital identity threats but the industry is still struggling to turn that knowledge into large‑scale execution. Hypr’s latest State of Passwordless Identity Assurance report shows passwordless and identity verification deployments stalling. RSA has been testing its own passwordless strategy internally, uncovering the hidden dependencies that still tether organizations to passwords. And in the public sector, Cisco Duo is positioning its zero‑trust platform as a way for agencies to align with new NIST cybersecurity standards. - [Financial News-UK: The Death of the Password – How Passkeys Secretly Took Over the Internet](https://fidoalliance.org/financial-news-uk-the-death-of-the-password-how-passkeys-secretly-took-over-the-internet/): Researchers revealed what might be the biggest collection of stolen login credentials ever gathered in one location sometime in the middle of 2025. A compiled dataset, organized and searchable, contains about 16 billion records, including usernames, passwords, account details scraped from infostealer malware, phishing operations, and years of accumulated breach archives, covering accounts across Google, Apple, Meta, and dozens of other platforms. There was no significant zero-day exploit. No advanced nation-state assault. Just the patient, quiet harvesting of a system that was based on shared secrets and never sufficiently considered what would happen if those secrets were no longer kept secret. It wasn’t a particularly bad password. It failed gradually at first, then all at once, much like a slow leak eventually floods a basement. - [BGR: Ditch Your Passwords And Start Using This More Secure Method](https://fidoalliance.org/bgr-ditch-your-passwords-and-start-using-this-more-secure-method/): Creating new passwords on the spot can be really taxing. And that can also lead to some sloppy practices, like repeating old passwords or modifying them. But it turns out that does a lot more harm than good, since you're likely generating weak, exploitable passwords as a result. A strong password often involves using a complex string of lowercase and uppercase letters, along with numbers and symbols. Although theoretically that sounds easy to do, actually coming up with them can be a pain, which is why many people have opted to use password managers. While top password managers are great for creating new, strong passwords and storing them, they aren't perfect. For example, your password manager depends on its own primary password to safeguard all of your deposited logins, which can create a single point of failure. As a result, held passwords can be maliciously stolen, leaving all your connected accounts vulnerable. - [FIDO Seminar: Advancing Passkeys in the Workforce](https://fidoalliance.org/fido-seminar-advancing-passkeys-in-the-workforce/): The FIDO Alliance hosted a one-day seminar on “Advancing Passkeys in the Workforce.” The seminar gathered senior security and identity leaders for practical insights, meaningful discussion, and networking during a lunch and learn seminar on the first day of the RSA Conference. - [SC Media: OneSpan’s Ashish Jain on why passkeys are ready for prime time in modern banking](https://fidoalliance.org/sc-media-onespans-ashish-jain-on-why-passkeys-are-ready-for-prime-time-in-modern-banking/): Authentication has long required an uneasy tradeoff between strong security and smooth user experience. - [Tech Radar: Why strong authentication beyond the browser will define the future of connected devices](https://fidoalliance.org/tech-radar-why-strong-authentication-beyond-the-browser-will-define-the-future-of-connected-devices/): The way we interact with technology is no longer confined to the browser. Cars, smart homes, wearable devices, and industrial systems are now deeply connected, driving unprecedented convenience and innovation, but also creating vast new attack surfaces. - [Security Brief US: RSA expands Microsoft tie-up with passwordless access](https://fidoalliance.org/security-brief-us-rsa-expands-microsoft-tie-up-with-passwordless-access/): RSA has expanded support between RSA ID Plus and Microsoft 365 E7, extending the companies' identity security partnership. - [PC Mag: Stop Using Passwords. Here’s Why You Should Switch to Passkeys ASAP](https://fidoalliance.org/pc-mag-stop-using-passwords-heres-why-you-should-switch-to-passkeys-asap/): Even though everyone knows "password123!" is terrible, it still lands at the top of "worst password" lists. We get it, no one likes remembering passwords, and even if you do have a password manager (and you should), changing them after every data breach is a pain. Luckily, passkeys may replace passwords entirely with something more secure that's tied to your devices. With luck, it may make the traditional email address-and-password combination obsolete. - [Inside RSA: Deploying FIDO and Passwordless Solutions at Scale](https://fidoalliance.org/inside-rsa-deploying-fido-and-passwordless-solutions-at-scale/): Case Study Authors: Shauna Pettit-Brown, Robert Hughes, Jean-Christophe Laurent, Kenn Chong, and Philip J Corriveau - [HYPR: The State of Passwordless Identity Assurance 2026](https://fidoalliance.org/hypr-the-state-of-passwordless-identity-assurance-2026/): Crucial Insights Into Identity Threats, Technologies and Trends - [Computing: Passwordless authentication gaining popularity, Computing research finds](https://fidoalliance.org/computing-passwordless-authentication-gaining-popularity-computing-research-finds/): Half of UK IT leaders polled say their organisation is now using passkeys. - [Finextra: Deep Dive: Mastercard Verifiable Intent vs Visa Trusted Agent Protocol](https://fidoalliance.org/finextra-deep-dive-mastercard-verifiable-intent-vs-visa-trusted-agent-protocol/): Agentic commerce breaks a core assumption of online payments, that a human is directly clicking “buy” on a trusted surface. Once software can browse, decide, and transact, merchants and networks lose the simplest security primitive: “the customer was here.” - [The Defiant: Mastercard and Google Team Up to Build Trust for AI-Powered Shopping](https://fidoalliance.org/the-defiant-mastercard-and-google-team-up-to-build-trust-for-ai-powered-shopping/): Mastercard has unveiled Verifiable Intent, a new open, standards-based trust framework co-developed with Google, designed specifically for "agentic commerce" — a world where artificial intelligence (AI) systems don't just assist shoppers, but actively plan, decide, and complete purchases autonomously. - [PYMNTS: Mastercard Unveils Open Standard to Verify AI Agent Transactions](https://fidoalliance.org/pymnts-mastercard-unveils-open-standard-to-verify-ai-agent-transactions/): Every time an AI agent makes a purchase, three questions hang over the transaction. Did the consumer actually authorize this? Did the agent follow instructions exactly? And if something goes wrong, can anyone prove it? The payments, AI and merchant sectors are all looking for universal answers to those questions. Mastercard is pitching a new standard as the solution. - [FinExtra: Fido Alliance sets sights on Latin America](https://fidoalliance.org/finextra-fido-alliance-sets-sights-on-latin-america/): As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, bad actors are exploiting technologies and processes, putting this progress at risk. - [FIDO Webinar: The Spectrum of Authentication: How BankID Norway Unifies Passkeys and Biometric Liveness](https://fidoalliance.org/fido-webinar-the-spectrum-of-authentication-how-bankid-norway-unifies-passkeys-biometric-liveness/): Organizations are grappling with an increasingly diverse and sophisticated threat landscape, including AI-powered phishing campaigns, physical presentation attacks, and scalable, automated injection attacks. Join experts from BankID, iProov and FIDO Alliance to explore how organizations can combat these growing threats by unifying passkeys with advanced liveness. - [Yahoo!Finance: WinMagic Reveals What Comes After Passkeys: Identity Assurance That Lives Beyond Login](https://fidoalliance.org/yahoofinance-winmagic-reveals-what-comes-after-passkeys-identity-assurance-that-lives-beyond-login/): WinMagic exposes the fundamental flaw in modern authentication: passkeys secure the login, but attackers have already moved on to sessions, tokens, and transactions. The company introduces Live Key and Live Identity in Transaction (LIT), extending cryptographic protection beyond the login moment to secure the entire session timeline—with zero user friction. - [Bleeping Computer: Bitwarden adds support for passkey login on Windows 11](https://fidoalliance.org/bleeping-computer-bitwarden-adds-support-for-passkey-login-on-windows-11/): Bitwarden announced support for logging into Windows 11 devices using passkeys stored in the manager's vault, enabling phishing-resistant authentication. - [Biometric Update: NFC-based IDV with liveness delivers zero fraud, fewer support calls for BankID Norway](https://fidoalliance.org/biometric-update-nfc-based-idv-with-liveness-delivers-zero-fraud-fewer-support-calls-for-bankid-norway/): With 4.7 million enrolled users in a country of roughly 5.6 million people, BankID Norway is one of the most widely adopted digital identity schemes in the world. In 2025 alone, the platform processed close to 901 million transactions, covering everything from tax filings and student loan applications to legal name changes and divorce proceedings. But scale exposes identity verification to threats, meaning that authentication alone is not enough. - [Yahoo! Finance: Yubico Unveils “YubiNation Partners”: A New Era of Global Channel Partnership to Secure Digital Identities in the Age of AI](https://fidoalliance.org/yahoo-finance-yubico-unveils-yubination-partners-a-new-era-of-global-channel-partnership-to-secure-digital-identities-in-the-age-of-ai/): Yubico, a modern cybersecurity company and creator of the most secure passkeys, today announced the launch of YubiNation Partners, a new global Channel program designed to unite a community of security experts. In the face of growing AI-driven cyber threats, the program enables partners to become trusted advisors and cultivate a safer digital world for their customers, making identities private and secure. - [Android Headlines: Dashlane Becomes First Password Manager to Implement FIDO Credential Exchange on Android](https://fidoalliance.org/android-headlines-dashlane-becomes-first-password-manager-to-implement-fido-credential-exchange-on-android/): Dashlane has implemented the FIDO Credential Exchange standard on Android to simplify vault transfers. This protocol replaces insecure CSV exports with an encrypted direct transfer between apps. While it enables the portability of passkeys, its current effectiveness is limited because other major providers like Google have yet to fully adopt the standard. - [ChosunBiz: Raonsecure launches Korea hiring drive to power Agentic AI security push](https://fidoalliance.org/chosunbiz-raonsecure-launches-korea-hiring-drive-to-power-agentic-ai-security-push/): Raonsecure said on the 26th it will launch an open recruitment drive for AI and security talent to lead the era of Agentic AI. - [MUO: Passwords are officially obsolete — here’s why you should make the jump today](https://fidoalliance.org/muo-passwords-are-officially-obsolete-heres-why-you-should-make-the-jump-today/): Our entire digital life is secured by a password, and it's up to us to use secure and unique passwords that can withstand emerging physical threads. Routine data breaches, phishing attacks, and compromised accounts put user data at risk — especially if you use the same password across multiple accounts. Considering the kinds of data stored in digital accounts in 2026, from banking accounts or credit card hubs, we need an option that's both secure and simple. Passwords are not the answer, but their replacement is just as useful and private as advertised. - [MSN: Why you simply don’t need a password manager anymore in 2026](https://fidoalliance.org/msn-why-you-simply-dont-need-a-password-manager-anymore-in-2026/): Federal authentication standards and major platform shifts have made passkeys the default login method for most consumer and enterprise accounts, pushing traditional password managers toward obsolescence. The FIDO2 protocol, backed by the W3C’s WebAuthn specification and endorsed by both NIST and CISA as the only widely available phishing-resistant authentication method, now ships natively in every major browser and operating system. For the growing number of users whose accounts rely on public-key credentials instead of shared secrets, the password manager has become a solution to a problem that no longer exists. - [Launching the FIDO Americas Adoption Forum](https://fidoalliance.org/launching-the-fido-americas-adoption-forum/): Digital economies across the Americas are expanding rapidly, presenting both new opportunities and risks. As a largely mobile-first region, there is widespread innovation, especially in payments. At the same time, bad actors are exploiting technologies and processes, putting this progress at risk. - [FIDO Paris Seminar 2026](https://fidoalliance.org/fido-paris-seminar-2026/): The FIDO Alliance hosted a one-day seminar on “Advancing Authentication, Identity and Payments in Europe.” The seminar gathered many influential leaders and decision-makers to explore Europe’s evolving authentication, identity, and payments landscape.  - [ID Tech: SK Telecom Joins FIDO Alliance Board as Passkeys Adoption Accelerates](https://fidoalliance.org/id-tech-sk-telecom-joins-fido-alliance-board-as-passkeys-adoption-accelerates/): SK Telecom has been appointed to the FIDO Alliance Board of Directors, adding a major mobile operator to the leadership group shaping industry priorities around passkeys and phishing-resistant authentication. - [PC Mag: Still Using Passwords? That’s Risky. Here’s Why You Should Switch to Passkeys Now](https://fidoalliance.org/pc-mag-still-using-passwords-thats-risky-heres-why-you-should-switch-to-passkeys-now/): Even though everyone knows 12345" is a terrible password, it still lands at the top of "worst password" lists. We get it, no one likes remembering passwords, and changing them after every data breach is a pain, even if you do have a password manager. Luckily, passkeys have a real chance to replace them entirely with something more secure, tied to your specific devices. With luck and time, it may make the traditional email address-and-password combination obsolete. - [Wired: How Passkeys Work—and How to Use Them](https://fidoalliance.org/wired-how-passkeys-work-and-how-to-use-them-2/): Passwords suck. They're hard to remember, but worse is playing the ever-evolving game of cybersecurity whack-a-mole with your most important accounts. That’s where passkeys come into play. The so-called “war on passwords” has taken off over the past two years, with titans like Google, Microsoft, and Apple pushing for a password-less future that the FIDO Alliance (a consortium made to “help reduce the world’s over-reliance on passwords”) has been trying to realise for over a decade. - [Mastercard: Unlock your key to a more secure checkout](https://fidoalliance.org/mastercard-unlock-your-key-to-a-more-secure-checkout/): Unlock your key to a more secure checkout. Use your unique payment passkey to secure your purchases. - [Integrating FIDO Standards into Secure OT Connectivity — A Practical Path to Resilience](https://fidoalliance.org/integrating-fido-standards-into-secure-ot-connectivity-a-practical-path-to-resilience/): Operational Technology (OT) environments — from industrial control systems to critical infrastructure networks — have traditionally prioritized safety and availability. The newly published Secure Connectivity Principles for Operational Technology (OT) guidance produced by the UK National Cyber Security Centre (NCSC) in partnership with agencies from Australia, Canada, US, Germany, Netherlands, and New Zealand underscores how evolving connectivity demands require a modern security posture that does not compromise operational integrity while facing an expanding threat landscape.  - [Enterprise IT News: Why APAC can lead the world in FIDO and passkey adoption](https://fidoalliance.org/enterprise-it-news-why-apac-can-lead-the-world-in-fido-and-passkey-adoption/): Asia-Pacific (APAC) is one of the most-attacked regions globally — accounting for 34 per cent of incidents in 2024, with valid-account abuse as the leading entry vector, according to the IBM X-Force 2025 Threat Intelligence Index — making strong identity protection a business imperative. Across business process outsourcing (BPO) operations, manufacturing floors, healthcare environments, and both SMEs and large enterprises, workers rely heavily on continuous access to applications and sensitive digital data, meaning the digital identity of every employee has effectively become the new perimeter. - [ID Tech: Better Identity Coalition Circulates Draft Voluntary Code of Conduct for Verifiable Credentials](https://fidoalliance.org/id-tech-better-identity-coalition-circulates-draft-voluntary-code-of-conduct-for-verifiable-credentials/): The Better Identity Coalition has circulated a draft voluntary code of conduct it describes as “rules of the road” for how organizations request and use data from verifiable digital credentials. The effort offers an early framework for limiting overly broad or invasive data requests as verifiable credentials move closer to real-world deployment. - [Biometric Update: Passkeys offer potential solution to increased deepfake attacks on financial services](https://fidoalliance.org/biometric-update-passkeys-offer-potential-solution-to-increased-deepfake-attacks-on-financial-services/): Among sectors vulnerable to AI-assisted fraud attacks, the financial industry is perhaps the ripest. With high-stakes remote transactions occurring at scale, increasingly involving AI agents, there are countless attack surfaces, and potentially massive payoffs. - [Biometric Update: Calling Utah: SEDI offers template for fast-tracking digital identity schemes](https://fidoalliance.org/biometric-update-calling-utah-sedi-offers-template-for-fast-tracking-digital-identity-schemes/): A presentation from Chief Privacy Officer for the State of Utah Christopher Bramwell at the FIDO Identity Policy Forum looks at how the state’s unique culture has influenced its leadership on digital identity in the U.S., in the form of its State Endorsed Digital Identity (SEDI) initiative. - [Biometric Update: FIDO’s Andrew Shikiar predicts the triumph of wallets in 2026](https://fidoalliance.org/biometric-update-fidos-andrew-shikiar-predicts-the-triumph-of-wallets-in-2026/): Passkey champions to develop certification profile as focus turns to digital credentials - [Meta Engineering: No Display? No Problem: Cross-Device Passkey Authentication for XR Devices](https://fidoalliance.org/meta-engineering-no-display-no-problem-cross-device-passkey-authentication-for-xr-devices/): Meta shares a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices). - [Payments Journal: Why the Future of Financial Fraud Prevention Is Passwordless](https://fidoalliance.org/payments-journal-why-the-future-of-financial-fraud-prevention-is-passwordless/): Fraud is evolving faster than ever, with AI-powered scams, deepfake-enabled identity theft, and a surge in account takeovers putting financial institutions on high alert and accountholders at risk. As the most visible safeguard of the past few decades, the humble password is coming under increasing scrutiny. - [Payments Dive: Charting 2026 payments trends](https://fidoalliance.org/payments-dive-charting-2026-payments-trends/): For our 2026 outlook, we picked six trends to better acquaint you with what to expect this year in the payments arena, but then we went a step further in selecting three worthy of a deeper dive. See all four stories below, and a brief explanation of why we focused where we did. - [CNBC: Data breaches climbed to a record high in 2025. How to protect your personal information](https://fidoalliance.org/cnbc-data-breaches-climbed-to-a-record-high-in-2025-how-to-protect-your-personal-information/): It’s the letter most consumers dread receiving — the notification that your personal information has been involved in a data breach. - [Cybersecurity Dive: Top 3 factors for selecting an identity access management tool](https://fidoalliance.org/cybersecurity-dive-top-3-factors-for-selecting-an-identity-access-management-tool/): It’s not like forgetting the milk at the grocery store. No big deal, just add it to the list for next time. But that kind of oversight in identity management isn’t as simple to fix, and organizations that adopt a solution later may find it becomes an expensive add-on to their security to-do list. - [Recap: FIDO Tokyo Seminar 2025 – Toward a Passwordless World: Deepening Japan’s Leadership and Deployment ](https://fidoalliance.org/recap-fido-tokyo-seminar-2025-toward-a-passwordless-world-deepening-japans-leadership-and-deployment/): On December 5, 2025, the digital identity community gathered at Tokyo Port City Takeshiba for the 12th FIDO Tokyo Seminar. Under the theme “Towards a Passwordless World”, the event brought together 300+  industry leaders, government officials, and engineers to discuss the effectiveness of passkeys as a countermeasure against phishing and to explore the future landscape of digital identity. - [Payment Industry Intelligence: Agentic Commerce and the quiet return of Guest Checkout](https://fidoalliance.org/payment-industry-intelligence-agentic-commerce-and-the-quiet-return-of-guest-checkout/): Agentic commerce is steadily rewiring how digital transactions occur. Instead of shoppers manually navigating screens, entering credentials and approving each step, intelligent software agents are beginning to select products, optimise pricing and initiate payment on the user’s behalf. - [WSJ: Out With the Old: Is Ending Passwords the Start of Improved Identity Security?](https://fidoalliance.org/wsj-out-with-the-old-is-ending-passwords-the-start-of-improved-identity-security/): From friction to fluidity: Why passkeys, biometrics, and magic links are poised to end the password era and increase privacy - [PCWorld: 1Password review: A password manager designed for the Apple crowd](https://fidoalliance.org/pcworld-1password-review-a-password-manager-designed-for-the-apple-crowd/): 1Password started as a macOS app, way back in 2006—and you can still feel that influence in its design. Even though the service now works across all major operating systems, the team still leans into a particular approach. This password manager is streamlined and runs smoothly, but users shouldn’t expect to see behind the veil. - [Passkey Ecosystem Upgrades and Improvements](https://fidoalliance.org/passkey-ecosystem-upgrades-and-improvements/): As passkeys move rapidly from a promising new technology to the clear industry standard for simple and secure authentication, the passkey ecosystem continues to evolve. Read about six new capabilities implementers should know about. - [MIXI Promotes a “Safe and Seamless Login Experience” with Passkey Deployment Across Both Consumer and Enterprise Environments](https://fidoalliance.org/mixi-promotes-a-safe-and-seamless-login-experience-with-passkey-deployment-across-both-consumer-and-enterprise-environments/): MIXI, Inc. (hereafter MIXI) is one of Japan’s leading internet companies, best known for its popular mobile game MONSTER STRIKE, among other entertainment services, with tens of millions of users. The company has also expanded into sports and lifestyle businesses, providing services that enrich the daily lives of a broad range of generations. - [Security Boulevard: Driving Passwordless Adoption with FIDO and Biometric Authentication](https://fidoalliance.org/security-boulevard-driving-passwordless-adoption-with-fido-and-biometric-authentication/): For decades, passwords have been the default mechanism for securing digital access. They are deeply embedded in enterprise systems and workflows, yet they were never designed to withstand today’s threat landscape. - [Biometric Update: Maker builds FIDO2-compliant LionKey USB dongle for passwordless security](https://fidoalliance.org/biometric-update-maker-builds-fido2-compliant-lionkey-usb-dongle-for-passwordless-security/): With their fiddly and indirect nature, one-time passwords (OTPs) are a curse of modern life. They’re a security risk and outdated. Frustrated, a maker has built a physical security key that’s compliant with FIDO2. - [Cybersecurity Market: Bitwarden Doubles Down on Identity Security as Passwords Finally Start to Lose Their Grip](https://fidoalliance.org/cybersecurity-market-bitwarden-doubles-down-on-identity-security-as-passwords-finally-start-to-lose-their-grip/): Bitwarden’s latest round of product updates reads less like a feature dump and more like a quiet assertion that identity security is finally maturing into something operational, measurable, and—crucially—fixable. Long positioned as an open, zero-knowledge alternative in the password manager market, Bitwarden is now pushing beyond storage and toward decision-making: seeing credential risk clearly, prioritizing it intelligently, and nudging humans toward action without turning security into another productivity tax. That shift matters. Credential abuse remains the front door for most breaches, yet remediation still drags, stalled by poor visibility and employee friction. Bitwarden Access Intelligence, now generally available, tackles that gap head-on by mapping weak, reused, or exposed credentials directly to business-critical applications, then guiding users through the correct update flows. Nine days to fix a known credential issue is an eternity in attacker time; collapsing that window is less glamorous than AI SOC slogans, but far more consequential. Even at the individual level, vault health alerts and password coaching quietly reinforce better hygiene where it actually happens—inside browsers and apps—addressing the stubborn reality that awareness alone doesn’t stop reuse, especially among younger users who already know the risks but still fall back on convenience. We’ve all been there, honestly. - [HID Global Blog: Understanding FIDO Alliance: Backbone of Passwordless Authentication](https://fidoalliance.org/hid-global-blog-understanding-fido-alliance-backbone-of-passwordless-authentication/): In today’s digital-first world, passwords are no longer enough. As phishing attacks and credential theft increase, enterprises require a secure, scalable and user-friendly method for authenticating users. That’s where the FIDO Alliance — a global consortium shaping the future of passwordless authentication — comes in. - [Corbado: Passkeys Japan: An Overview](https://fidoalliance.org/corbado-passkeys-japan-an-overview/): In 2025, Japan accelerated passkey adoption in response to evolving security challenges. Following a rise in unauthorized access incidents across the financial sector, regulators emphasized that "ID/password-only authentication and even email/SMS one-time passwords are not sufficient" and that stronger authentication methods like passkeys should be prioritized for high-risk financial actions. - [New Scientist: Passwords will be on the way out in 2026 as passkeys take over](https://fidoalliance.org/new-scientist-passwords-will-be-on-the-way-out-in-2026-as-passkeys-take-over/): Can you remember all your passwords off the top of your head? If so, you probably have too few of them – or, heaven forbid, only one that you use everywhere. But that problem could become a thing of the past in 2026. - [Biometric Update: NIST announces new mDL use case, resources to support financial sector adoption](https://fidoalliance.org/biometric-update-nist-announces-new-mdl-use-case-resources-to-support-financial-sector-adoption/): A webinar on mobile driver’s licenses (mDLs), presented by the National Cybersecurity Center of Excellence (NCCoE) at the National Institute of Standards and Technology (NIST), introduces new resources to help financial institutions implement support for mDLs. - [Cyber Insider: Telegram adds passkey support for secure frictionless logins](https://fidoalliance.org/cyber-insider-telegram-adds-passkey-support-for-secure-frictionless-logins/): Telegram has introduced support for passkeys in its latest update, marking a significant shift away from SMS-based login systems in favor of modern, phishing-resistant authentication methods. - [ZDNet: The coming AI agent crisis: Why Okta’s new security standard is a must-have for your business](https://fidoalliance.org/zdnet-the-coming-ai-agent-crisis-why-oktas-new-security-standard-is-a-must-have-for-your-business/): Counting Google, Amazon, and Microsoft among its early adopters, the new standard will provide organizations with more visibility and control over external applications. Here's how it works. - [Tech HQ: FIDO Alliance encourages adoption of digital credentials](https://fidoalliance.org/tech-hq-fido-alliance-encourages-adoption-of-digital-credentials/): The FIDO (Fast IDentity Online) Alliance has announced a new initiative designed to accelerate the adoption of verifiable digital credentials and identity wallets. Its undertaking hopes to let technology organisations build a trust-based ecosystem for digital identities, helping move the industry beyond the fragmented and sometimes incompatible solutions currently prevalent. Its initiative will provide a framework for best practice. - [American Banker: BankThink Banks need to adopt passkeys as a safer alternative to passwords](https://fidoalliance.org/american-banker-bankthink-banks-need-to-adopt-passkeys-as-a-safer-alternative-to-passwords/): By FIDO Alliance's Andrew Shikar - [Mobile ID World: FIDO Alliance Sharpens Passkey Trust With New Metadata Service Rules](https://fidoalliance.org/mobile-id-world-fido-alliance-sharpens-passkey-trust-with-new-metadata-service-rules/): The FIDO Alliance is tightening how relying parties evaluate passkeys and other FIDO authenticators, rolling out new versions of its Metadata Service (MDS) and a streamlined Convenience Metadata Service aimed at making it easier to separate trustworthy authenticators from outdated or non-compliant devices. The update is pitched as a way to raise assurance levels for passkey deployments without sacrificing user experience across mobile and desktop platforms. - [Biometric Update: FIDO Alliance broadens scope with new digital credentials work, deployments](https://fidoalliance.org/biometric-update-fido-alliance-broadens-scope-with-new-digital-credentials-work-deployments/): The FIDO Alliance is leveling up. Several announcements show the passwordless-focused organization evolving, as it expands beyond its initial push for passkeys to engage with the wider identity ecosystem. - [The Register: Death to one-time text codes: Passkeys are the new hotness in MFA](https://fidoalliance.org/the-register-death-to-one-time-text-codes-passkeys-are-the-new-hotness-in-mfa/): Whether you're logging into your bank, health insurance, or even your email, most services today do not live by passwords alone. Now commonplace, multifactor authentication (MFA) requires users to enter a second or third proof of identity. However, not all forms of MFA are created equal, and the one-time passwords orgs send to your phone have holes so big you could drive a truck through them. - [Recap: FIDO Taipei Seminar 2025 – Welcome to Passkey World](https://fidoalliance.org/recap-fido-taipei-seminar-2025-welcome-to-passkey-world/): On December 2nd, 2025, the digital identity community gathered in Taipei for the FIDO Taipei Seminar 2025. Under the theme "Welcome to Passkey World," the event brought together around 300 CISOs, business leaders, government officials, and identity architects to discuss the accelerating global shift away from passwords and the rapid adoption of phishing-resistant authentication across the Asia-Pacific region. - [Passkeys Week 2025: The Resources, Talks, and Success Stories](https://fidoalliance.org/passkeys-week-2025-the-resources-talks-and-success-stories/): In November we took part in Passkeys Week, an industry-wide campaign to accelerate the adoption of passkeys and encourage developers to build passkey support into their apps, websites, and authentication products. - [Dark Reading: Enterprise FIDO Authentication: An Easy, 3-Step Plan](https://fidoalliance.org/dark-reading-enterprise-fido-authentication-an-easy-3-step-plan/): Enterprise passkey adoption has reached a tipping point. According to new data from HID and the FIDO Alliance, two-thirds of executives believe that passkey deployment is a high or critical priority, and 87% have either successfully deployed or are currently deploying passkeys. - [ID TECH: FIDO Alliance Tightens Authenticator Verification with Metadata Service Update](https://fidoalliance.org/id-tech-fido-alliance-tightens-authenticator-verification-with-metadata-service-update/): The FIDO Alliance has released a major update to its Metadata Service (MDS) that is intended to improve how relying parties vet passkey and FIDO authenticator devices, with a particular focus on compliance, security assurance, and user experience. In a news post announcing the changes, FIDO describes the new MDS v3.1 and v3.1.1 releases, along with a new Convenience Metadata Service, as a critical step in supporting the continued evolution of the FIDO ecosystem. - [CNET Japan: FIDO Alliance Launches New Initiative to Accelerate Passkey Adoption, Next Up: Digital Credentials](https://fidoalliance.org/cnet-japan-fido-alliance-launches-new-initiative-to-accelerate-passkey-adoption/): At a meeting held in Tokyo on December 5th, the FIDO Alliance explained the current status of the adoption of "Passkey Authentication (FIDO2)" and announced that as a new initiative, it aims to realize a secure and convenient digital wallet that stores digital credentials. - [FIDO Alliance Launches New Digital Credentials Initiative to Accelerate and Secure an Interoperable Digital Identity Ecosystem](https://fidoalliance.org/fido-alliance-launches-new-digital-credentials-initiative-to-accelerate-and-secure-an-interoperable-digital-identity-ecosystem/): New Digital Credentials Working Group to work with global FIDO Alliance members and industry partners to align digital identity ecosystem  - [ID TECH: FIDO Alliance Brings Authenticate Conference to Asia-Pacific With Singapore Event Focused on Passkeys and Digital Credentials](https://fidoalliance.org/id-tech-fido-alliance-brings-authenticate-conference-to-asia-pacific-with-singapore-event-focused-on-passkeys-and-digital-credentials/): The FIDO Alliance is expanding its flagship Authenticate conference series to the Asia-Pacific region with Authenticate APAC 2026, a two-day event in Singapore dedicated to phishing-resistant authentication and digital identity. The conference will be held June 2 to 3, 2026 at the Grand Hyatt Singapore, followed by a FIDO Member Plenary from June 4 to 5 at the same venue. - [Enhancing Compliance and User Experience with Major Updates to the FIDO Metadata Service](https://fidoalliance.org/enhancing-compliance-and-user-experience-with-major-updates-to-the-fido-metadata-service/): We’re excited to announce updates to the FIDO Metadata Service (MDS), which helps ensure organizations have the information necessary to successfully validate authenticators. As organizations deploy passkeys and FIDO authentication, it is critical to validate trusted, certified authenticators. - [Passkeys Week Webinar: Ask Us Anything!](https://fidoalliance.org/passkeys-week-webinar-ask-us-anything/): As part of Passkeys Week, which took place on November 17 - 21, 2025, FIDO Alliance hosted a live, interactive Ask Us Anything (AMA) session designed for developers, product managers, and anyone building—or buying—authentication products and services. Attendees were able to bring their questions about passkey implementation, UX, security, standards, and ecosystem adoption directly to the experts shaping the industry. - [Biometric Update: Regulatory clarification sets stage for major FIDO biometrics uptake in South Korea](https://fidoalliance.org/biometric-update-regulatory-clarification-sets-stage-for-major-fido-biometrics-uptake-in-south-korea-2/): South Korea has eliminated a significant barrier to the usage of the FIDO protocol for passwordless authentication by confirming that it falls outside the scope of a requirement for user consent to process biometrics. - [Recap of the FIDO Alliance Korea Working Group Workshop](https://fidoalliance.org/recap-of-the-fido-alliance-korea-working-group-workshop/): The FIDO Alliance Korea Working Group (FKWG) held its year-end workshop on November 14, 2025, at the Telecommunications Technology Association (TTA) office in Pangyo. Co-hosted by Samsung Electronics and TTA, the workshop brought together local FIDO members and invited guests to discuss the latest developments in passkey deployment, biometric authentication, and the accelerating momentum behind phishing-resistant authentication across the country. - [FIDO Alliance Announces First Authenticate Conference for the Asia-Pacific Region](https://fidoalliance.org/fido-alliance-announces-first-authenticate-conference-for-the-asia-pacific-region/): The industry’s premier event dedicated to digital identity and authentication expands globally with Authenticate APAC 2026 in Singapore - [Financial IT: HYPR and Yubico deepen partnership to secure and scale passkey deployment through automated identity verification](https://fidoalliance.org/financial-it-hypr-and-yubico-deepen-partnership-to-secure-and-scale-passkey-deployment-through-automated-identity-verification/): For years, HYPR and Yubico have stood shoulder to shoulder in the mission to eliminate passwords and improve identity security. Yubico’s early and sustained push for FIDO-certified hardware authenticators and HYPR’s leadership as part of the FIDO Alliance mission to reduce the world’s reliance on passwords have brought employees and customers alike into the era of modern authentication. - [Biometric Update: Regulatory clarification sets stage for major FIDO biometrics uptake in South Korea](https://fidoalliance.org/biometric-update-regulatory-clarification-sets-stage-for-major-fido-biometrics-uptake-in-south-korea/): South Korea has eliminated a significant barrier to the usage of the FIDO protocol for passwordless authentication by confirming that it falls outside the scope of a requirement for user consent to process biometrics. - [Cyber Insider: Bitwarden brings passkey login support to Chrome extension](https://fidoalliance.org/cyber-insider-bitwarden-brings-passkey-login-support-to-chrome-extension/): Bitwarden has rolled out support for passwordless login via passkeys across its browser extensions and web vault, allowing users to authenticate without entering a username, password, or two-factor code. - [WebProNews: Passkeys Rise as Black Friday’s Fraud Shield](https://fidoalliance.org/webpronews-passkeys-rise-as-black-fridays-fraud-shield/): As Black Friday 2025 approaches, passwords remain digital security's weak link, exploited by AI-driven scams. Dashlane CEO John Bennett champions passkeys for frictionless, phishing-resistant authentication, with e-commerce leaders like Amazon leading adoption. Dashlane's tools and deals bolster fraud protection for shoppers and businesses. - [IDAC Podcast: The FIDO Alliance’s Next Frontier: Digital Credentials and Wallets](https://fidoalliance.org/idac-podcast-the-fido-alliances-next-frontier-digital-credentials-and-wallets/): Live from Authenticate 2025, Jeff Steadman and Jim McDonald sit down with the Cal Ripken of IDAC, Andrew Shikiar, Executive Director and CEO of the FIDO Alliance. Andrew shares exciting updates on the incredible progress of Passkeys, revealing that over 3 billion are now in use securing accounts. We discuss the key themes of the conference, including the ongoing arms race with AI in security and the critical role of identity verification. Andrew also unveils the new Passkey Index, an initiative to provide industry benchmarks for deployment success. Looking ahead, the conversation shifts to the FIDO Alliance's broadening focus on digital credentials and wallets, aiming to solve the usability and certification challenges that have held the space back. Finally, we hear about the global expansion of the Authenticate conference brand, with a new event launching in Singapore. - [Beyond the Protocol: The Human-Centered Shift Defining the Future of Workforce Security](https://fidoalliance.org/beyond-the-protocol-the-human-centered-shift-defining-the-future-of-workforce-security/): By FIDO Alliance UX Working Group’s Enterprise Subgroup leaders Patryk Les, Yubico and Philip Corriveau, RSA - [Pocket-lint: Windows 11 is about to work way better with passkeys](https://fidoalliance.org/pocket-lint-windows-11-is-about-to-work-way-better-with-passkeys/): It's no secret that Microsoft is on board with ushering in a fully passwordless computing future -- specifically one that's powered by a newfangled technology known as passkeys. Back in June, the tech giant confirmed its intention to bring so-called plugin passkey provider integration to Windows 11 in a future update, and, as of the recently-released November 2025 security update, the functionality is now live for a growing number of PC users running the latest version of the operating system. - [9TO5Mac: Apple @ Work Podcast: State of the union for passkeys](https://fidoalliance.org/9to5mac-apple-work-podcast-state-of-the-union-for-passkeys-2/): In this episode of Apple @ Work, Rew Islam from Dashlane joins the show to talk about the company’s new report: The 2025 Dashlane Passkey Power 20. - [9TO5Mac: Apple @ Work Podcast: State of the union for passkeys](https://fidoalliance.org/9to5mac-apple-work-podcast-state-of-the-union-for-passkeys/): In this episode of Apple @ Work, Rew Islam from Dashlane joins the show to talk about the company’s new report: The 2025 Dashlane Passkey Power 20. - [Security Boulevard: HYPR and Yubico Deepen Partnership to Secure and Scale Passkey Deployment Through Automated Identity Verification](https://fidoalliance.org/security-boulevard-hypr-and-yubico-deepen-partnership-to-secure-and-scale-passkey-deployment-through-automated-identity-verification/): For years, HYPR and Yubico have stood shoulder to shoulder in the mission to eliminate passwords and improve identity security. Yubico’s early and sustained push for FIDO-certified hardware authenticators and HYPR’s leadership as part of the FIDO Alliance mission to reduce the world’s reliance on passwords have brought employees and customers alike into the era of modern authentication. - [Digital Trends: Windows 11 finally lets you use Passkeys through your own password manager](https://fidoalliance.org/digital-trends-windows-11-finally-lets-you-use-passkeys-through-your-own-password-manager/): Microsoft is making Windows 11 a lot friendlier to your favorite password manager. Windows 11 now supports third-party passkey managers, meaning you’re not locked into Microsoft Password Manager anymore. - [WinBuzzer: Microsoft Edge Now Syncs Passkeys Across Windows Devices, Bolstering Passwordless Push](https://fidoalliance.org/winbuzzer-microsoft-edge-now-syncs-passkeys-across-windows-devices-bolstering-passwordless-push/): Microsoft is rolling out a significant update to its Edge browser that allows users to save and sync passkeys across their Windows devices. Announced on November 3, the new feature integrates passkeys directly into the Microsoft Password Manager, starting with Edge version 142. - [Biometric Update: iProov certified for biometric deepfake protection with Ingenium IAD test](https://fidoalliance.org/biometric-update-iproov-certified-for-biometric-deepfake-protection-with-ingenium-iad-test/): iProov’s biometric injection attack detection technology has passed an evaluation by Ingenium Biometrics to the Level 2 (High) standard set out in Europe’s CEN TS 18099. - [WebProNews: WhatsApp Rolls Out Biometric Passkeys for Encrypted Chat Backups](https://fidoalliance.org/webpronews-whatsapp-rolls-out-biometric-passkeys-for-encrypted-chat-backups/): WhatsApp has introduced passkey-encrypted chat backups using biometric authentication like Touch ID or Face ID, simplifying end-to-end encryption and replacing cumbersome 64-digit keys. This enhances security for cloud-stored messages amid rising cyber threats, potentially setting a new standard for messaging apps and promoting broader privacy adoption. - [Biometric Update: New benchmarking tool shows passkeys boost conversion success by 30%](https://fidoalliance.org/biometric-update-new-benchmarking-tool-shows-passkeys-boost-conversion-success-by-30/): FIDO Alliance and Liminal collaborate on utilization snapshot - [Forbes: Cybersecurity Is A Digital Identity Problem And We Must Deal With It](https://fidoalliance.org/forbes-cybersecurity-is-a-digital-identity-problem-and-we-must-deal-with-it/): One particular leaf of that nettle is authentication, and here I think we Brits can have some optimism. NCSC is working with the government and the FIDO Alliance on improving the adoption of “passkeys" across the public and private sectors. If you are not familiar with passkeys (which are already widely used), imagine you want to sign in to your Google Account on a new device. Instead of entering a password, a passkey allows you to log in to your account with a device you’ve already verified (e.g., your phone). You don't need to remember a password and no-one else can log in as you because they don’t have your phone. - [Biometric Update: Passkeys mature to occupy critical role in authentication for digital ID systems](https://fidoalliance.org/biometric-update-passkeys-mature-to-occupy-critical-role-in-authentication-for-digital-id-systems/): The passkey tipping point may be fast approaching. As the anointed successor to passwords, passkeys are seeing increased support from huge global companies, improved data analysis and better resources. And, significantly from an industry standpoint, the FIDO Alliance appears to be on the verge of reorienting its priorities to encompass more work on account recovery and digital credentials – a sure sign that, even if passkeys do not deliver the fatal blow to passwords many have predicted, they are established enough for their primary defender to declare a kind of victory in its primary mission. - [Mastercard Cybersecurity Blog: Reimagining online authentication to outfox AI-powered cyber scammers](https://fidoalliance.org/mastercard-cybersecurity-blog-reimagining-online-authentication-to-outfox-ai-powered-cyber-scammers/): The Mastercard Newsroom recently sat down with Andrew Shikiar, FIDO’s Executive Director and CEO, to learn how the FIDO's Payments Working Group is helping bolster protection in a rapidly changing digital world. - [WUSA: Why you should consider passkeys instead of passwords for online safety](https://fidoalliance.org/wusa-why-you-should-consider-passkeys-instead-of-passwords-for-online-safety/): Andrew Shikiar, Executive Director and CEO of the FIDO Alliance tells us why passkeys are superior to passwords for online safety. The simple step to protect yourself online is to upgrade to passkeys. - [PC Mag: Passkey Adoption Sees Striking Progress, With One Obvious Leader](https://fidoalliance.org/pc-mag-passkey-adoption-sees-striking-progress-with-one-obvious-leader/): Things really have improved, according to a new Dashlane study, and yet we’re sure that many of the sites you use all the time have yet to get the memo about passkeys. - [Member Report: The 2025 Dashlane Passkey Power 20](https://fidoalliance.org/member-report-the-2025-dashlane-passkey-power-20/): Despite years of warnings from security experts, passwords remain the Achilles' heel of digital security. According to Dashlane data, the average person now manages 301 passwords across their personal and work accounts. Yet, credential abuse remains the most common initial attack vector.1 For CISOs and IT leaders, the problem is clear: The authentication method designed to protect users has become their greatest liability. - [FIDO Webinar: Designing Passkeys for Everyone: Making Strong Authentication Simple at Scale](https://fidoalliance.org/fido-webinar-designing-passkeys-for-everyone-making-strong-authentication-simple-at-scale/): Attendees joined this webcast to hear from members of the FIDO Alliance’s UX Working Group explore the critical UX considerations in designing and deploying passkeys at scale, from initial user onboarding to seamless cross-device synchronization.  - [MobileIDWorld: Google Chrome Launches Automatic Passkey Generation for Android Users](https://fidoalliance.org/mobileidworld-google-chrome-launches-automatic-passkey-generation-for-android-users/): Google Chrome has introduced a new automatic passkey implementation for Android that streamlines the user authentication process by automatically generating passkeys after password-based sign-ins. The development marks a significant advancement in the broader industry transition from traditional passwords to more secure authentication methods, following similar initiatives from Apple and Microsoft. - [Biometric Update: BixeLab joins FIDO Face Verification program, certifies Aware ](https://fidoalliance.org/biometric-update-bixelab-joins-fido-face-verification-program-certifies-aware/): Aware has received FIDO Alliance Certification for Face Verification, gaining recognition for its identity verification tech including liveness detection and facial matching capabilities. - [Biometric Update: HID upgrades passkey, FIDO authentication capabilities with IDmelon acquisition](https://fidoalliance.org/biometric-update-hid-upgrades-passkey-fido-authentication-capabilities-with-idmelon-acquisition/): Texas-based HID has reached an agreement to acquire Vancouver, Canada-based logical access control provider IDmelon to upgrade its portfolio of FIDO authentication offerings. The addition of IDmelon’s technology enables HID to easily implement customers’ physical access cards and mobile devices as FIDO2 security keys, according to the joint announcement. - [Techstination Radio/Podcast: What you should know about passkeys for online security](https://fidoalliance.org/techstination-what-you-should-know-about-passkeys-for-online-security/): Interview with FIDO's Andrew Shikiar on what you should know about passkeys for online security. - [WDEF News: Switching to Passkeys for Safety](https://fidoalliance.org/wdef-news-switching-to-passkeys-for-safety/): CHATTANOOGA, Tenn. (WDEF) – October is Cybersecurity Month, a reminder for everyone to take small but meaningful steps to stay safe online.  - [WTVM News: FIDO’s Megan Shamas talks online safety, using passkeys](https://fidoalliance.org/wtvm-interview-fidos-megan-shamas-talks-online-safety-using-passkeys/): Megan Shamas, CMO of the FIDO Alliance shares why passkeys may be more effective than passwords during Cybersecurity Month. - [Authenticate 2025: Day 3 Recap](https://fidoalliance.org/authenticate-2025-day-3-recap/): By: FIDO staff - [Authenticate 2025: Day 2 Recap](https://fidoalliance.org/authenticate-2025-day-2-recap/): By: FIDO Staff - [Best Stablecoin Wallets for Everyday Use in 2025](https://fidoalliance.org/best-stablecoin-wallets-for-everyday-use-in-2025/): The rise of stablecoins has transformed how we handle digital payments, cross-border transactions, and everyday financial activities in the cryptocurrency ecosystem. With stablecoins like USDT, USDC, and DAI gaining mainstream adoption, choosing the right stablecoin wallet has become crucial for anyone looking to navigate the digital economy efficiently. What makes walllet.com revolutionary is its seedless security approach. Unlike conventional wallets that require users to manage complex 12 or 24-word seed phrases, walllet.com uses institutional-grade biometric security powered by proven technologies from Apple, Google, and the FIDO alliance.  - [Authenticate 2025: Day 1 Recap](https://fidoalliance.org/authenticate-2025-day-1-recap/): By FIDO staff - [FIDO Alliance Launches Passkey Index, Revealing Significant Passkey Uptake and Business Benefits](https://fidoalliance.org/fido-alliance-launches-passkey-index-revealing-significant-passkey-uptake-and-business-benefits/): Passkey Index provides a composite view of passkey utilization and business impact data from leading online service providers - [Six Months of Passkey Pledge Progress](https://fidoalliance.org/six-months-of-passkey-pledge-progress/): In April we invited organizations around the world to take the Passkey Pledge, a voluntary commitment to increase awareness and adoption of passkey sign-ins to make the web safer and more accessible. - [Passkey Index 2025](https://fidoalliance.org/passkey-index-2025/): FIDO has launched the Passkey Index, which provides a composite view of data from leading service providers - including Amazon, Google, LY Corporation, Mercari Inc., Microsoft, NTT DOCOMO, PayPal, Target and TikTok - on the adoption, utilization and business impacts of passkeys. It reveals significant passkey uptake and benefits for online services offering passkey sign-ins. Read the full report here. - [White Paper: FIDO and the Shared Signals Framework](https://fidoalliance.org/white-paper-fido-and-the-shared-signals-framework/): Thank you for your patience as we draft version 2 of FIDO and the Shared Signals Framework. - [Biometric Update: Germany pushes passkey adoption, releases draft technical guidelines](https://fidoalliance.org/biometric-update-germany-pushes-passkey-adoption-releases-draft-technical-guidelines/): Germany’s Federal Office for Information Security (BSI) is asking for public comment on a draft document that outlines technical considerations for configuring passkey servers. - [Biometric Update: Yubico finds passkeys awareness still lacking in global survey](https://fidoalliance.org/biometric-update-yubico-finds-passkeys-awareness-still-lacking-in-global-survey/): There is a persistent disconnect between perceived cybersecurity and actual vulnerability. That’s the key finding from Yubico’s 2025 Global State of Authentication Survey. The findings indicate a world still reliant on outdated authentication practices, highlighting the need to align personal and workplace cyber hygiene. - [PC Mag: Ditch Your Passwords: Why Passkeys Are the Future of Online Security](https://fidoalliance.org/pc-mag-ditch-your-passwords-why-passkeys-are-the-future-of-online-security/): Passkeys are revolutionizing the way we secure our online accounts, with the potential to eliminate passwords altogether. We explain why they offer stronger protection for your digital life and how you can start using them. - [IT Brief: Help desks emerge as cybersecurity weak spot amid rising attacks ](https://fidoalliance.org/it-brief-help-desks-emerge-as-cybersecurity-weak-spot-amid-rising-attacks/): Bojan Simic, Chief Executive of HYPR and a FIDO Alliance board member, warns that IT help desks are increasingly targeted by attackers using social engineering tactics. These tactics often involve leveraging stressful scenarios, such as an executive locked out of their account just before boarding a flight, to pressure help desk agents into bypassing or overlooking security protocols. "The help desk shouldn't be the weakest link; it should be the first line of defence. That means moving beyond guesswork and adopting identity verification that confirms who someone is, versus what they know or the device they're using. With phishing-resistant, standards-based verification built into support workflows, agents stop being human lie detectors and start being defenders," said Simic.  - [IDAC Podcast: Going Passkey Phishing with Nishant Kaushik, FIDO Alliance](https://fidoalliance.org/idac-podcast-going-passkey-phishing-with-nishant-kaushik-fido-alliance/): In this episode of the Identity at the Center podcast, Jeff and Jim discuss various aspects of identity access management (IAM) policies and the importance of having a solid foundation. They emphasize the need for automation, controls, and how IAM policies should be created without technology limitations in mind. The discussion also covers the implementation challenges and the evolving concept of identity verification. Jeff, Jim, and their guest, Nishant Kaushik, the new CTO at the FIDO Alliance, also delve into the issues surrounding the adoption of passkeys, highlighted by Rusty Deaton’s IDPro article, and address some common concerns about their security. Nishant offers insights into ongoing work at FIDO Alliance, the potential of digital identity, and the importance of community in the identity sector. The episode concludes with mentions of upcoming conferences and an homage to the late identity expert, Andrew Nash. - [Ideem: Q/A with Andrew Shikiar, CEO of FIDO](https://fidoalliance.org/ideem-qa-with-andrew-shikiar-ceo-of-fido/): We had the pleasure of sitting down with Andrew Shikiar, CEO of the FIDO Alliance known for their creation and evangelism of the Passkey the authentication method we've all come to know and love. The team here at Ideem, is of course huge fans of the passkey and what it has done to revolutionize how people authenticate themselves and were honored that Andrew took the time to answer all of our questions about passkeys and banking. That Q&A is below. Of course if you're interested in learning more about how Ideem is making passkeys bank-grade you can learn more at our site. - [First Credit Union: Transforming Digital Banking with Passkeys](https://fidoalliance.org/first-credit-union-transforming-digital-banking-with-passkeys/): Founded in 1955, First Credit Union is a member-owned financial institution in New Zealand with over 60,000 members. The organization delivers secure and innovative digital banking experiences through its comprehensive online banking platform. Members access their accounts via mobile app and browser options to manage finances anytime, anywhere. The credit union has embraced cutting-edge authentication technology to enhance both security and user experience for its diverse membership base. - [TechGenyz: Password-Free Future: How Biometrics & Passkeys Unlock True Security ](https://fidoalliance.org/techgenyz-password-free-future-how-biometrics-passkeys-unlock-true-security/): While biometrics offer convenience, passkeys provide the backbone for the next stage in authentication. Developed as a part of a global effort by Apple, Google, Microsoft, and the FIDO Alliance, passkeys replace traditional passwords with cryptographic keys stored securely on a user’s device. Instead of typing in a word or a phrase, users can confirm their identity through a fingerprint, a face scan, or a prompt in a trusted device.  - [Forbes: The iPhone’s New Camera? Whatever. The iPhone’s New Wallet? Cool. ](https://fidoalliance.org/forbes-the-iphones-new-camera-whatever-the-iphones-new-wallet-cool/): Apple’s approach to identity in wallets is built on open standards, including the W3C’s Digital Credentials API and FIDO Alliance protocols. This is important to identity nerds like me because they are standards that enable privacy-enhancing exchanges of digital credentials, allowing consumers to (crucially) prove what they are (over 18, entitled to drive, holding a valid ticket) without having to divulge who they are.   - [Biometric Update: Bitwarden among first to implement FIDO credential exchange standards on iOS 26](https://fidoalliance.org/biometric-update-bitwarden-among-first-to-implement-fido-credential-exchange-standards-on-ios-26/): Apple iOS 26 has landed, and it includes support for FIDO Alliance Credential Exchange standards to enable secure, end-to-end encrypted transfers of passkeys, passwords and other credentials across platforms and apps. A release from large open-source login management service Bitwarden says it is “among the first credential managers on iOS 26 to implement the Credential Exchange standards, helping lead passkey and password portability with a secure, standardized way for users to move credentials between Apple Passwords, Bitwarden and other compatible services.”  - [Driving Automotive Innovation with FIDO Standards and Certification](https://fidoalliance.org/driving-automotive-innovation-with-fido-standards-and-certification/): Attendees joined this webcast to hear how FIDO Alliance standards and certification can support the automotive industry as it transitions toward software-defined vehicles, autonomous technologies, and connected services. This transition brings an unprecedented opportunity to innovate and capitalize on new business models (such as in-vehicle commerce and subscription services) but also introduces significant cybersecurity threats and user experience challenges.  - [Driving Automotive Innovation with FIDO Standards and Certification](https://fidoalliance.org/fido-webinar-driving-automotive-innovation-with-fido-standards-and-certification/): Attendees joined this webcast to hear how FIDO Alliance standards and certification can support the automotive industry as it transitions toward software-defined vehicles, autonomous technologies, and connected services. This transition brings an unprecedented opportunity to innovate and capitalize on new business models (such as in-vehicle commerce and subscription services) but also introduces significant cybersecurity threats and user experience challenges.  - [The Passkey Playbook | HID Global](https://fidoalliance.org/the-passkey-playbook-hid-global/): Explore how to deploy passwordless authentication at scale — securely, strategically and with minimal disruption. - [Podcast: The Passwordless Shift: Rethinking Identity for the Modern Enterprise](https://fidoalliance.org/podcast-the-passwordless-shift-rethinking-identity-for-the-modern-enterprise/): In the inaugural episode of Imprivata's new podcast, Access Point, hosts Joel Burleson-Davis and Chip Hughes sit down with Andrew Shikiar, CEO of the FIDO Alliance, to explore the global movement toward passwordless authentication. - [The Indian Express: ‘Password resets cost businesses more than they realise’: Zoho exec on ROI of going passwordless](https://fidoalliance.org/the-indian-express-password-resets-cost-businesses-more-than-they-realise-zoho-exec-on-roi-of-going-passwordless/): The world is rapidly moving away from traditional security methods. With FIDO standards in place, more companies are shifting toward passwordless authentication. Many industry players are already phasing out passwords from their authenticator apps. - [Biometric Update: To build trust in biometrics, Vietnam banks should adopt FIDO passkeys: report](https://fidoalliance.org/biometric-update-to-build-trust-in-biometrics-vietnam-banks-should-adopt-fido-passkeys-report/): VinCSS has released an industry first report on the authentication experience in apps for Vietnamese banks, and it shows a “strong shift from traditional to modern authentication methods” in the country’s banking ecosystem. - [Back End News: HID offers passwordless authentication to support BSP compliance](https://fidoalliance.org/back-end-news-hid-offers-passwordless-authentication-to-support-bsp-compliance/): HID, a company that provides secure identity solutions, announced the availability of its updated FIDO-certified authentication solutions in the Philippines, to help financial institutions and enterprises comply with the Bangko Sentral ng Pilipinas’ (BSP) new rules on IT risk management under the Anti-Financial Account Scamming Act (AFASA). - [Security Boulevard: Beyond Passwords: A Guide to Choosing the Right Passkey](https://fidoalliance.org/security-boulevard-beyond-passwords-a-guide-to-choosing-the-right-passkey/): For many market analysts, cybersecurity agencies and authentication experts, passkeys, based on FIDO2 standard protocol, appear as the future proof authentication technology that will become mainstream within the next years. - [White Paper: Passkeys and Verifiable Digital Credentials: A Harmonized Path to Secure Digital Identity](https://fidoalliance.org/passkeys-and-verifiable-digital-credentials-a-harmonized-path-to-secure-digital-identity/): Christine Owen, 1Kosmos Teresa Wu, IDEMIA Public Security - [PC Mag: Lose Your Device, Lose Your Accounts? Not If You Back Up Your Passkeys](https://fidoalliance.org/pc-mag-lose-your-device-lose-your-accounts-not-if-you-back-up-your-passkeys/): Passkeys are more secure than passwords since they're tied to a device, but what if you lose your phone? The trick lies in how you generate passkeys in the first place. - [Wired: How Passkeys Work—and How to Use Them](https://fidoalliance.org/wired-how-passkeys-work-and-how-to-use-them/): Passkeys want to create a password-free future. Here’s what they are and how you can start using them. - [Passkeys Are Not Broken. The Conversation About Them Often Is](https://fidoalliance.org/passkeys-are-not-broken-the-conversation-about-them-often-is/): Every few months, like clockwork, a talk or article appears claiming that new research has uncovered a “vulnerability” with passkeys.  This can understandably raise concern for executives and product leaders looking to uplift their authentication frameworks. But these reports have a pattern: they highlight opportunities for exploitation in the environment where passkeys are used, not any vulnerability in passkeys themselves. - [Dark Reading: NIST Digital Identity Guidelines Evolve with Threat Landscape](https://fidoalliance.org/dark-reading-nist-digital-identity-guidelines-evolve-with-threat-landscape/): In a bid to improve overall security of the identity ecosystem, the National Institute of Standards and Technology updated its Digital Identity Guidelines earlier this month. The first revision since 2017, many organizations should be able to implement the updated guidelines without much difficulty as part of their identity strategy. - [Research Snipers: Microsoft Authenticator Deletes All Stored Passwords, Pushes Users Toward Passkeys](https://fidoalliance.org/research-snipers-microsoft-authenticator-deletes-all-stored-passwords-pushes-users-toward-passkeys/): As announced, Microsoft today deletes all stored passwords from his authenticator app. Users have to secure their access data before they are lost permanently. Other functions of the app are preserved. - [Security.World: HID Unveils Next-Generation FIDO Hardware And Centralized Management At Scale](https://fidoalliance.org/hid-unveils-next-generation-fido-hardware-and-centralized-management-at-scale/): HID, a worldwide leader in trusted identity and access management solutions, has announced a new line of FIDO-certified credentials—now powered by the new Enterprise Passkey Management (EPM) solution— designed to help organizations deploy and manage passkeys at the enterprise scale.  - [GB News: Microsoft will start DELETING your passwords from today, and there’s only one way to save them](https://fidoalliance.org/gb-news-microsoft-will-start-deleting-your-passwords-from-today-and-theres-only-one-way-to-save-them/): Microsoft has started to delete all passwords saved in its Authenticator app — and if you want to make sure you're not locked-out of your favourite websites and apps, there's one way to save your previous logins. - [ZDNet: Syncable vs. non-syncable passkeys: Are roaming authenticators the best of both worlds?](https://fidoalliance.org/zdnet-syncable-vs-non-syncable-passkeys-are-roaming-authenticators-the-best-of-both-worlds/): Like or not, a replacement for passwords -- known as passkeys -- is coming your way, if it hasn't already. The three big ideas behind passkeys are that they cannot be guessed in the way passwords often can (and are), the same passkey cannot be re-used across different websites and apps (the way passwords can), and you cannot be tricked into divulging your passkeys to malicious actors, often through techniques such as phishing, smishing, quishing, and malvertising.  - [Intelligent CISO: HID unveils next-generation FIDO hardware and centralised management at scale](https://fidoalliance.org/intelligent-ciso-hid-unveils-next-generation-fido-hardware-and-centralised-management-at-scale-2/): HID, a leader in trusted identity and access management solutions, has announced a new line of FIDO-certified credentials – now powered by the new Enterprise Passkey Management (EPM) solution – designed to help organizations deploy and manage passkeys at the enterprise scale.  - [ZDNet: What if your passkey device is stolen? How to manage risk in our passwordless future](https://fidoalliance.org/zdnet-what-if-your-passkey-device-is-stolen-how-to-manage-risk-in-our-passwordless-future/): Part of the "passkeys are more secure than passwords" story is derived from the fact that passkeys are non-human-readable secrets -- stored somewhere on your device -- that even you have very limited access to.  - [Intelligent CISO: HID unveils next-generation FIDO hardware and centralised management at scale](https://fidoalliance.org/intelligent-ciso-hid-unveils-next-generation-fido-hardware-and-centralised-management-at-scale/): HID, a leader in trusted identity and access management solutions, has announced a new line of FIDO-certified credentials – now powered by the new Enterprise Passkey Management (EPM) solution – designed to help organizations deploy and manage passkeys at the enterprise scale.  - [MobileIDWorld: Google Chrome Enhances Security with Mandatory Biometric Authentication for Password Autofill](https://fidoalliance.org/mobileidworld-google-chrome-enhances-security-with-mandatory-biometric-authentication-for-password-autofill/): Google has implemented significant enhancements to biometric authentication and security features in Chrome and Google Workspace, marking the latest step in the company’s broader push toward stronger authentication methods. These updates build upon previous Chrome security improvements while addressing critical vulnerabilities in desktop password management. - [9to5Mac: Apple @ Work: Passkey portability is finally here in iOS 26 and macOS Tahoe 26](https://fidoalliance.org/9to5mac-apple-work-passkey-portability-is-finally-here-in-ios-26-and-macos-tahoe-26/): With iOS 26 and macOS Tahoe 26, Apple is solving a key problem, though For the first time, Apple is adding support for true passkey portability. This means you can move your credentials from Apple Passwords to a dedicated password manager like 1Password, Dashlane, or Bitwarden, and even move them back. The system handles the transfer securely and locally, so you don’t have to worry about exporting plaint text CSV files and crossing your fingers that nothing gets exposed. - [Reddit Implements Mandatory ID Verification for UK Users Under Online Safety Act](https://fidoalliance.org/reddit-implements-mandatory-id-verification-for-uk-users-under-online-safety-act/): Reddit has implemented mandatory age verification for UK users to comply with the country’s Online Safety Act, which took effect in July 2025. The legislation requires digital platforms to prevent minors from accessing unsafe content, particularly mature or adult material, following Ofcom’s broader push for stricter online age verification across digital platforms. - [White Paper: Addressing Cybersecurity Challenges in the Automotive Industry](https://fidoalliance.org/white-paper-addressing-cybersecurity-challenges-in-the-automotive-industry/): Abstract - [National World: 16 billion passwords leaked: How to protect yourself as cybersecurity experts warn of repeat attacks](https://fidoalliance.org/national-world-16-billion-passwords-leaked-how-to-protect-yourself-as-cybersecurity-experts-warn-of-repeat-attacks/): Cybersecurity experts are urging internet users to take immediate steps to secure their online accounts, after largest-ever data leak exposed more than 16 billion login credentials including from major platforms like Google, Facebook, Apple, and even government services. - [ZD NET: How passkeys work: Your passwordless journey begins here](https://fidoalliance.org/zd-net-how-passkeys-work-your-passwordless-journey-begins-here/): Over the last few decades, compromised usernames and passwords have typically been at the root of some of the most sensational, damaging, and costly data breaches. An incessant drumbeat of advice about how to choose and use strong passwords and how not to fall prey to social engineering attacks has done little to keep threat actors at bay.  - [MobileIDWorld: Meta Rolls Out Passkey Authentication for Facebook Mobile Users Globally](https://fidoalliance.org/mobileidworld-meta-rolls-out-passkey-authentication-for-facebook-mobile-users-globally/): Meta has begun rolling out passkey login authentication for Facebook users on iOS and Android mobile devices, marking a significant advancement in the industry-wide movement away from traditional password-based security. The implementation follows similar moves by tech giants Apple, Google, and Microsoft who have been leading the charge toward passwordless authentication. - [The Hacker News: Microsoft Removes Password Management from Authenticator App Starting August 2025](https://fidoalliance.org/the-hacker-news-microsoft-removes-password-management-from-authenticator-app-starting-august-2025/): Microsoft has said that it's ending support for passwords in its Authenticator app starting August 1, 2025. - [PCmag: This Password Manager Now Lets You Create an Account Without a Password](https://fidoalliance.org/pcmag-this-password-manager-now-lets-you-create-an-account-without-a-password-2/): Dashlane lets you open an account with a FIDO2-spec USB security key as your authentication. - [ZDNET: Facebook’s new passkey support could soon let you ditch your password forever](https://fidoalliance.org/zdnet-facebooks-new-passkey-support-could-soon-let-you-ditch-your-password-forever/): For all of us who hate passwords, passkeys represent a simpler and safer way of authenticating online accounts. But adoption has been slow, with many companies and websites still relying on passwords. Now the world's biggest social media platform is jumping on the bandwagon. - [Expert Insights Podcast: #64 – Passwordless Authentication and the Rise of Passkeys](https://fidoalliance.org/expert-insights-podcast-64-passwordless-authentication-and-the-rise-of-passkeys/): Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, joins us to discuss the shift from passwords to passkeys and the role of FIDO in driving secure, passwordless authentication. He explores the challenges of adoption, the importance of identity verification, and how cross-platform interoperability is accelerating passkey use. The conversation also touches on the impact of generative AI on cybersecurity and what the future holds for passkeys in building long-term resilience. - [Ars Technica: Coming to Apple OSes: A seamless, secure way to import and export passkeys](https://fidoalliance.org/ars-technica-coming-to-apple-oses-a-seamless-secure-way-to-import-and-export-passkeys-2/): Apple this week provided a glimpse into a feature that solves one of the biggest drawbacks of passkeys, the industry-wide standard for website and app authentication that isn't susceptible to credential phishing and other attacks targeting passwords. - [Blog: 2025 FIDO India Working Group Member Meetup and Workshop](https://fidoalliance.org/blog-fido-india-working-group-member-meetup-and-workshop/): The FIDO Alliance hosted its annual India Working Group (FIWG) Member Meetup & Workshop on June 6, 2025, at Google’s Ananta campus in Bengaluru. With over 100 attendees representing leading technology companies, financial service providers, telecom operators, government agencies, retailers, and platform providers, the event served as an important forum for advancing phishing-resistant, passwordless authentication efforts in India. - [MobileIDWorld: Apple Introduces Cross-Platform Passkey Import/Export Features Across Operating Systems](https://fidoalliance.org/mobileidworld-apple-introduces-cross-platform-passkey-import-export-features-across-operating-systems/): Apple has announced significant enhancements to its operating systems that will implement secure import and export capabilities for passkeys, building on the company’s ongoing efforts to eliminate traditional passwords. The new features match standards developed by the FIDO Alliance for cross-platform credential management, joining similar initiatives from Microsoft and Google in the push toward passwordless authentication. - [Techopedia: FIDO2 & Passkeys: The Future of Passwordless Authentication](https://fidoalliance.org/techopedia-fido2-passkeys-the-future-of-passwordless-authentication/): Passwordless authentication has picked up in recent years. But the method drawing the most interest in security circles is physical security keys based on the FIDO2 standard. - [asmag Security & IoT: Passwordless authentication: From trend to ‘strategic imperative’](https://fidoalliance.org/asmag-security-iot-passwordless-authentication-from-trend-to-strategic-imperative/): For modern IT or Internet users, logging in to a website or app using a password is all too familiar. Increasingly, however, passwords create security concerns as they can be easily cracked or stolen. This is where passwordless authentication provides a more secure and convenient alternative. - [Meta Newsroom: Introducing Passkeys on Facebook for an Easier Sign-In](https://fidoalliance.org/meta-newsroom-introducing-passkeys-on-facebook-for-an-easier-sign-in/): We’re introducing passkeys on Facebook for mobile devices, offering another tool to safeguard your privacy and security. Passkeys are a new way to verify your identity and log in to your account that’s easier and more secure than traditional passwords.  - [FIDO Alliance Releases Authenticate 2025 Agenda](https://fidoalliance.org/fido-alliance-releases-authenticate-2025-agenda/): Carlsbad, Calif., June 18, 2025 – The FIDO Alliance has announced the agenda for Authenticate 2025, the only industry conference dedicated to digital identity and authentication with a focus on phishing-resistant sign-ins with passkeys. The event will take place October 13–15, 2025 at the Omni La Costa Resort and Spa in Carlsbad, Calif., with options for virtual participation available. - [MSN: Google Pushes 2 Billion Gmail Users to Adopt Passkeys Over Passwords](https://fidoalliance.org/msn-google-pushes-2-billion-gmail-users-to-adopt-passkeys-over-passwords/): Google is making its biggest security push yet. The company strongly urges its 2 billion Gmail users to switch passwords to passkeys. While not mandating immediate changes, Google has made passkeys the default authentication method. They’ve also set a hard deadline for third-party apps. The FBI reported cyber attacks jumped 33% last year. Those attacks cost over $16 billion in damages. Google’s response shows how seriously Big Tech is taking the password problem affecting every internet user. - [MSSP Alert: authID Integrates with Ping to Spread Passwordless Authentication](https://fidoalliance.org/mssp-alert-authid-integrates-with-ping-to-spread-passwordless-authentication/): authID’s decision this month to integrate its biometric identity verification technology with Ping Identity’s PingOne DaVinci service is a necessary step at a time when humans continue to be the weakest security link for organizations and bad actors increasingly target passwords to gain access to corporate networks, according to Jeff Scheidel, vice president of operations for the Denver-based company. - [Ars Technica: Coming to Apple OSes: A seamless, secure way to import and export passkeys](https://fidoalliance.org/ars-technica-coming-to-apple-oses-a-seamless-secure-way-to-import-and-export-passkeys/): Apple OSes will soon transfer passkeys seamlessly and securely across platforms. - [FIDO Seminar: Authentication, Identity and the Road Ahead](https://fidoalliance.org/fido-seminar-presentations-authentication-identity-the-road-ahead/): The FIDO Alliance and host sponsor Thales recently held a one day seminar on authentication, identity and the road ahead. - [Passwordless Authentication and the Rise of Passkeys: Expert Insights Podcast with Andrew Shikiar](https://fidoalliance.org/passwordless-authentication-and-the-rise-of-passkeys-expert-insights-podcast-with-andrew-shikiar/): Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, joins us to discuss the shift from passwords to passkeys and the role of FIDO in driving secure, passwordless authentication. He explores the challenges of adoption, the importance of identity verification, and how cross-platform interoperability is accelerating passkey use. The conversation also touches on the impact of generative AI on cybersecurity and what the future holds for passkeys in building long-term resilience. - [MobileIDWorld: Mastercard Launches Passkey Authentication in Europe, Achieves 50% E-commerce Adoption](https://fidoalliance.org/mobileidworld-mastercard-launches-passkey-authentication-in-europe-achieves-50-e-commerce-adoption/): Mastercard has launched advanced payment passkeys across Europe as part of its initiative to enhance online transaction security and replace traditional passwords. The company reports that its tokenization and passkey implementation has achieved nearly 50 percent adoption in European e-commerce transactions, building on its successful passkey deployment in Latin America earlier this year. - [PYMNTS: OneSpan Acquires Passwordless Authentication Specialist Nok Nok Labs](https://fidoalliance.org/pymnts-onespan-acquires-passwordless-authentication-specialist-nok-nok-labs/): OneSpan announced Thursday (June 5) its acquisition of Nok Nok Labs, a provider of FIDO passwordless software authentication solutions. - [PCMag: This Password Manager Now Lets You Create an Account Without a Password](https://fidoalliance.org/pcmag-this-password-manager-now-lets-you-create-an-account-without-a-password/): Dashlane lets you open an account with a FIDO2-spec USB security key as your authentication. - [Biometric Update: 10 million passkeys registered for Mercari market app amid phishing crisis](https://fidoalliance.org/biometric-update-10-million-passkeys-registered-for-mercari-market-app-amid-phishing-crisis/): Mercari, the Japanese e-commerce company behind the Mercari marketplace, has surpassed 10 million registered users of passkeys for authentication. - [Biometric Update: Yubico simplifies passwordless](https://fidoalliance.org/biometric-update-yubico-simplifies-passwordless/): Yubico, a provider of hardware authentication security keys, has announced the expanded availability of YubiKey as a Service to all countries in the European Union. - [PYMNTS: Entersekt and Stanchion Team to Enhance Payment Integration](https://fidoalliance.org/pymnts-entersekt-and-stanchion-team-to-enhance-payment-integration/): Authentication software company Entersekt has launched a partnership with South Africa-based PayTech solution provider Stanchion. - [Info Security Buzz: From Passwords to Passkeys: The Future of Digital Identity Protection](https://fidoalliance.org/info-security-buzz-from-passwords-to-passkeys-the-future-of-digital-identity-protection/): Passwords have been used as the first line of defense in protecting one’s digital identity, but they are fast becoming obsolete due to rampant identity theft. There seems to be no value in passwords anymore due to the increase in breaches of security systems on different platforms. This calls for an easier method of suppressing theft. - [Business Review: NETOPIA Payments launches Click to Pay: a simpler, faster, and more secure online payment experience](https://fidoalliance.org/business-review-netopia-payments-launches-click-to-pay-a-simpler-faster-and-more-secure-online-payment-experience/): NETOPIA Payments becomes the first online payment processor in the world to implement Click to Pay with Passkey FIDO (Fast Identity Online) – a modern online checkout solution built on EMV® global standards, designed to redefine the digital payment experience: faster, safer, and without manual card data entry. - [White Paper: DBSC/DPOP as Complementary Technologies to FIDO Authentication](https://fidoalliance.org/white-paper-dbsc-dpop-as-complementary-technologies-to-fido-authentication/): Shane Weeden, IBMAn Ho, IBM - [Techradar Pro: Millions of Brits to be impacted by UK Gov decision to move away from passwords, 2FA and the replacement is far from perfect](https://fidoalliance.org/techradar-pro-millions-of-brits-to-be-impacted-by-uk-gov-decision-to-move-away-from-passwords-2fa-and-the-replacement-is-far-from-perfecttechradar-pro/): The UK government has said it will roll out passkey technology across its digital services later in 2025, aiming to phase out SMS-based verification in favour of a more secure, user-friendly alternative. - [Independent: Government to roll out passwords replacement on Gov.UK to boost cyber security](https://fidoalliance.org/independent-government-to-roll-out-passwords-replacement-on-gov-uk-to-boost-cyber-security/): The National Cyber Security Centre said moving to digital passkeys to log on to Gov.UK was a vital step in making the tech more ubiquitous. - [Expert Insights: What’s Next For Cybersecurity? 19+ Key Predictions From Security Experts](https://fidoalliance.org/expert-insights-whats-next-for-cybersecurity-19-key-predictions-from-security-experts/): At the 2025 RSAC Conference in San Francisco, our team met with dozens of industry experts, cybersecurity professionals, and investors to find out more about the biggest security technologies and trends that are impacting your business.  - [SC Media: Microsoft moves to default passkey sign-ins](https://fidoalliance.org/sc-media-microsoft-moves-to-default-passkey-sign-ins/): Microsoft has officially shifted to passkeys, such as facial recognition, fingerprint scans, and PINs, as the default sign-in method for all new accounts beginning this month, marking its most significant step yet toward a password-free future, according to TechRepublic. - [Gov Info Security: UK Government to Roll Out Passkeys Late This Year](https://fidoalliance.org/gov-info-security-uk-government-to-roll-out-passkeys-late-this-year/): FIDO-Based Authentication to Replace SMS-Based Verification, Says UK NCSC - [NCSC: UK pioneering global move away from passwords](https://fidoalliance.org/ncsc-uk-pioneering-global-move-away-from-passwords/): The UK government is set to roll out passkey technology for its digital services later this year as an alternative to the current SMS-based verification system, offering a more secure and cost-effective solution that could save several million pounds annually. - [ID Tech Wire: FIDO Alliance Launches Payment Authentication Working Group](https://fidoalliance.org/id-tech-wire-fido-alliance-launches-payment-authentication-working-group/): The FIDO Alliance announced today the launch of a new Payments Working Group (PWG) focused on developing and implementing FIDO authentication solutions specifically for payment use cases. This initiative marks a significant expansion of the organization’s efforts to eliminate password dependencies in critical digital transactions. - [Biometric Update: It’s World Passkey Day, actually: trust, adoption grows for FIDO credential](https://fidoalliance.org/biometric-update-its-world-passkey-day-actually-trust-adoption-grows-for-fido-credential/): World Password Day is no longer. The annual day to promote secure password practices has run its course, and the FIDO Alliance (whose stated mission, to be fair, is to bring the world beyond passwords) has rebranded World Password Day as World Passkey Day – an occasion to celebrate the encrypted FIDO credentials that combine data you possess (a digital key or credential) with a biometric trait (something you are, usually a face or fingerprint). - [PC Mag: RIP Passwords: Microsoft Moves to Passkeys as the Default on New Accounts](https://fidoalliance.org/pc-mag-rip-passwords-microsoft-moves-to-passkeys-as-the-default-on-new-accounts/): Anyone setting up a new Microsoft account will soon find they’re encouraged to use a passkey during the sign-up process. - [The Verge: Microsoft goes passwordless by default on new accounts](https://fidoalliance.org/the-verge-microsoft-goes-passwordless-by-default-on-new-accounts/): After supporting passwordless Windows logins for years and even allowing users to delete passwords from their accounts, Microsoft is making its biggest move yet toward a future with no passwords. Now it will ask people signing up for new accounts to only use more secure methods like passkeys, push notifications, and security keys instead, by default. - [BetaNews: Research confirms consumers are turning to passkeys to protect their accounts](https://fidoalliance.org/betanews-research-confirms-consumers-are-turning-to-passkeys-to-protect-their-accounts/): As you'll already know, today is World Passkey Day and the FIDO Alliance has released an independent study of over 1,300 consumers across the US, UK, China, South Korea, and Japan to understand how passkey usage and consumer attitudes towards authentication have evolved. - [Cyber Security News: 15 Billion User Gain Passwordless Access to Microsoft Account Using Passkeys](https://fidoalliance.org/cyber-security-news-15-billion-user-gain-passwordless-access-to-microsoft-account-using-passkeys/): As the first-ever World Passkey Day replaces the traditional World Password Day, Microsoft joins the FIDO Alliance in celebrating a milestone achievement: over 15 billion online accounts now have access to passwordless authentication through passkeys. - [Forbes: Microsoft Warns All Windows Users—Delete Your Password](https://fidoalliance.org/forbes-microsoft-warns-all-windows-users-delete-your-password/): Microsoft is on a mission to delete passwords for a billion users, given that “the password era is ending.” The Windows-maker warns users that “bad actors know it, which is why they’re desperately accelerating password-related attacks while they still can.” And those attacks are now making headlines weekly. - [TechRadar: World Password Day 2025: All the news, updates and advice from our experts as it happened](https://fidoalliance.org/world-password-day-2025-all-the-news-updates-and-advice-from-our-experts-as-it-happened/): The FIDO Alliance has also recently invited companies to participate in the World Passkey Pledge to create a more secure future, and move past the vulnerability and hassle of passwords. - [Celebrating World Passkey Day 2025: Showcase of Real-World Passkey Deployments](https://fidoalliance.org/celebrating-world-passkey-day-2025-showcase-of-real-world-passkey-deployments/): May 1, 2025 - [FIDO Alliance Champions Widespread Passkey Adoption and a Passwordless Future on World Passkey Day 2025](https://fidoalliance.org/fido-alliance-champions-widespread-passkey-adoption-and-a-passwordless-future-on-world-passkey-day-2025/): New global survey: More than two thirds of users familiar with passkeys turn to them for simpler, safer sign-ins as password pain persists - [Consumer Password and Passkey Trends: World Passkey Day 2025](https://fidoalliance.org/wpd-report-2025-consumer-password-passkey-trends/): Passkeys are no longer just a concept: The future of sign-in is here and consumers are ready. Built on the open authentication standards developed by theFIDO Alliance, passkeys are quickly gaining momentum among global service providers. Why? Because they offer africtionless, phishing-resistant, passwordless sign-in experience that is redefining digital security and user convenience. - [FIDO Alliance Launches Payments Working Group](https://fidoalliance.org/fido-alliance-launches-payments-working-group/): April 29, 2025 – The FIDO Alliance has launched a Payments Working Group (PWG) to define and drive FIDO solutions for payment use cases. The PWG will also act as subject matter experts and internal advisors within the FIDO Alliance on issues affecting the use of FIDO solutions for payment use cases. The PWG is co-chaired by Henna Kapur of Visa and Jonathan Grossar of Mastercard, with other FIDO Alliance member company participants including American Express; Cartes Bancaires; Discover; Futurae; Infineon; OneSpan; PayPal; Royal Bank of Canada – Solution Acceleration & Innovation; and Thales. - [Case Study: Microsoft](https://fidoalliance.org/case-study-microsoft/): Describe your service/platform/product and how it’s using FIDO authentication. - [Case Study: Nikkei ](https://fidoalliance.org/case-study-nikkei/): Describe your service/platform/product and how it’s using FIDO authentication. - [Case Study: VicRoads](https://fidoalliance.org/case-study-vicroads/): Background: VicRoads - [Case Study: Zoho Corporation](https://fidoalliance.org/case-study-zoho-corporation/): Describe your service/platform/product and how it’s using FIDO authentication. - [Case Study: Samsung Electronics](https://fidoalliance.org/case-study-samsung-electronics/): Describe your service/platform/product and how it’s using FIDO authentication. - [Case Study: ABANCA](https://fidoalliance.org/case-study-abanca/): Describe your service/platform/product and how it’s using FIDO authentication. - [ZD NET: Why the road from passwords to passkeys is long, bumpy, and worth it – probably](https://fidoalliance.org/zd-net-why-the-road-from-passwords-to-passkeys-is-long-bumpy-and-worth-it-probably/): Out of the blue, I received a text from my father asking me, "What's the difference between a password and a passkey?"  - [Forbes: Microsoft’s Password Deletion For 1 Billion Users—Do This Now](https://fidoalliance.org/forbes-microsofts-password-deletion-for-1-billion-users-do-this-now/): Your phone, computer and tablet is now at risk, as the nightmare of AI-powered attacks comes true. There are now multiple warnings into the use of mainstream AI platforms to design, develop and even execute attacks that are almost impossible to detect. - [Engadget: How to use the Apple Passwords app](https://fidoalliance.org/engadget-how-to-use-the-apple-passwords-app/): Apple’s new Passwords app (introduced with iOS 18, iPadOS 18, and macOS Sequoia) is a big leap forward in making password management simple and user-friendly for Apple users, even if it's not as robust as other password managers. If you’ve ever fumbled through Safari settings to find a saved login or toggled through iCloud Keychain menus to edit credentials, the Passwords app is for you. It’s designed to give you a dedicated home for all your saved login credentials, passkeys, Wi-Fi passwords and two-factor authentication codes, all in one secure, easy-to-navigate interface. - [ABANCA News: ABANCA achieves international FIDO certification for its ABANCA Key service](https://fidoalliance.org/abanca-news-abanca-achieves-international-fido-certification-for-its-abanca-key-service/): ABANCA has achieved international FIDO certification for the Llave ABANCA service, the digital identity verification technology solution developed by the bank that allows customers to validate mobile banking transactions securely and quickly by unlocking their phone. - [IT Brew: Lessons learned by an RSA IT pro implementing passwordless](https://fidoalliance.org/it-brew-lessons-learned-by-an-rsa-it-pro-implementing-passwordless/): Going passwordless is difficult for a lot of companies, even the ones with “security” in the name. - [Biometric Update: Inverid joins FIDO Alliance to bring NFC expertise to DocAuth](https://fidoalliance.org/biometric-update-inverid-joins-fido-alliance-to-bring-nfc-expertise-to-docauth/): Inverid has joined the FIDO Alliance. A release from the Dutch identity verification firm says it will bring expertise in document authenticity verification to FIDO users of DocAuth document authenticity specifications. - [Highlights from the FIDO Alliance APAC Regional Member Meetup & Workshop: Collaborating for a Passwordless Future](https://fidoalliance.org/highlights-from-the-fido-alliance-apac-regional-member-meetup-workshop/): On March 18, 2025, the FIDO Alliance convened its APAC regional members and key stakeholders at the Telecommunications Technology Association (TTA) Auditorium in Seongnam, South Korea, for a full-day meetup and workshop. The event focused on advancing simpler, stronger authentication across the region and served as a vital platform for technical updates, regional progress, and real-world implementation insights around passkeys. - [FIDO Alliance Launches the Passkey Pledge to Further Accelerate Global Movement Away from Passwords ](https://fidoalliance.org/fido-alliance-launches-the-passkey-pledge-to-further-accelerate-global-movement-away-from-passwords/): Organizations are encouraged to take the Passkey Pledge ahead of World Passkey Day on May 1  - [MobileIDWorld: Google Developing Passkey Transfer Feature for Android Password Manager](https://fidoalliance.org/mobileidworld-google-developing-passkey-transfer-feature-for-android-password-manager/): Google is developing a new feature that will allow secure passkey transfers between Android devices through its Google Password Manager service. The functionality, which is currently under development, aims to simplify the process of moving authentication credentials across devices while maintaining security standards. The development follows Google’s recent enhancements to its Password Manager, including improved security features and user interface updates. - [Forbes: Google’s Gmail Upgrade—Good And Bad News For 3 Billion Users](https://fidoalliance.org/forbes-googles-gmail-upgrade-good-and-bad-news-for-3-billion-users/): Just days after Google confirmed it is bringing its next AI upgrade to Gmail, with major privacy implications, there’s more good and bad news for the 3 billion users relying on Google to deliver secure, spam-free email to their phones and computers. It turns out that a dangerous email attack has operated under the radar for years — until now. - [TechRadar: Great news everyone! Google is going to let you transfer your passkeys to a new phone](https://fidoalliance.org/techradar-great-news-everyone-google-is-going-to-let-you-transfer-your-passkeys-to-a-new-phone/): Google’s password manager may soon allow you to transfer your passkeys to a new phone, making their use as a login tool even easier. - [International Security Journal: Passkeys set to become leading authentication method by 2027, HYPR reports](https://fidoalliance.org/international-security-journal-passkeys-set-to-become-leading-authentication-method-by-2027-hypr-reports/): HYPR, an Identity Assurance Company, has released the fifth edition of its ‘State of Passwordless Identity Assurance Report.’ - [Security Info Watch: iProov launches facial biometric MFA support targeting workforce identity theft](https://fidoalliance.org/security-info-watch-iproov-launches-facial-biometric-mfa-support-targeting-workforce-identity-theft/): This device-independent, FIDO Alliance-certified biometric authentication solution helps organizations mitigate the risk of one of workforce security’s most crucial concerns: account takeover. - [Forbes: Microsoft Warns 1 Billion Windows Users—Do Not Use Password](https://fidoalliance.org/forbes-microsoft-warns-1-billion-windows-users-do-not-use-password/): All change for Microsoft. The company has suddenly confirmed a major update “for over 1 billion end users,” as the deletion of passwords for all users becomes real. Your Microsoft password, it warns, “could be easily forgotten or guessed by an attacker,” and it’s now time “to completely remove the password from your account.” - [White Paper: Passkeys: The Journey to Prevent Phishing Attacks](https://fidoalliance.org/white-paper-passkeys-the-journey-to-prevent-phishing-attacks/): This white paper is part of a three-part series on preventing phishing attacks through passkey deployment: - [White Paper: FIDO Alliance Guidance for U.S. Government Agency Deployment of FIDO Authentication](https://fidoalliance.org/white-paper-fido-alliance-guidance-for-u-s-government-agency-deployment-of-fido-authentication/): This document is intended to highlight areas where FIDO offers the best value to address U.S. Government use cases as an enhancement of existing infrastructure, while minimizing rework as U.S. Government Agencies advance their zero trust strategies with phishing-resistant authentication tied to enterprise identity as the foundation. - [IT News: Over 200,000 myGov users disable passwords in passkey shift](https://fidoalliance.org/it-news-over-200000-mygov-users-disable-passwords-in-passkey-shift/): New figures reveal that over 200,000 users of myGov password stopped using passwords in favour of exclusively using passkeys as their login method by the end of last year. - [Mobile ID World: VicRoads Implements Passkeys Authentication System for Enhanced Digital Security](https://fidoalliance.org/mobile-id-world-vicroads-implements-passkeys-authentication-system-for-enhanced-digital-security/): VicRoads, Victoria’s road transport authority, has implemented a passkeys authentication system as part of its digital security enhancement initiative, marking a significant step in Australia’s broader transition toward advanced digital identity solutions. The new system moves away from traditional password-based authentication methods toward a more secure passwordless approach, following similar changes by major technology providers like Microsoft in recent months. - [The Payers: Fime secures FIDO IDV certification for identity verification](https://fidoalliance.org/the-payers-fime-secures-fido-idv-certification-for-identity-verification/): Fime’s testing laboratories in both EMEA and Taiwan have obtained full accreditation under the FIDO Alliance Identity Verification (IDV) Certification Programme. - [Help Net Security: Goodbye passwords? Enterprises ramping up passkey adoption](https://fidoalliance.org/help-net-security-goodbye-passwords-enterprises-ramping-up-passkey-adoption/): 87% of companies have, or are in the midst of, rolling out passkeys with goals tied to improved user experience, enhanced security, and compliance, according to the FIDO Alliance. - [Get With IT Podcast: The State of Passkey Adoption](https://fidoalliance.org/get-with-it-podcast-the-state-of-passkey-adoption/): In this episode, Jenna Barron interviews Andrew Shikiar, CEO and executive director of FIDO Alliance. They discuss the state of passkey adoption in the industry today and how organizations can prepare for adopting them. - [Fime supports fight against identity fraud with FIDO ID verification accreditations](https://fidoalliance.org/fime-supports-fight-against-identity-fraud-with-fido-id-verification-accreditations/): Fime has achieved full  FIDO Alliance Identity Verification (IDV) Certification Program accreditation across multiple regions. Both the Fime EMEA and Fime Taiwan testing laboratories can now support identity verification vendors in certifying their Document Authenticity and Face Verification solutions, helping combat fraud while enhancing the user experience. - [MobileIDWorld: Tech Giants Microsoft, Google, and Apple Drive Global Passkey Adoption with Visa Support](https://fidoalliance.org/mobileidworld-tech-giants-microsoft-google-and-apple-drive-global-passkey-adoption-with-visa-support/): Major technology companies Microsoft, Google, and Apple are driving widespread adoption of passkeys as an alternative to traditional passwords, leveraging biometric authentication methods like facial recognition and fingerprint scanning for enhanced security and user convenience. The initiative builds on the FIDO Alliance standards that these companies have been developing since 2019. - [Security Infowatch: How FIDO Can Safeguard Against Advanced Cyber Threats](https://fidoalliance.org/security-infowatch-how-fido-can-safeguard-against-advanced-cyber-threats/):  FIDO as the Future of Authentication: Traditional password-based systems are vulnerable to phishing, credential stuffing, and other cyberattacks. FIDO (Fast Identity Online) uses public key cryptography to deliver phishing-resistant, passwordless authentication. Implementation Roadmap: Organizations should assess current authentication methods, educate stakeholders, select FIDO-compatible solutions, and roll out the technology gradually to maximize security and user adoption. Security Meets Usability: FIDO enhances security and simplifies the user experience with biometrics, hardware tokens, and multi-device passkeys, offering both protection and convenience. - [Forbes: AI Can Crack Your Passwords Fast—6 Tips To Stay Secure](https://fidoalliance.org/forbes-ai-can-crack-your-passwords-fast-6-tips-to-stay-secure/): Do you think your trusty 8-character password is safe? In the age of AI, that might be wishful thinking. Recent advances in artificial intelligence are giving hackers superpowers to crack and steal account credentials. Researchers have demonstrated that AI can accurately guess passwords just by listening to your keystrokes. By analyzing the sound of typing over Zoom, the system achieved over 90% accuracy in some cases. - [MobileIDWorld: Google Replacing Gmail SMS Authentication with QR Code Verification System](https://fidoalliance.org/mobileidworld-google-replacing-gmail-sms-authentication-with-qr-code-verification-system/): Google has announced plans to phase out SMS-based authentication for Gmail accounts in favor of more secure methods like QR code verification and passkeys. The change follows similar moves by other tech giants like Microsoft and Apple to strengthen authentication methods as part of the company’s broader security enhancement initiatives. - [Biometric Update: Passkeys for enterprise report from FIDO says adoption is growing](https://fidoalliance.org/biometric-update-passkeys-for-enterprise-report-from-fido-says-adoption-is-growing/): A new report from the FIDO Alliance aims to understand the state of passkey deployments by enterprises in the U.S. and UK, including methods for deploying FIDO passkeys, total employees enrolled and perceived barriers to deployment. - [Identity Week: New FIDO Alliance report: 87% of enterprises in the U.S. and UK are deploying passkeys](https://fidoalliance.org/new-fido-alliance-report-87-of-enterprises-in-the-u-s-and-uk-are-deploying-passkeys/): The FIDO Alliance along with underwriters Axiad, HID, and Thales today released its State of Passkey Deployment in the Enterprise report, finding that 87% of surveyed companies have, or are in the midst of, rolling out passkeys with goals tied to improved user experience, enhanced security, and compliance. - [The State of Passkey Deployment in the Enterprise: A Snapshot of Passkey Deployments for Employee Sign-ins in the U.S. and UK](https://fidoalliance.org/research-state-of-passkey-deployment-in-the-enterprise-a-snapshot-of-deployments-employee-sign-ins-us-uk/): A Snapshot of Passkey Deployments for Employee Sign-ins in the U.S. and UK - [New FIDO Alliance Research Shows 87% of U.S. and UK Workforces are Deploying Passkeys for Employee Sign-ins](https://fidoalliance.org/new-fido-alliance-research-shows-87-percent-us-uk-workforces-are-deploying-passkeys-for-employee-sign-ins/): Respondents report positive impacts on user experience, security, productivity, and cost reduction from deploying a mix of device-bound and synced passkeys - [Biometric Update: Biometrics connecting ID and payments through digital wallets, apps and passkeys](https://fidoalliance.org/biometric-update-biometrics-connecting-id-and-payments-through-digital-wallets-apps-and-passkeys/): Biometrics are connecting with payment credentials, whether through numberless credit cards and banking apps or passkeys, as the concrete steps towards linking digital identity and payment systems shows up as a major theme in the week’s most-read stories on Biometric Update. Mastercard announced it will ditch the familiar credit card number in favor of on-device biometrics and tokenization, while everyone in digital wallets, from the EUDI Wallet Consortium to Fime and Mattr to Apple is looking at how to bring together identity and payments, and Visa arguing for the role of passkeys in a converged digital ID and payments ecosystem. - [CPO Magazine: Passkey Authentication and Its Relevant Authentication Standards](https://fidoalliance.org/cpo-magazine-passkey-authentication-and-its-relevant-authentication-standards/): Passkey authentication replaces traditional passwords with a pair of cryptographic keys—public and private. The private key stays on the user’s device, while the public key sits on the server. During login, the server issues a challenge that only the private key can solve, and the response gets verified using the public key. No passwords are transmitted or stored, which reduces the attack surface significantly. Password leaks and brute-force attempts become non-issues because there is no static secret to steal or guess. - [HealthcareIT: Passwords Are the Problem: How More Secure Authentication Methods Can Transform Healthcare Workflows](https://fidoalliance.org/healthcareit-passwords-are-the-problem-how-more-secure-authentication-methods-can-transform-healthcare-workflows/): Username and password authentication is a fixture in healthcare but one that continues to hinder operations and put patient privacy – and care – at risk. In just the first three months of 2024, there were over 116 data breaches in the healthcare industry, allowing cybercriminals to access private patient data, medications, clinical records, Social Security numbers, and more by employing tactics like phishing emails and malware. - [Health Management: The Future of Healthcare Security: Embracing Passwordless Authentication](https://fidoalliance.org/health-management-the-future-of-healthcare-security-embracing-passwordless-authentication/): Traditional username and password authentication remains a standard practice in healthcare, but it increasingly compromises operational efficiency, patient privacy and care quality. In the first quarter of 2024 alone, over 116 data breaches exposed sensitive patient data, including medications, clinical records and Social Security numbers. Cybercriminals use tactics like phishing and malware to exploit these vulnerabilities, underscoring the need for stronger authentication measures. As a response, passwordless authentication is gaining traction, offering a more secure and streamlined approach to access management. Although the transition will take time, the next decade will likely see widespread adoption of passwordless solutions as the limitations of passwords become too costly to ignore. - [FIDO Alliance Melbourne Seminar 2025](https://fidoalliance.org/fido-alliance-melbourne-seminar-2025/): The FIDO Alliance recently held a pivotal one-day seminar exploring the transformative power of passkey authentication in Australia and beyond. - [Thales Launches FIDO Key Management Solution for Enterprise Passwordless Authentication](https://fidoalliance.org/thales-launches-fido-key-management-solution-for-enterprise-passwordless-authentication/): Thales has unveiled a new solution designed to streamline the deployment and management of FIDO security passkeys for large-scale implementations. The OneWelcome FIDO Key Lifecycle Management solution enables organizations to efficiently manage the complete lifecycle of FIDO keys while transitioning to passwordless authentication systems. The launch follows Thales’ previous efforts in passwordless authentication, expanding their enterprise security portfolio. - [Yuno Rolls Out Mastercard Payment Passkey in Latin America to Combat Fraud and Streamline Checkouts](https://fidoalliance.org/yuno-rolls-out-mastercard-payment-passkey-in-latin-america-to-combat-fraud-and-streamline-checkouts/): Following the launch by Yuno, merchants in Brazil, Argentina, and Chile can replace increasingly vulnerable traditional authentication methods, such as one-time passwords, with Mastercard Payment Passkey Service, which uses device-based biometrics, such as fingerprints and facial recognition already available on smartphones, to authenticate purchases. - [Goodbye to manual card entry: Mastercard reveals when the new era of one-click online payments begins](https://fidoalliance.org/goodbye-to-manual-card-entry-mastercard-reveals-when-the-new-era-of-one-click-online-payments-begins/): Changes are on the way for online shopping and e-commerce. The traditional way of paying for items online by typing in your credit card details (card number and CVV security code) will soon be a thing of the past. - [Onboarding the Future: Guide for Edge Deployment with FIDO Device Onboard (FDO)](https://fidoalliance.org/onboarding-the-future-guide-for-edge-deployment-with-fido-device-onboard-fdo/): Why You Should Consider the FDO Standard for Zero-Trust Device Onboarding - [MobileIDWorld: Passkey Adoption Surges 550% in 2024 as Bitwarden Reports 1.1M New Implementations](https://fidoalliance.org/mobileidworld-passkey-adoption-surges-550-in-2024-as-bitwarden-reports-1-1m-new-implementations/): The adoption of passkeys in digital authentication has shown significant growth throughout 2024, building on the momentum started by major platform providers in their shift away from traditional passwords. While falling short of earlier predictions of 15 billion accounts, password management provider Bitwarden reported a 550 percent increase in daily passkey creation in December 2024 compared to the previous year, with approximately 1.1 million passkeys created in Q4 alone. - [PayPal Newsroom: Solving the Convenience and Security Equation](https://fidoalliance.org/paypal-newsroom-solving-the-convenience-and-security-equation/): PayPal has remained at the forefront of the digital payment revolution for more than 25 years by creating innovative experiences that empower over 400 million consumers and merchants to move money easily and securely. - [Analytics Insight: Revolutionizing Digital Security: The Rise of Passkeys](https://fidoalliance.org/analytics-insight-revolutionizing-digital-security-the-rise-of-passkeys/): The Core of Passkey Technology - [TechRadar: Passwords out, passkeys in: The future of secure authentication](https://fidoalliance.org/techradar-passwords-out-passkeys-in-the-future-of-secure-authentication/): Since the inception of the internet, passwords have been the primary authentication factor to gain access to online accounts. Yubico’s recent Global State of Authentication survey of 20,000 employees found that 58 percent still use a username and password to login to personal accounts, with 54 percent using this login method to access work accounts. - [MobileIDWorld: Research Reveals Security Implications of FIDO2 and Synced Passkeys](https://fidoalliance.org/mobileidworld-research-reveals-security-implications-of-fido2-and-synced-passkeys/): Recent academic research has revealed new insights into the security considerations surrounding FIDO2 authentication and synced passkeys, highlighting both the strengths and potential vulnerabilities of current authentication systems. The analysis comes at a time when major technology companies are increasingly adopting passkey technology, with Microsoft reporting login times three times faster than traditional passwords. - [ZDNet: What are passkeys? How going passwordless can simplify your life in 2025](https://fidoalliance.org/zdnet-what-are-passkeys-how-going-passwordless-can-simplify-your-life-in-2025/): You probably have a lot of passwords in your life. - [Tech Target: Adopt passkeys over passwords to improve UX, drive revenue](https://fidoalliance.org/tech-target-adopt-passkeys-over-passwords-to-improve-ux-drive-revenue/): The digital economy continues to rely on password-based authentication, but password weaknesses -- and human nature -- make them horrible for security. Password use also impacts businesses' bottom lines because every year, forgotten passwords and password resets result in millions of dollars of lost sales and wasted IT staff hours. - [Federal Register: Strengthening and Promoting Innovation in the Nation’s Cybersecurity](https://fidoalliance.org/federal-register-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/): A Presidential Document by the Executive Office of the President on 01/17/2025 - [Insurance Business: Experts warn NZ businesses to prepare for AI-driven cyber threats](https://fidoalliance.org/insurance-business-experts-warn-nz-businesses-to-prepare-for-ai-driven-cyber-threats/): Cybersecurity experts are calling on New Zealand businesses to strengthen their defences as cyber threats grow in sophistication. - [Biometric Update: State of passkeys 2025: passkeys move to mainstream](https://fidoalliance.org/biometric-update-state-of-passkeys-2025-passkeys-move-to-mainstream/): More than 1 billion people have activated at least one passkey according to the FIDO Alliance – an astonishing number that highlights the quick evolution of passkeys from a buzzword to a trusted login method. In just two years, consumer awareness of the technology jumped from 39% to 57%. Let’s see how passkeys have moved to mainstream. - [National Cyber Security Centre: Passkeys: they’re not perfect but they’re getting better](https://fidoalliance.org/national-cyber-security-centre-passkeys-theyre-not-perfect-but-theyre-getting-better/): Passkeys are the future of authentication, offering enhanced security and convenience over passwords, but widespread adoption faces challenges that the NCSC is working to resolve. - [GlobeNewswire: Passwordless Authentication Market to Surpass Valuation of US$ 8,944.3 Million By 2033](https://fidoalliance.org/globenewswire-passwordless-authentication-market-to-surpass-valuation-of-us-8944-3-million-by-2033/): Growing enterprise reliance on biometric and token-based authentication propels the passwordless market forward. Providers innovate frictionless FIDO2/WebAuthn solutions, boosting collaboration between fintech, retail, and the public sector, while unresolved interoperability hinders the seamless global rollout of passkey technologies. - [GlobeNewswire: Expanding the API Economy and CIAM with Passkeys, Identity Verification, and Decentralized Identity](https://fidoalliance.org/globenewswire-expanding-the-api-economy-and-ciam-with-passkeys-identity-verification-and-decentralized-identity/): The study illustrates successful implementations of CIAM solutions across various verticals and use cases. This report's geographic coverage is global. The study period is 2023-2029, with 2024 as the base year and 2025-2029 as the forecast period. - [HYPR Unmasks a Fake IT Worker: North Korea Isn’t the Only Threat](https://fidoalliance.org/hypr-unmasks-a-fake-it-worker-north-korea-isnt-the-only-threat/): Highlights: - [White Paper: Secure Payment Confirmation](https://fidoalliance.org/white-paper-secure-payment-confirmation/): Marc Findon, Nok Nok LabsJonathan Grossar, MastercardFrank-Michael Kamm, Giesecke+DevrientHenna Kapur, VisaSue Koomen, American ExpressGregoire Leleux, WorldlineAlain Martin, ThalesStian Svedenborg, BankID BankAxept - [2024 FIDO Alliance Seoul Public Seminar: Unlocking a Secure Tomorrow with Passkeys](https://fidoalliance.org/content-2024-fido-alliance-seoul-public-seminar-unlocking-a-secure-tomorrow-with-passkeys/): The FIDO Alliance’s Seoul Public Seminar was held on December 10, 2024, at the SK Telecom Pangyo Office. The theme for this milestone event was Unlocking a Secure Tomorrow with Passkeys and the event attracted nearly 200 attendees. The seminar gave professionals a chance to share the latest developments and implementations of simpler and stronger online authentication technology with passkeys. - [Business Reporter: Addressing the bias issue in biometrics](https://fidoalliance.org/business-reporter-addressing-the-bias-issue-in-biometrics/): Bias in biometric identity systems still exists, but it is manageable, argues Andrew Shikiar at the FIDO Alliance - [Biometric Update: Passkeys build momentum, enabling access to 15 billion online accounts](https://fidoalliance.org/biometric-update-passkeys-build-momentum-enabling-access-to-15-billion-online-accounts/): FIDO passkey adoption doubles in 2024 as major firms opt for passwordless log-in - [Podcast: The Password Problem](https://fidoalliance.org/podcast-the-password-problem/): In this episode of the Trust Issues podcast, host David Puner sits down with Andrew Shikiar, the Executive Director and CEO of the FIDO Alliance, to discuss the critical issues surrounding password security and the innovative solutions being developed to address them. Andrew highlights the vulnerabilities of traditional passwords, their susceptibility to phishing and brute force attacks, and the significant advancements in passwordless authentication methods, particularly passkeys. He explains how passkeys, based on FIDO standards, utilize asymmetric public key cryptography to enhance security and reduce the risk of data breaches.  - [ASRock Industrial Sets New Standard in Secure IoT Deployment with FDO Device Onboard](https://fidoalliance.org/content-asrock-industrial-sets-new-standard-in-secure-iot-deployment-with-fdo-device-onboard/): Imagine connecting and configuring devices on an oil rig in the middle of the ocean with limited human intervention. That’s the reality of what can be achieved with the FIDO Alliance’s Device Onboarding (FDO) standard. This is an example of the applications that IoT pioneer ASRock Industrial is bringing to life. - [Passkey Adoption Doubles in 2024: More than 15 Billion Online Accounts Can Leverage Passkeys for Faster, Safer Sign-ins](https://fidoalliance.org/passkey-adoption-doubles-in-2024-more-than-15-billion-online-accounts-can-leverage-passkeys/): Momentum continues in Japan with notable passkey success stories and deployments from Nikkei, Tokyu, Google, Sony Interactive Entertainment, KDDI, LY Corporation, Mercari and NTT DOCOMO - [Finextra: Thought Leadership: The Future of Payment Authentication](https://fidoalliance.org/finextra-thought-leadership-the-future-of-payment-authentication/): In this PREDICT 2025 USA interview, Andrew Shikiar, Executive Director and CEO, FIDO Alliance, discusses how the industry has been exploring the death of the password for decades, how this conversation has evolved and where we are with passkeys today – pinpointing why making progress with eliminating dependence on passwords is of paramount importance. - [CISA: USDA Stops Credential Phishing with FIDO Authentication](https://fidoalliance.org/cisa-usda-stops-credential-phishing-with-fido-authentication/): As the saying goes, malicious actors don’t break in—they log in. There's a significant truth in that statement. Today, many organizations struggle to protect their staff from credential phishing, a challenge that's only grown as attackers increasingly execute “MFA bypass” attacks.  - [Practical Ecommerce: Passkeys Gain Traction with Ecommerce Shoppers](https://fidoalliance.org/practical-ecommerce-passkeys-gain-traction-with-ecommerce-shoppers/): Passkeys allow users to log in to their secure accounts without passwords. Ecommerce businesses were first in line when the FIDO Alliance introduced passkeys in 2022. The trade association, which stands for Fast ID Online, launched in 2012 with a mission to reduce the world’s password reliance. - [FIDO Alliance | Free Yourself From Passwords with Passkeys](https://fidoalliance.org/fido-alliance-free-yourself-from-passwords-with-passkeys/): Watch the video to learn how to go passwordless with passkeys. - [Passkeys Explainer Video | FIDO Alliance](https://fidoalliance.org/fido-alliance-passkeys-explainer-video/): We all know passwords are frustrating to use, and not safe. Passkeys are the replacement for passwords. Strong cryptographic security behind passkeys prevents phishing attacks, reduces security breaches and account takeovers. Passkeys make sign-ins fast, simple, and secure. Passkeys also sync easily across all user devices, including new ones. Passkeys for businesses reduce IT time, avoid desktop hassles, and there’s no more costly password resets. - [ARC Advisory Group: Wireless Broadband Alliance Integrates OpenRoaming with FIDO Device Onboard to Enable Zero-Touch Framework for IoT Device Onboarding](https://fidoalliance.org/arc-advisory-group-wireless-broadband-alliance-integrates-openroaming-with-fido-device-onboard-to-enable-zero-touch-framework-for-iot-device-onboarding/): The Wireless Broadband Alliance (WBA), the global industry body dedicated to improving Wi-Fi standards and services, announced a new framework for WBA integrating OpenRoaming and FIDO Device Onboard (FDO). This initiative is intended to enable a seamless and secure zero-touch onboarding process for Internet of Things (IoT) Wi-Fi devices. - [Fast Company: Say Goodbye to Passwords](https://fidoalliance.org/fast-company-say-goodbye-to-passwords/): It’s been a couple of years since Apple, Google, and Microsoft started trying to kill the password, and its demise seems more likely than ever. - [Daily Mail: Top 10 passwords used in the United States revealed – stop using them immediately if they’re yours](https://fidoalliance.org/daily-mail-top-10-passwords-used-in-the-united-states-revealed-stop-using-them-immediately-if-theyre-yours/): Experts discovered the top 10 overused passwords in the US that could put you at risk of being easily hacked. - [Branch enhances security and user experience with passkey implementation](https://fidoalliance.org/branch-enhances-security-and-user-experience-with-passkey-implementation/): Corporate Overview - [The Associated Press: One Tech Tip: Replacing passwords with passkeys for an easier login experience](https://fidoalliance.org/the-associated-press-one-tech-tip-replacing-passwords-with-passkeys-for-an-easier-login-experience/): You might have noticed that many online services are now offering the option of using passkeys, a digital authentication method touted as an easier and more secure way to log in.  - [Biometric Update: Mastercard replacement of OTPs with passkeys and Click to Pay reaches APAC](https://fidoalliance.org/biometric-update-mastercard-replacement-of-otps-with-passkeys-and-click-to-pay-reaches-apac/): Mastercard is enabling faster and more convenient online transactions with its newest feature, Mastercard Click to Pay, launching in the Asia-pacific region. - [The Record: These major software firms took CISA’s secure-by-design pledge. Here’s how they’re implementing it](https://fidoalliance.org/the-record-these-major-software-firms-took-cisas-secure-by-design-pledge-heres-how-theyre-implementing-it/): The Cybersecurity and Infrastructure Security Agency’s (CISA) secure-by-design pledge has hit its six-month mark, and companies that took the pledge say they’ve made significant security improvements since they signed onto the initiative. - [Security Boulevard: FIDO: Consumers are Adopting Passkeys for Authentication](https://fidoalliance.org/security-boulevard-fido-consumers-are-adopting-passkeys-for-authentication/): There appears to be growing momentum behind the use of passkeys as an alternative identity verification tool to passwords, with the familiarity with the technology growing over the past two years while the use of passwords as declined a bit, according to the Fast IDentity Online (FIDO) Alliance. - [Retail TouchPoints: The Login Effect: The Role of Customer Authentication Psychology in Retail Success](https://fidoalliance.org/retail-touchpoints-the-login-effect-the-role-of-customer-authentication-psychology-in-retail-success/): Retail lags in authentication modernization, but not because providers aren’t interested in upgrading. It’s because customers actively reject change. Familiarity, ease of implementation and legacy system compatibility all mean that very few retailers offer anything beyond usernames and passwords, not even two-factor (2FA) and multi-factor authentication (MFA). - [J:COM turns to Passwordless Authentication](https://fidoalliance.org/jcom-turns-to-passwordless-authentication/): Corporate Overview - [TechRadar: Youth of today say passwords are old news; passkeys are the future](https://fidoalliance.org/techradar-youth-of-today-say-passwords-are-old-news-passkeys-are-the-future/): Younger generations see passwords as outdated and are opting for passkeys, a FIDO-backed technology offering more secure, passwordless authentication. With increasing support from popular apps and services, young users are helping to drive this transition towards safer, FIDO-endorsed security solutions. - [ZDNET: Passkeys are more popular than ever. This research explains why](https://fidoalliance.org/zdnet-passkeys-are-more-popular-than-ever-this-research-explains-why/): The FIDO Alliance's fourth annual Online Authentication Barometer reveals significant growth in awareness and adoption of passkeys, with 57% of surveyed consumers now familiar with the technology (up from 39% in 2022). As awareness increases, FIDO is urging more brands to adopt passkey support to help combat the rising sophistication of online threats and scams. - [HiTRUST Brings Passkeys to Colatour Travel](https://fidoalliance.org/hitrust-brings-passkeys-to-colatour-travel/): This seamless experience is now possible thanks to HiTRUST’s latest collaboration with Taiwan’s leading travel platform, Colatour. Building on nearly a decade of trusted partnership, HiTRUST and Colatour have launched an innovative passwordless solution. Powered by global FIDO standards, it redefines the security of digital travel booking platforms. - [New Data Finds Brands are Losing Younger Customers Due to Password Pain, as Passkeys Gain Mainstream Momentum](https://fidoalliance.org/new-data-finds-brands-are-losing-younger-customers-due-to-password-pain-as-passkeys-gain-mainstream-momentum/): Global FIDO Alliance study reveals latest consumer trends and attitudes towards authentication methods and their perceived online security - [Research Findings: Consumer Trends and Attitudes Towards Authentication Methods](https://fidoalliance.org/research-findings-consumer-trends-and-attitudes-towards-authentication-methods/): Global FIDO Alliance study reveals latest consumer trends and attitudes towards authentication methods and their perceived online security - [Vox: A world without passwords is in sight](https://fidoalliance.org/vox-a-world-without-passwords-is-in-sight/): Thanks to passkeys, you may not need to remember a password ever again. - [Android Authority: Passkeys make switching to Android more challenging, but not for long](https://fidoalliance.org/android-authority-passkeys-make-switching-to-android-more-challenging-but-not-for-long/): The FIDO Alliance is aware of passkey lock-in, and it’s actively working to address that: - [ZDNet: Passkeys take yet another big step towards killing off passwords](https://fidoalliance.org/zdnet-passkeys-take-yet-another-big-step-towards-killing-off-passwords/): One of the drawbacks to passkeys is that currently there's no way to import or export them between devices. The FIDO Alliance wants to change that. - [Bleeping Computer: Amazon says 175 million customers now use passkeys to log in](https://fidoalliance.org/bleeping-computer-amazon-says-175-million-customers-now-use-passkeys-to-log-in/): Amazon says 175 million customers now use passkeys to log in: - [MacRumors:](https://fidoalliance.org/macrumors/): FIDO Alliance Working on Making Passkeys Portable Across Platforms: - [Wired: The War on Passwords Is One Step Closer to Being Over](https://fidoalliance.org/wired-the-war-on-passwords-is-one-step-closer-to-being-over/): “Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced this month. - [The FIDO Alliance Launches Comprehensive Web Resource to Accelerate Passkey Adoption](https://fidoalliance.org/fido-alliance-launches-comprehensive-web-resource-to-accelerate-passkey-adoption/): Passkey Central provides leaders with education about passkeys and steps to implement them for consumer sign-ins - [FIDO Alliance Publishes New Specifications to Promote User Choice and Enhanced UX for Passkeys](https://fidoalliance.org/fido-alliance-publishes-new-specifications-to-promote-user-choice-and-enhanced-ux-for-passkeys/): The FIDO Alliance has published a working draft of a new set of specifications for secure credential exchange that, when standardized and implemented by credential providers, will enable users to securely move passkeys and all other credentials across providers. The specifications are the result of commitment and collaboration amongst members of the FIDO Alliance’s Credential Provider Special Interest Group  including representatives from: 1Password, Apple, Bitwarden, Dashlane, Enpass, Google, Microsoft, NordPass, Okta, Samsung and SK Telecom. - [FIDO APAC Summit 2024: Unlocking a Secure Tomorrow by Accelerating the Future of Authentication in Asia-Pacific](https://fidoalliance.org/fido-apac-summit-2024-accelerating-future-authentication-asia-pacific/): Building on the success of last year's summit in Vietnam, the FIDO APAC Summit 2024 in Kuala Lumpur, Malaysia, once again brought together thought leaders, policymakers, technology innovators, and industry experts from across the Asia-Pacific region. With over 350 attendees from 15 countries—including Australia, China, France, Hong Kong, India, Indonesia, Japan, Malaysia, the Philippines, Singapore, South Korea, Taiwan, Thailand, the USA, and Vietnam—this year's event served as a powerful platform for sharing knowledge, inspiring collaboration, and exploring the evolution of secure and convenient authentication technologies. - [Webinar: NIST SP 800-63 Digital Identity Standard: Updates and What it Means for Passkeys](https://fidoalliance.org/webinar-nist-sp-800-63-digital-identity-standard-updates-what-it-means-for-passkeys/): The fourth revision of the draft NIST SP 800-63-4 Digital Identity Guidelines is now open for public comment. - [Webinar: NIST SP 800-63 Digital Identity Standard: Updates & What it Means for Passkeys](https://fidoalliance.org/content-webinar-nist-sp-800-63-digital-identity-standard-updates-what-it-means-for-passkeys/): The fourth revision of the draft NIST SP 800-63-4 Digital Identity Guidelines is now open for public comment. - [White Paper: Displace Password + OTP Authentication with Passkeys](https://fidoalliance.org/white-paper-displace-password-otp-authentication-with-passkeys/): Husnan Bajwa, Beyond IdentityJosh Cigna, YubicoJing Gu, Beyond Identity - [Passkeys Hackathon Tokyo: A Showcase of Innovation and Excellence](https://fidoalliance.org/passkeys-hackathon-tokyo-a-showcase-of-innovation-and-excellence/): By Atsuhiro Tsuchiya, APAC Market Development Sr. Manager - [Bias in Biometrics: How Organizations Can Launch Remote Identity Verification Confidently](https://fidoalliance.org/bias-in-biometrics-how-organizations-can-launch-remote-identity-verification-confidently/): Most of us today are accustomed to unlocking our smartphones with a simple glance or touch. In the blink of the tech industry’s eye, biometric authentication has quickly become a normal part of our daily lives. - [White Paper: High Assurance Enterprise FIDO Authentication](https://fidoalliance.org/white-paper-high-assurance-enterprise-fido-authentication/): Sean Miller, RSA - [White Paper: FIDO Authentication for Moderate Assurance Use Cases](https://fidoalliance.org/white-paper-fido-authentication-for-moderate-assurance-use-cases/): Jerome Becquart, AxiadGreg Brown, AxiadMatt Estes, Amazon Web Services - [White Paper: Replacing Password-Only Authentication with Passkeys in the Enterprise](https://fidoalliance.org/white-paper-replacing-password-only-authentication-with-passkeys-in-the-enterprise/): Khaled Zaky, Amazon Web Services - [White Paper: FIDO Deploying Passkeys in the Enterprise – Introduction](https://fidoalliance.org/white-paper-fido-deploying-passkeys-in-the-enterprise-introduction/): Dean H. Saxe, Amazon Web Services, Co-Chair FIDO Enterprise Deployment Working Group - [White Paper: FIDO Attestation: Enhancing Trust, Privacy, and Interoperability in Passwordless Authentication](https://fidoalliance.org/fido-attestation-enhancing-trust-privacy-and-interoperability-in-passwordless-authentication/): Khaled Zaky, Amazon Web ServicesMonty Wiseman, Beyond IdentitySean Miller, RSA Security Eric Le Saint, Visa - [Webinar: Misconceptions about passkeys](https://fidoalliance.org/webinar-misconceptions-about-passkeys-a-panel-discussion-with-okta-and-the-fido-alliance/): In the years since passkeys were first announced, a lot has changed in their availability to consumers, nomenclature across platforms, and even implementation requirements. However, one thing that has yet to change is the need for more awareness on what passkeys are, how they work, and their benefits. - [Passkeys Webinar: Achieving End-to-End Passwordless](https://fidoalliance.org/passkeys-webinar-achieving-end-to-end-passwordless/): Authentication is a complicated problem with ever-creeping scope. Passkeys provide phishing-resistance at the point of authentication, but you need protection at enrollment and during the authenticated session thereafter, too, to truly fortify the authentication process against evolving threats.  - [Authenticate Update: 2024 Agenda Released](https://fidoalliance.org/authenticate-update-2024-agenda-released/): Carlsbad, Calif, August 14, 2024 – The FIDO Alliance has announced its agenda today for Authenticate 2024, held October 14-16, 2024, at the Omni La Costa Resort and Spa in Carlsbad, California. - [New CISA Guide Calls for Phishing-Resistant Forms of Authentication and Passkeys by Default](https://fidoalliance.org/cisa-secure-by-demand-guide-phishing-resistant-authentication-passkeys-by-default/): Andrew Shikiar, FIDO Alliance Executive Director & CEO - [Strengthening Authentication with Passkeys in Automotive and Beyond](https://fidoalliance.org/strengthening-authentication-passkeys-automotive-fido-munich-seminar-2024/): On July 16th, 2024, the FIDO Alliance held a seminar focused on the fit for FIDO authentication and device onboarding within the automotive industry. Co-hosted with Swissbit, the event had over 100 attendees who heard from various stakeholders on the need and opportunity for standards-based approaches to securing the automotive workforce and manufacturing process. Themes included how passkeys and FIDO-certified biometrics can help transform the future of in-vehicle experiences, especially with in-car payments, smart cars, and IoT. - [FIDO Munich Seminar: Strengthening Authentication with Passkeys in Automotive and Beyond](https://fidoalliance.org/content-presentations-fido-munich-seminar-strengthening-authentication-with-passkeys-in-automotive-and-beyond/): The FIDO Alliance recently held a seminar in Munich for a comprehensive dive into FIDO authentication and passkeys. The seminar, co-hosted by Swissbit, provided an exploration of the current state of passwordless technology, detailed discussions on how passkeys work, their benefits, case studies, and practical implementation strategies. Attendees learned about current and emerging elements of the FIDO Certified program and how they pertain across sectors, including a focus on automotive and payments use cases.  - [Battling Deepfakes with Certified Identity Verification](https://fidoalliance.org/battling-deepfakes-with-certified-identity-verification/): The digital transformation and the proliferation of e-identity schemes have escalated the need for secure and reliable online identity verification methods, especially in light of the alarming trend of AI-generated “deepfakes.” As internet users have learned about the increasing threat of deepfakes, they have become increasingly concerned about their identities being spoofed online, according to a new study conducted by the FIDO Alliance. As a result, deepfake awareness and the risks associated with them have steadily increased. - [Wedding Park Deploys Company-Wide Passwordless Authentication for Internal Cloud Service Logins](https://fidoalliance.org/case-study-wedding-park-deploys-company-wide-fido-authentication/): Corporate overview: - [UX Webinar Series: Essentials for Adopting Passkeys for your Consumer Authentication Strategy](https://fidoalliance.org/ux-webinar-series-slides-essentials-for-adopting-passkeys-for-your-consumer-authentication-strategy/): In part one of this four-part webinar series, attendees learned why major service providers are adopting passkeys as the foundation of their consumer authentication strategy. This webinar is for a nontechnical audience. It is intended to help you investigate the nuances of passkey roll-out strategies and end user experiences (UX) for consumers. - [UX Webinar Series: Aligning Authentication Experiences with Business Goals](https://fidoalliance.org/ux-webinar-series-slides-aligning-authentication-experiences-with-business-goals/): In the second of a four-part webinar series, attendees learned how to adapt your authentication experiences to better solve key metrics for consumer authentication. This webinar is for a nontechnical audience seeking user interface and workflow guidance for consumer authentication. - [UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consumer Authentication](https://fidoalliance.org/ux-webinar-series-slides-drive-revenue-and-decrease-costs-with-passkeys-for-consumer-authentication/): In the third of a four-part webinar series, attendees learned how to drive revenue and decrease costs with passkeys for consumer authentication. This webinar is for a nontechnical audience seeking to make sound business decisions for new consumer authentication strategies. - [UX Webinar Series: Essentials for Adopting Passkeys for your Consumer Authentication Strategy](https://fidoalliance.org/ux-webinar-series-essentials-for-adopting-passkeys-for-your-consumer-authentication-strategy/): In part one of this four-part webinar series, attendees learned why major service providers are adopting passkeys as the foundation of their consumer authentication strategy. This webinar is for a nontechnical audience. It is intended to help you investigate the nuances of passkey roll-out strategies and end user experiences (UX) for consumers. - [UX Webinar Series: Aligning Authentication Experiences with Business Goals](https://fidoalliance.org/ux-webinar-series-aligning-authentication-experiences-with-business-goals/): In the second of a four-part webinar series, attendees learned how to adapt your authentication experiences to better solve key metrics for consumer authentication. This webinar is for a nontechnical audience seeking user interface and workflow guidance for consumer authentication. - [UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consumer Authentication](https://fidoalliance.org/ux-webinar-series-drive-revenue-and-decrease-costs-with-passkeys-for-consumer-authentication/): In the third of a four-part webinar series, attendees learned how to drive revenue and decrease costs with passkeys for consumer authentication. This webinar is for a nontechnical audience seeking to make sound business decisions for new consumer authentication strategies. - [UX Webinar Series: Passkeys Design Guidelines AMA ask me anything!](https://fidoalliance.org/ux-webinar-series-passkeys-design-guidelines-ama/): In the final edition of a four-part webinar series attendees had the opportunity to ask FIDO Alliance subject matter experts anything in an: “Ask Me Anything” format! - [What is a passkey? Why Apple is betting on password-free tech](https://fidoalliance.org/what-is-a-passkey-password-apple-ios-18-google-microsoft-bank/): The digital realm has long struggled with the vulnerabilities inherent in password-based authentication systems. With iOS 18 launching in September, Apple introduces a groundbreaking API for developers to implement passkeys, transforming how users secure their online accounts. This innovation is set to create a password-less future, significantly enhancing user data protection. - [FIDO APAC Summit 2024 Announces Keynotes, Speakers, and Sponsors](https://fidoalliance.org/fido-apac-summit-2024-announces-keynotes-speakers-and-sponsors/): The FIDO Alliance is thrilled to announce the lineup for its highly anticipated second FIDO APAC Summit, set to take place at the JW Marriott Kuala Lumpur on September 10-11, 2024. Co-hosted by SecureMetric Technology and supported by Malaysia Digital Economy Corporation (MDEC) and CyberSecurity Malaysia, this premier event is dedicated to advancing phishing-resistant FIDO authentication across the region under the theme, "Unlocking a Secure Tomorrow." - [The Register: AWS is pushing ahead with MFA for privileged accounts. What that means for you.](https://fidoalliance.org/the-register-aws-is-pushing-ahead-with-mfa-for-privileged-accounts-what-that-means-for-you/): AWS is making multi-factor authentication (MFA) mandatory for privileged users, specifically management account root users and standalone account root users. Customers must enable MFA within a 30-day grace period to maintain account access. - [IT Brew: FIDO Alliance announces identity-proofing certification](https://fidoalliance.org/it-brew-fido-alliance-announces-identity-proofing-certification/): FIDO’s Face Verification Certification tests for security, liveness, and bias in remote identity verification technology through FIDO-accredited laboratories, and ISO and industry standards. Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, highlights that this certification technology “gives licensing companies added assurance that a vendor is performing well.” - [Find Biometrics: ID Talk: Passkeys, Standards, and Selfie Certification with FIDO’s Andrew Shikiar](https://fidoalliance.org/find-biometrics-id-talk-passkeys-standards-and-selfie-certification-with-fidos-andrew-shikiar/): Andrew Shikiar, FIDO’s Executive Director and CEO, discusses key topics in authentication and identity security on the ID Talk podcast (produced by Find Biometrics), including passkeys, phishing threats, deepfakes, FIDO's vendor accreditation, and the new Face Verification Certification program. - [AWS Expands MFA Requirements, Boosting Security and Usability with Passkeys](https://fidoalliance.org/aws-expands-mfa-requirements-boosting-security-and-usability-with-passkeys/): AWS has announced the introduction of FIDO passkeys for multi-factor authentication (MFA) to further secure customer accounts. This move aligns with AWS's objective to offer a secure cloud environment by incorporating secure-by-design and safe-by-default principles. FIDO passkeys offer a strong and easy MFA option, leveraging public key cryptography to resist phishing attempts and enhance overall account protection. - [ID Talk Podcast: Passkeys, Standards, and Selfie Certification with FIDO’s Andrew Shikiar](https://fidoalliance.org/id-talk-passkeys-standards-and-selfie-certification-with-fidos-andrew-shikiar/): The FIDO Alliance, founded in 2012, stands as a pivotal organization in the identity technology sector, advocating for strong passwordless authentication mechanisms. The Alliance has been instrumental in establishing influential industry standards, promoting the adoption of biometrics, and enhancing digital security through two-factor and multi-factor authentication technologies. - [InfoSecurity Magazine: #Infosec2024: CISOs Need to Move Beyond Passwords to Keep Up With Security Threats](https://fidoalliance.org/content-cisos-need-to-move-beyond-passwords-to-keep-up-with-security-threats/): Passwordless systems, even if they stop short of a full zero-trust environment, improve convenience as well as security. CISOs should look at approaches such as the FIDO model or web 3.0 technologies as a basis for future authentication systems. - [SC Media: Identiverse 2024: Deepfakes, passkeys and more](https://fidoalliance.org/sc-media-identiverse-2024-deepfakes-passkeys-and-more/): Two predominant themes stood out at last week's Identiverse 2024 conference in Las Vegas. First, there was the issue of how to defend against rapidly evolving advances in deepfakes, especially for live remote verification. Second, there was a common assumption that widespread adoption of passkeys is right around the corner, and that organizations must prepare to manage and secure passkeys when they become mainstream. - [White Paper: Synced Passkey Deployment: Emerging Practices for Consumer Use Cases](https://fidoalliance.org/white-paper-synced-passkey-deployment-emerging-practices-for-consumer-use-cases/): This paper explores the emerging practices surrounding the use of synced passkeys which allow passkey use across multiple devices by syncing the passkeys over the cloud, specifically addressing the initial choices and considerations for service providers (aka relying parties or RPs). These practices are in their early stages and are likely to progress, since operating systems, browsers, and passkey providers are still in a phase of enhancing functionality. This document outlines crucial areas such as registration, authentication, passkey management, and accessibility for RPs to consider and presents a range of emerging approaches for adopting this technology. The objective is to guide RPs through these budding strategies, acknowledging that the specifics of ensuring secure and convenient passkey usage may evolve as the digital landscape continues to advance. - [FIDO Alliance Osaka Seminar](https://fidoalliance.org/fido-alliance-osaka-seminar-presentations-photos/): FIDO Alliance held a one-day seminar in Osaka for a comprehensive dive into passkeys. The seminar covered the current state of passwordless technology, a deep dive on how passkeys work, their benefits, practical implementation strategies and considerations, regulatory considerations, and case studies.  - [FIDO Alliance addresses accuracy and bias in remote biometric identity verification technologies with first industry testing and certification program](https://fidoalliance.org/fido-alliance-addresses-accuracy-bias-in-remote-biometric-identity-verification-technologies-industry-first-testing-certification-program/): Face Verification Certification launched to bring confidence to ID ecosystem among rising online identity theft and bias concerns   - [FIDO Alliance Releases New Design Guidelines for Optimizing User Sign-in Experience with Passkeys](https://fidoalliance.org/new-design-guidelines-optimizing-user-sign-in-experience-with-passkeys/): May 29, 2024 – The FIDO Alliance today released new design guidelines to help accelerate passkey adoption and deployment.  - [Remote ID Verification – Bringing Confidence to Biometric Systems Consumer Insights 2024](https://fidoalliance.org/remote-identity-verification-biometric-systems-consumer-insights-2024/): Online identity theft has steadily risen in recent years, while the generative AI boom has driven a new wave of deepfake-powered attacks that threaten remote enrollment and identity security. Meanwhile, bias in biometric systems has been monitored for some time, varying significantly across solutions and impacting consumer trust and perception of the technology. - [CXMToday: Visa Unveils Card Updates](https://fidoalliance.org/cxmtoday-visa-unveils-card-updates/): Built on the latest Fast Identity Online (FIDO) standards, the Visa Payment Passkey Service confirms a consumer’s identity and authorises online payments with a quick scan of their biometrics like a face or fingerprint. When shopping online, Visa passkeys replace the need for passwords or one-time codes, enabling more streamlined, secure transactions. - [Identity Week: State of Michigan’s MiLogin supported by FIDO passkeys](https://fidoalliance.org/identity-week-state-of-michigans-milogin-supported-by-fido-passkeys/): The system leverages passkeys based on FIDO authentication promoting strong authentication, unifying Michigan’s approach to cybersecurity and improving the user experience. - [FindBiometrics: Visa Brings Passkeys to Online Payments in Major FIDO Victory](https://fidoalliance.org/visa-brings-passkeys-to-online-payments-in-major-fido-victory/): Visa has introduced passkeys to the payment industry, enabling customers to authorize online purchases through a biometric scan on their smartphones or computers when making a purchase online. - [FIDO Taipei Workshop: Securing the Edge with FDO](https://fidoalliance.org/content-presentations-fido-taipei-workshop-securing-fdo/): On April 24, 2024, the FIDO Alliance held its first ever in-person FDO Workshop at the Institute of Information Science, Academia Sinica Nangang Campus in Taipei. The event attracted over 100 attendees from 30 different organizations. This workshop was dedicated to unveiling the power of the FIDO Device Onboard (FDO)—a revolutionary open standard that simplifies and secures the device onboarding process by moving away from legacy approaches that often rely on inefficient and insecure passwords and other knowledge-based credentials. - [FIDO Taipei Workshop: Securing the Edge with FDO](https://fidoalliance.org/content-blog-fido-taipei-workshop-fdo/): On April 24, 2024, the FIDO Alliance held its first ever in-person FDO Workshop at the Institute of Information Science, Academia Sinica Nangang Campus in Taipei. The event attracted over 100 attendees from 30 different organizations. This workshop was dedicated to unveiling the power of the FIDO Device Onboard (FDO)—a revolutionary open standard that simplifies and secures the device onboarding process by moving away from legacy approaches that often rely on inefficient and insecure passwords and other knowledge-based credentials. - [Tech Radar: Navigating towards a passwordless future](https://fidoalliance.org/navigating-towards-a-passwordless-future/): Traditionally, passwords have served as the primary means of securing digital identities, yet their limitations are becoming increasingly evident. To pave the way for a passwordless future, accessibility is paramount. Any alternative authentication method must be inclusive, catering to users across diverse technological environments. Whether it's the latest smartphone or a dated desktop, the authentication process should seamlessly adapt. For example, solutions like the FIDO Alliance's Web Authentication (WebAuthn) standard aim to bridge this accessibility gap, enabling passwordless logins across a spectrum of devices and platforms. - [Security Informed: trinamiX Unveils Secure Face Authentication In Foldable Phones](https://fidoalliance.org/trinamix-unveils-secure-face-authentication-in-foldable-phones/): This touchless solution offers enhanced security and convenience, meeting the biometric security requirements set by organizations such as the International Internet Finance Authentication Alliance (IIFAA), the FIDO Alliance, and Android (Google). - [The Fintech Times: Visa Reveals Digital Products to be Launched Over the Year Catering to Evolving Consumer Demands](https://fidoalliance.org/visa-reveals-digital-products-catering-to-evolving-consumer-demands/): Built on the latest Fast Identity Online (FIDO) standards, the Visa Payment Passkey Service confirms a consumer’s identity and authorises online payments with a quick scan of their biometrics like a face or fingerprint. When shopping online, Visa passkeys replace the need for passwords or one-time codes, enabling more streamlined, secure transactions. - [PYMNTS: Visa Recasts Digital Wallet Landscape at Intersection of Identity and Payments](https://fidoalliance.org/pymnts-visa-recasts-digital-wallet-landscape-at-intersection-of-identity-and-payments/): Visa has enhanced their security and streamlined transactions by onboarding passkeys. Now consumers can confirm their identity and authorize online payments through facial or fingerprint scans, eliminating the need for passwords and one-time codes. - [Biometric Update: Authenticate 2024](https://fidoalliance.org/biometric-update-authenticate-2024/): Authenticate 2024Omni La Costa Resort & Spa, Carlsbad, CAOctober 14-16, 2024 - [Biometric Update: Passkeys continue march to mainstream with Visa, WhatsApp updates](https://fidoalliance.org/biometric-update-passkeys-continue-march-to-mainstream-with-visa-whatsapp-updates/): FIDO2 protocol finding wide adoption but analysts may have found MITM vulnerability. - [FIDO Seminar at RSAC: The State of Authentication 2024: The Global Progress Past Passwords](https://fidoalliance.org/content-presentations-fido-seminar-at-rsac-2024/): FIDO Alliance's seminar at RSAC 2024 included the latest with FIDO authentication and passkeys – and more! During the seminar, the FIDO Alliance and its industry stakeholders discussed the latest developments in the global movement to passwordless technology for better security and user experiences. - [State of Michigan’s MiLogin  Adopts Passkeys](https://fidoalliance.org/state-of-michigans-milogin-adopts-passkeys/): The State of Michigan's Department of Technology, Management &  Budget (DTMB) is a principal department of the state’s government  responsible for providing a wide range of support functions to other state  agencies.   - [The Register: Microsoft, Google do a victory lap around passkeys](https://fidoalliance.org/the-register-microsoft-google-do-a-victory-lap-around-passkeys/): Passkeys are based on a FIDO alliance standard that's supported by Apple, Microsoft and Google. Think of them as password replacements. The tech, simply put, works like this: When you create an account for a website or app, your device generates a cryptographic public-private key pair. - [Silicon Republic: Microsoft and Google are pushing harder for passkeys](https://fidoalliance.org/silicon-republic-microsoft-and-google-are-pushing-harder-for-passkeys/): Passkeys have been growing rapidly in popularity. In the UK, for instance, more than half the population has enabled passkeys on at least one of their accounts, according to a FIDO Alliance survey published this week. What’s more, around a fifth have passkeys activated on every account that allows them. - [TechCrunch: Google expands passkey support to its Advanced Protection Program ahead of the US presidential election](https://fidoalliance.org/techcrunch-google-expands-passkey-support-to-its-advanced-protection-program-ahead-of-the-us-presidential-election/): Google is introducing passkey support to its Advanced Protection Program (APP), designed for individuals facing elevated risks of targeted attacks, including campaign workers, candidates, journalists, human rights activists, and others. The company reports that passkeys have authenticated users over 1 billion times across more than 400 million Google Accounts since the introduction of passkey support in 2022. - [Microsoft Blog: Microsoft introduces passkeys for consumer accounts](https://fidoalliance.org/microsoft-blog-microsoft-introduces-passkeys-for-consumer-accounts/): Ten years ago, Microsoft envisioned a bold future: a world free of passwords. Every year, we celebrate World Password Day by updating you on our progress toward eliminating passwords for good. Today, we’re announcing passkey support for Microsoft consumer accounts, the next step toward our vision of simple, safe access for everyone. - [ZDNet: Two years in, Google says passkeys now protect more than 400 million accounts](https://fidoalliance.org/zdnet-two-years-in-google-says-passkeys-now-protect-more-than-400-million-accounts/): Google Account users have authenticated themselves using passkeys more than 1 billion times, but passwords are likely to be around for years. - [Google Blog: Passkeys, cross-account protection and new ways we’re protecting your accounts](https://fidoalliance.org/google-blog-passkeys-cross-account-protection-and-new-ways-were-protecting-your-accounts/): For World Password Day, we’re sharing updates to passkeys across our products and sharing more ways we’re keeping people safe online. - [CNET: World Password Day: We’re closer to ditching this crackable tech](https://fidoalliance.org/cnet-world-password-day-were-closer-to-ditching-this-crackable-tech/): Passkeys promise to be a big help, but until they take hold, we all need to make sure we're still using good passwords. - [The Washington Post: Microsoft is changing how you log in to your accounts](https://fidoalliance.org/the-washington-post-microsoft-is-changing-how-you-log-in-to-your-accounts/): Microsoft 365, Copilot and Skype accounts can use "passkeys", which are more secure than passwords. - [New Survey: Half of People Use Passkeys as Frustrations with Passwords Continue](https://fidoalliance.org/new-survey-half-of-people-use-passkeys-as-frustrations-with-passwords-continue/): 20% of the world’s top 100 websites now support the password alternative - [Verdict: OneSpan: Partner Ecosystem Profile](https://fidoalliance.org/verdict-onespan-partner-ecosystem-profile/): The company’s various solutions include regulatory compliance, PSD2 compliance, FIDO standard, fraud prevention, mobile app security, transaction signing, digital onboarding and omnichannel security solutions. It operates in North America, Europe and the Asia Pacific regions. - [Tech telegraph: WhatsApp now rolling out passkey support for iPhone users](https://fidoalliance.org/tech-telegraph-whatsapp-now-rolling-out-passkey-support-for-iphone-users/): Passkey is a technology developed by the FIDO Alliance in collaboration with major companies like Apple, Google, and Microsoft. Instead of traditional passwords, it enables users to log in using secure methods like facial recognition or biometrics, eliminating the need to create and type a passcode. - [Biometric Update: NIST issues guidance to fit passkeys into digital identity recommendations](https://fidoalliance.org/biometric-update-nist-issues-guidance-to-fit-passkeys-into-digital-identity-recommendations/): Andrew Shikiar, CEO of the FIDO Alliance, noted that the updated NIST guidance confirms passkeys' ability, along with other FIDO authenticators, to meet AAL2 and AAL3 requirements. Synchronized passkeys can achieve AAL2, while device-bound passkeys can reach AAL3. - [TechCrunch: WhatsApp adds global support for passkeys on iOS](https://fidoalliance.org/techcrunch-whatsapp-adds-global-support-for-passkeys-on-ios/): WhatsApp is launching passkey verification on iOS, eliminating the requirement for users to manage SMS one-time passcodes. The company announced on Wednesday that this feature is currently being rolled out and will soon be accessible to all iOS users. - [NIST cites phishing resistance of synced passkeys in Digital Identity Guidelines update](https://fidoalliance.org/nist-cites-phishing-resistance-of-synced-passkeys-in-digital-identity-guidelines-update/): Andrew Shikiar, FIDO Alliance Executive Director & CEO - [FIDO Paris Seminar: Mastering Passkeys, the Future of Secure Authentication:](https://fidoalliance.org/fido-paris-seminar/): FIDO Alliance and host sponsor Thales held a one-day seminar in Paris for a comprehensive dive into passkeys. The seminar provided an exploration of the current state of passwordless technology, detailed discussions on how passkeys work, their benefits, practical implementation strategies and considerations, and case studies.  - [Tech Radar: Bitwarden now supports passkeys on iOS devices](https://fidoalliance.org/tech-radar-bitwarden-now-supports-passkeys-on-ios-devices/): Popular free password manager Bitwarden now supports passkeys on iOS devices. The news follows the recent trend of password managers bringing passkey support to mobile, including Keeper and Proton Pass. Bitwarden added passkey support to its desktop browser extension last year, and now users can create and store passkeys on their iOS app too. Android support is yet to arrive, however. - [GB News: Elon Musk just killed passwords on X, here’s what you need to use a passkey to login](https://fidoalliance.org/gb-news-elon-musk-just-killed-passwords-on-x-heres-what-you-need-to-use-a-passkey-to-login/): Passkeys were developed by the FIDO Alliance, an industry body with the stated aim of helping to "reduce the world’s over-reliance on passwords" with the likes of Apple, Google and Microsoft amongst its members. First promoted as an alternative to passwords back in mid-2022, the clever system relies on the same biometrics that allow you login to your iPhone, iPad, Windows PCs, Samsung phones and tablets, Android phones, and dozens more, without typing out a password or PIN. - [Dark Reading: Selecting the Right Authentication Protocol for Your Business](https://fidoalliance.org/dark-reading-selecting-the-right-authentication-protocol-for-your-business/): Authentication protocols like passkeys serve as the backbone of online security, enabling users to confirm their identities securely and access protected information and services. Passkeys have been deployed by several major organizations such as Google, Apple, Shopify, Best Buy, TikTok, and GitHub. - [TechCrunch: X adds support for passkeys globally on iOS](https://fidoalliance.org/techcrunch-x-adds-support-for-passkeys-globally-on-ios/): X has officially extended support for passkeys to all global iOS users. This news was announced on the heels of the social media platform introducing passkeys to US-based users earlier in January. - [Tech Telegraph: 5 easy tasks to supercharge your cybersecurity](https://fidoalliance.org/tech-telegraph-5-easy-tasks-to-supercharge-your-cybersecurity/): This post summarises five ways for consumers to improve their cybersecurity. FIDO USB keys and passkeys are included. Of passkeys, the article said: "Services including Google are switching to passwordless 'passkey' authentication that supercharges security without needing 2FA, but that technology is still in its early adoption days." - [Source Security: Introducing the latest innovation from Sentry Enterprises: The batteryless multi-funciton biometric credential](https://fidoalliance.org/source-security-introducing-the-latest-innovation-from-sentry-enterprises-the-batteryless-multi-funciton-biometric-credential/): Sentry Enterprises announced its latest innovation - a multi-factor physical and logical access solution that aims to offer more affordable and secure biometric security. It is FIDO2 compliant. - [Android Headlines: Keeper password manager app to get Passkeys support following browser extensions](https://fidoalliance.org/android-headlines-keeper-password-manager-app-to-get-passkeys-support-following-browser-extensions/): Keeper Security is introducing passkeys support to its smartphone applications, addressing the ongoing struggle websites face with user authentication methods. Passkeys, created by FIDO, allows users to ditch traditional usernames and passwords and securely log in to a website, app, or other digital services. - [Security Today: Mobile IDs, MFA and Sustainability Emerge as Top Trends in New HID Report](https://fidoalliance.org/security-today-mobile-ids-mfa-and-sustainability-emerge-as-top-trends-in-new-hid-report/): The end of passwords is near as the FIDO Alliance is paving the way toward new and more secure authentication options that will be part of a more robust Zero Trust architecture. - [Silicon Republic: The long road to passkeys: When will they become mainstream?](https://fidoalliance.org/silicon-republic-the-long-road-to-passkeys-when-will-they-become-mainstream/): Andrew Shikiar, CEO at FIDO Alliance discusses the various benefits of passkeys and the long-discussed goal of removing our password dependence. - [Innovation & Tech Today: Minimize Risk and Fraud With New Technologies](https://fidoalliance.org/innovation-tech-today-minimize-risk-and-fraud-with-new-technologies/): Biometric authentication, advocated by FIDO, revolutionizes fraud prevention by replacing vulnerable passwords. With many users abandoning transactions due to forgotten passwords, biometrics offer secure verification through PINs, fingerprints, or facial scans, mitigating cyber risks. - [Cloudflare TV: Why security keys are the safest way to secure the web](https://fidoalliance.org/cloudflare-tv-why-security-keys-are-the-safest-way-to-secure-the-web/): Cloudflare CTO John Graham-Cumming joins FIDO Alliance's Andrew Shikiar in a fireside chat to discuss the significance of hardware keys in combating online attacks like phishing, offering insights for businesses seeking to protect their employees. - [Recap: Virtual Summit: Demystifying Passkey Implementations](https://fidoalliance.org/recap-virtual-summit-demystifying-passkey-implementations/): By: FIDO staff - [Identity Week: HID’s 2024 report highlights mobile IDs, MFA, and sustainability in security trends](https://fidoalliance.org/identity-week-hids-2024-report-highlights-mobile-ids-mfa-and-sustainability-in-security-trends/): With over 83% of organisations currently using MFA, the shift away from password-dependency is clear. However, the report indicates a slower but growing implementation of Zero Trust architectures, currently in place in up to 16% of larger organisations. The development of standards like FIDO heralds a move toward more secure authentication options. - [Neowin: Proton Pass gets passkey support for both free and paid users](https://fidoalliance.org/neowin-proton-pass-gets-passkey-support-for-both-free-and-paid-users/): Proton has announced passkey support in its Proton Pass password manager, which now offers enhanced security and usability for both free and paid users across all platforms. - [Biometric Update: FIDO’s influence expands with new security key and board member](https://fidoalliance.org/biometric-update-fidos-influence-expands-with-new-security-key-and-board-member/): Cisco has further solidified its commitment to passkeys by joining the FIDO Alliance’s board of member representatives. Andrew Shikiar, executive director and CEO of the FIDO Alliance welcomes Cisco's expanded involvement, noting their historical contributions through Duo Security and now as an official member. - [Tech Telegraph: Best PC and laptop security accessories 2024](https://fidoalliance.org/tech-telegraph-best-pc-and-laptop-security-accessories-2024/): If you haven’t had the pleasure of using biometrics on a device for authentication through Windows Hello, you’re missing out. It’s much faster and easier than having to type in your password. - [Android Headlines: X Android App Beta Gets Password-less Passkeys Authentication Support](https://fidoalliance.org/android-headlines-x-android-app-beta-gets-password-less-passkeys-authentication-support/): Passkeys enhance security by eliminating traditional passwords and relying on the interaction between Private and Public keys for user authentication, reducing the instance of phishing attacks and data breaches. Passkeys are gaining traction among various platforms, including websites, gaming platforms, and Windows 11 apps. - [The New Stack: 3 Steps to Make Logins with Passkeys Reliable](https://fidoalliance.org/the-new-stack-3-steps-to-make-logins-with-passkeys-reliable/): Passkeys offer modern and secure authentication by enabling cryptography-backed user authentication with a frictionless user experience. With users becoming more accustomed to passkeys, 2024 is the year to ditch passwords and upgrade to passkeys with these considerations in mind. - [TeleMedia Online: Should All Mobile Business Apps Scrap Passwords and Integrate Biometrics?](https://fidoalliance.org/telemedia-online-should-all-mobile-business-apps-scrap-passwords-and-integrate-biometrics/): Now that all the most advanced mobile devices on the market offer biometric authentication, it’s a good opportunity for apps to align with this and integrate it. FIDO Alliance reported that around 80 percent of data leaks are linked to passwords, so it would be useful for a better alternative to become more widespread. - [Security Magazine: Cyber Insights 2024: A Dire Year for CISOs?](https://fidoalliance.org/security-magazine-cyber-insights-2024-a-dire-year-for-cisos/): “CISOs are too often overlooked or low on resources, funding and/or business support to properly implement change,” adds Andrew Shikiar, executive director at FIDO. “Resting the legal liability on one individual is overlooking the vacuum of responsibility and engagement at the top of organizations that is preventing meaningful change and true cyber resilience.” - [Biometric Update: FIDO Alliance ensures long-term value of its specifications in post quantum era](https://fidoalliance.org/biometric-update-fido-alliance-ensures-long-term-value-of-its-specifications-in-post-quantum-era/): The FIDO Alliance is actively involved in integrating PQC into its standards to ensure long-term efficacy and security, forming working groups to understand the implications and develop migration strategies. With the addition of Prove Identity to its Board of Directors, the coalition continues its mission to shaping future standards for identity authentication. - [Engadget: 1Password adds passkey support for Android](https://fidoalliance.org/engadget-1password-adds-passkey-support-for-android/): Passkey adoption is on the rise, showcased by 1Password's support of passkeys for Android devices to provide a more secure alternative to traditional passwords through the use of public and private keys. - [Mercari’s Passkey Authentication Speeds Up Sign-in 3.9 Times](https://fidoalliance.org/mercaris-passkey-authentication-speeds-up-sign-in-3-9-times/): Mercari, Inc. is a Japanese e-commerce company, offering marketplace services as well as online and mobile payment solutions. With Mercari users can sell items on the marketplace, and make purchases in physical stores. In 2023, they implemented passkeys. This article will explain the motivation behind their decision and the results they achieved. - [Tech Game World: Passkeys are arriving on PlayStation: how the smart alternative to the password works](https://fidoalliance.org/tech-game-world-passkeys-are-arriving-on-playstation-how-the-smart-alternative-to-the-password-works/): The advantages are many. Let’s start by saying that Passkeys are more secure than traditional passwords. These are fraud resistant and follow standards Fast Identity Online (FIDO )established by the FIDO Alliance, a global organization of which the Sony Group (owner of PlayStation) is part. The FIDO Alliance is responsible for defining and promoting the more advanced authentication standards for a wide range of devices and platforms. The goal is to reduce the dependence on passwords, which are considered an obsolete method in contemporary times. These standards are supported by leading companies and institutions in the technology sector, with which PlayStation itself has collaborated to offer an optimal access experience. - [PCMag: No More Passwords: Sony Adopts Passkeys for PlayStation 4, PS5](https://fidoalliance.org/pcmag-no-more-passwords-sony-adopts-passkeys-for-playstation-4-ps5/): Sony has introduced passkey support for PlayStation, eliminating the need for traditional passwords. Users can now opt for a more secure and convenient sign-in method by setting up a passkey stored on their phone or laptop. Passkeys use unique cryptographic keys that remain on the device which are phishing resistant, and can be accessed through other devices in case of loss. - [EMVCo and FIDO Alliance Provide Essential Guidance on Use of FIDO with EMV 3DS](https://fidoalliance.org/emvco-and-fido-alliance-provide-essential-guidance-on-use-of-fido-with-emv-3ds/): As leaders in authentication and payments spaces respectively, the FIDO Alliance and EMVCo collaborate to provide guidance on how FIDO authentication can be incorporated in payment use-cases allowing merchants, acquirers/PSPs and issuers to have a consistent way to submit and process FIDO authentication data.   - [Cybersecurity Policy Forum: Identity, Authentication and the Road Ahead](https://fidoalliance.org/cybersecurity-policy-forum-identity-authentication-and-the-road-ahead/): 2023 demonstrated that we still have a lot of work to do when it comes to protecting Americans from identity theft and identity-related cybercrime. The GAO and FinCEN together documented more than $300 billion in identity-related cybercrime, DHS’ Cyber Safety Review Board (CSRB) outlined how weaknesses in legacy authentication tools enabled adversaries to launch a wave of high-profile attacks, and millions of Americans struggled to recover from identity theft. Meanwhile, the introduction of new tools powered by biometrics and AI to help block attacks also raised concerns about equity and bias, and in the physical world, many Americans still struggle to get foundational credentials that they need to prove who they are. As 2024 kicks off, these issues will all continue to be front and center.   - [Security Journal: Fingerprints agrees distribution partnership with Ansal Component](https://fidoalliance.org/security-journal-fingerprints-agrees-distribution-partnership-with-ansal-component/): Fingerprints’ biometric access solution is designed for physical and logical access devices and applications such as smart locks, FIDO tokens, crypto wallets and more. - [FinExtra: Mitigating fraud risk: effective strategies for small financial institutions](https://fidoalliance.org/finextra-mitigating-fraud-risk-effective-strategies-for-small-financial-institutions/): Passwords are one of the most common targets for fraudsters. Strengthening password security demands robust authentication methods, risk-based measures and behavioural analysis to detect anomalies. Active exploration of innovations like Passwordless Login, based on the robust Fast Identity Online 2 (FIDO2) standards developed by the FIDO Alliance, is essential to bolster online security and authentication.  - [Engadget: PlayStation now supports passkey sign-ins](https://fidoalliance.org/engadget-playstation-now-supports-passkey-sign-ins/): Sony Interactive Entertainment (SIE) introduces passkey support for PlayStation accounts, allowing users to log in via their mobile device or computer's screen unlocking method like PIN, fingerprint, or facial recognition. Passkeys enhance security by preventing reuse or sharing, reducing vulnerability to phishing and data breaches. - [The Verge: Now you can sign into your PlayStation account without a password](https://fidoalliance.org/the-verge-now-you-can-sign-into-your-playstation-account-without-a-password/): Sony PlayStation has introduced passkey support for account logins, enabling users to authenticate without passwords. Similar to Nintendo's implementation, users can now use authentication methods like iOS Face ID or Android fingerprint sensors for account access. - [FIDO Alliance Announces Call for Speakers and Sponsors for FIDO APAC Summit 2024](https://fidoalliance.org/fido-alliance-announces-call-for-speakers-sponsors-for-fido-apac-summit-2024/): February 21, 2024 - [Intelligent Health.Tech: Site security: Passwordless fingerprint authentication](https://fidoalliance.org/intelligent-health-tech-site-security-passwordless-fingerprint-authentication/): Thales has announced the SafeNet IDPrime FIDO Bio Smart Card – a security key that enables strong multi-factor authentication (MFA) for the enterprise. This new contactless smart card allows users to access enterprise devices, applications and cloud services using a fingerprint instead of a password.  - [StateTech Magazine: How Passwordless Authentication Supports Zero Trust](https://fidoalliance.org/statetech-magazine-how-passwordless-authentication-supports-zero-trust/): Utilizing FIDO passkeys addresses security risks associated with password-based systems which often lead to account takeovers, data breaches and even stolen identities. While password managers and legacy forms of two-factor authentication offer incremental improvements, there has been industry-wide collaboration to create passkey sign-in technology that is more convenient and more secure. - [TechTarget: How passwordless helps guard against AI-enhanced attacks](https://fidoalliance.org/techtarget-how-passwordless-helps-guard-against-ai-enhanced-attacks/): In the age of generative AI, phishing scams (which already account for 90% of data breaches according to CISA) are becoming increasingly persuasive and humanlike. To mitigate these evolving threats, organizations should prioritize transitioning to passkeys, a phishing-resistant alternative backed by industry giants like Google, Apple, Amazon, and Microsoft, to enhance both security and usability. - [The Wall Street Journal: Forget Passwords and Badges: Your Body Is Your Next Security Key](https://fidoalliance.org/the-wall-street-journal-forget-passwords-and-badges-your-body-is-your-next-security-key/): Andrew Shikiar, executive director of the FIDO Alliance, emphasizes the importance of biometric scans as hacking attempts and other cyber threats have become more sophisticated. - [White Paper: Addressing FIDO Alliance’s Technologies in Post Quantum World](https://fidoalliance.org/white-paper-addressing-fido-alliances-technologies-in-post-quantum-world/): There has been considerable press, a number of papers, and several formal initiatives concerned with quantum computing’s impact on cryptographic algorithms and protocols. Most standards development organizations are addressing concerns about the impact on the security of the currently deployed cryptographic algorithms and protocols. This paper presents FIDO Alliance initiatives that address the impact of quantum computing on the Alliance’s specifications and how the FIDO Alliance is working to retain the long-term value provided by products and services based on the FIDO Alliance specifications.  - [Webinar: Next-Gen Authentication: Implementing Passkeys for your Digital Services](https://fidoalliance.org/webinar-next-gen-authentication-implementing-passkeys-for-your-digital-services/): Despite their shortcomings, passwords have been a necessary evil; an unavoidable reality. No wonder online services have struggled to get rid of passwords for nearly three decades. Not anymore! Passkeys have emerged as a modern form of authentication, offering a superior user experience and higher security. With over 8 billion accounts already protected by passkeys, the question for service providers isn’t “if” they should be adopting passkeys, rather “when” and “how”.  - [WIRED: I Stopped Using Passwords. It’s Great—and a Total Mess](https://fidoalliance.org/wired-i-stopped-using-passwords-its-great-and-a-total-mess/): More than 8 billion online accounts can set up passkeys right now, says Andrew Shikiar, the chief executive of the FIDO Alliance, an industry body that has developed the passkey over the past decade. So, I decided to kill my passwords. - [TechRound: Top 10 UK Business Cybersecurity Providers](https://fidoalliance.org/techround-top-10-uk-business-cybersecurity-providers/): Intercede’s solutions offer maximum protection against data breaches, focusing on: - [国际安全期刊》:MFA 在打击网络钓鱼中的作用](https://fidoalliance.org/%e5%9b%bd%e9%99%85%e5%ae%89%e5%85%a8%e6%9c%9f%e5%88%8a%e3%80%8b%ef%bc%9amfa-%e5%9c%a8%e6%89%93%e5%87%bb%e7%bd%91%e7%bb%9c%e9%92%93%e9%b1%bc%e4%b8%ad%e7%9a%84%e4%bd%9c%e7%94%a8/) - [International Security Journal: The role of MFA in the fight against phishing](https://fidoalliance.org/international-security-journal-the-role-of-mfa-in-the-fight-against-phishing/): Based on FIDO Alliance and W3C standards, passkeys replace passwords with cryptographic key pairs.This requires the user to further authenticate themselves off-site using either soft or hardware-bound solutions. - [Gear Patrol: Want a Faster, More Secure Way of Logging into X on Your iPhone? Use a Passkey](https://fidoalliance.org/gear-patrol-want-a-faster-more-secure-way-of-logging-into-x-on-your-iphone-use-a-passkey/): X (formerly Twitter) has introduced passkeys for iPhone users as an alternative to traditional passwords. Passkeys offer heightened security through its inherent two-step authentication system and are generated by the device along with the X account, making it less vulnerable to phishing and unauthorized access. - [ITPro: The end of passwords – and how businesses will embrace it](https://fidoalliance.org/itpro-the-end-of-passwords-and-how-businesses-will-embrace-it/): Big tech firms including Microsoft, Apple and Google have been moving towards a passwordless future for several years, with solutions such as security keys and more recently, passkeys, starting to take off as part of multi-factor authentication (MFA) setups.  - [GovTech: Forum Questions Future of Digital Identity, Path Forward](https://fidoalliance.org/govtech-forum-questions-future-of-digital-identity-path-forward/): At the recent ID policy forum, the FIDO Alliance, The Identity Theft Resource Center, and other cybersecurity experts discussed the need for new identity verification methods as data breaches reached record levels in 2023. Panelists argued that relying solely on knowledge-based methods like passwords and Social Security numbers is no longer secure and highlighted the importance of multifactor authentication, passkeys, and biometric checks. - [PCMag: Passkeys Are Here: We Just Have to Convince People to Use Them](https://fidoalliance.org/pcmag-passkeys-are-here-we-just-have-to-convince-people-to-use-them/): In a recent identity and authentication conference, Andrew Shikiar, Executive Director of the FIDO Alliance, declared 2023 as the "year of the passkey," citing 8 billion user accounts with passkey access. Shikiar also emphasized the importance of passkeys in enhancing security, streamlining customer experiences, and gradually eliminating the reliance on traditional passwords, while acknowledging ongoing challenges and gaps in support across different industries and platforms. - [Recap: 2024 Identity, Authentication and the Road Ahead Policy Forum](https://fidoalliance.org/recap-2024-identity-authentication-and-the-road-ahead-policy-forum/): What's the state of identity and authentication in 2024? - [SRF: Change your Password Day: New standard passkey: Are passwords soon a thing of the past?](https://fidoalliance.org/srf-change-your-password-day-new-standard-passkey-are-passwords-soon-a-thing-of-the-past/): Passwords are as old as computers – but are still considered insecure and cumbersome. But now there is hope: “Passkey” is the name of a new procedure in which you don’t have to remember passwords or type in codes – and it’s still more secure. Behind it is FIDO, an alliance of large IT companies. SRF digital editor Peter Buchmann explains what it's about. - [IdentityWeek: Mastercard: 80% of data breaches linked to passwords](https://fidoalliance.org/identityweek-mastercard-80-of-data-breaches-linked-to-passwords/): Mastercard is modernising digital interactions underpinned by biometric and AI-powered tools which provide less friction than endless password authentication. The company has joined the FIDO Alliance that calls for  encrypted passkey solutions and specifications to end passwords. The Mastercard Biometric Authentication Service provides a FIDO certified passwordless authentication that allows users to verify their identity using biometrics. - [PCMag: X Now Supports Passkey Login on iOS](https://fidoalliance.org/pcmag-x-now-supports-passkey-login-on-ios/): X (previously known as Twitter) will now let its users login with a passkey instead of a password - but only on iOS devices. X announced its intentions to adopt the passwordless technology a while back, and now it has launched the feature for iPhone users. It allows for a quicker way to login, only requiring users to authenticate with whatever they use to lock their device, such as their fingerprint, FaceID, or PIN.  - [TechCrunch: X adds support for passkeys on iOS after removing SMS 2FA support last year](https://fidoalliance.org/techcrunch-x-adds-support-for-passkeys-on-ios-after-removing-sms-2fa-support-last-year/): X, formerly known as Twitter, has introduced support for passkeys, a secure login method for U.S. users on iOS devices. This implementation follows the removal of SMS 2FA support for non-paying, which was criticized for reducing overall security last year. - [FIDO Alliance Announces Call for Speakers for Authenticate 2024](https://fidoalliance.org/fido-alliance-announces-call-for-speakers-for-authenticate-2024/): Carlsbad, Calif., January 24, 2024 - The FIDO Alliance is pleased to announce the return of Authenticate, the only industry conference dedicated to all aspects of user authentication – including a focus on FIDO-based sign-ins with passkeys.  - [Computer Weekly: Thanks to AI tools, attackers also have an easy time of it](https://fidoalliance.org/computer-weekly-thanks-to-ai-tools-attackers-also-have-an-easy-time-of-it/): Instead of fighting AI with AI, it's time for companies to rewrite the rules and get to the root of the problem - and that's traditional login methods. A byline from Rolf Lindemann. - [Professional Security Magazine: Mitigating AI security risks](https://fidoalliance.org/professional-security-magazine-mitigating-ai-security-risks/): Major tech companies and members of the FIDO Alliance such as Google, Apple, and Microsoft have been aiming to eliminate passwords completely. The use of alternative, modern authentication methods such as passkeys and security keys based on the FIDO protocol, are phishing-resistant and cannot be circumvented by AI. - [Retail Banker International: Banks don’t have to compromise on security to prioritise consumer convenience](https://fidoalliance.org/retail-banker-international-banks-dont-have-to-compromise-on-security-to-prioritise-consumer-convenience/): Biometric authentication powered by the global FIDO standard is the way forward to meet the needs of customers, but also the diverse requirements of banks and other financial institutions. - [The Wall Street Journal: 11 Technology Trends To Watch This Year](https://fidoalliance.org/the-wall-street-journal-11-technology-trends-to-watch-this-year/): Major companies like Google, Apple, and Amazon have adopted passkeys as their secure login method. With over eight billion passkey-enabled accounts and an anticipated 20 billion by the end of 2024, passkeys offer enhanced protection against hacking attempts and minimize the risk of security breaches. - [Techopedia: Secure Authentication: Will Passkeys Kill the Password?](https://fidoalliance.org/techopedia-secure-authentication-will-passkeys-kill-the-password/): Passkeys represent a revolutionary shift in online authentication, which could mean a potential end to the traditional password methods. Supported by Apple, Google, and Microsoft, FIDO passkeys utilize biometrics (or device PINs) to offer a more streamlined, user-friendly, and secure method of protecting online identities. - [2023 FIDO Seoul Public Seminar: Charting the Future of Online Authentication with Passkeys](https://fidoalliance.org/2023-fido-seoul-public-seminar-charting-the-future-of-online-authentication-with-passkeys/): The FIDO Seoul Public Seminar, “Passkeys – Online Authentication Paradigm Shift,” was hosted on December 5, 2023, at the SK Telecom Headquarters in Seoul by SK Telecom’s developer community, DEVOCEAN. This marked yet another significant milestone in the journey towards simpler and stronger online authentication. The event drew an audience of over 200, showcasing a myriad of updates and advancements in the realm of passkeys. - [Webinar Recap: Passkey Technology Implementation and Application](https://fidoalliance.org/webinar-recap-passkey-technology-implementation-and-application/): On December 27, 2023, FIDO China Working Group successfully hosted a webinar titled "Passkeys Technology Implementation and Application." Chaired by Henry Chai, who also serves as the co-chair of FIDO China Working Group, the event provided a highly professional platform for discussion. Yang Li (OPPO), Shaobo Han (Uni-ID), and Mengyang Lin (FIT2CLOUD) joined as guest speakers and shared their insights and practical experiences regarding the implementation and application of passkeys technology. Over 100 industry professionals attended the event and actively participated in post-sharing discussions. - [IT Security Wire: Key Strategies for Enterprise Cybersecurity in 2024](https://fidoalliance.org/it-security-wire-key-strategies-for-enterprise-cybersecurity-in-2024/): In 2024, companies will see more adoption of passkeys and other MFA methods to access business assets. Passkey adoption, along with biometrics, hardware tokens, and public-key cryptography, will replace the use of passwords. These security technologies will also help mitigate phishing and social engineering, which target credential theft. One way to reduce risk and boost security patches is the usage of proximity badges, physical tokens, or USB devices (FIDO2-compliant keys). - [Geeky Gadgets: 2024 Cybersecurity trends with the evolution of artificial intelligence](https://fidoalliance.org/geeky-gadgets-2024-cybersecurity-trends-with-the-evolution-of-artificial-intelligence/): The traditional password system is becoming obsolete, making way for more secure methods like FIDO standard passkeys. These new authentication tools, (which can be physical or digital), don’t require users to remember complex passwords and are designed to reduce the risk of security breaches. - [The Verge: Passkeys: All the news and updates around passwordless sign-on](https://fidoalliance.org/the-verge-passkeys-all-the-news-and-updates-around-passwordless-sign-on/): By using authentication mechanisms built into a users own device offering heightened security, passkeys are expected to replace passwords in the near future. Backed by Apple, Google, and Microsoft, passkeys are built on WebAuthn tech and stored directly on your device, making them more secure than passwords or PINs which can easily be stolen. - [Dark Reading: Getting Started With Passkeys, One Service at a Time](https://fidoalliance.org/dark-reading-getting-started-with-passkeys-one-service-at-a-time/): Executive Director of the FIDO Alliance, Andrew Shikiar, emphasized the potential for over 7 billion accounts enabled to use passkeys at the end of 2023. Supported by Apple, Google, and Microsoft, these tech giants worked with FIDO to establish a standardized passkey system using certificates compliant with WebAuthn. - [Fintech Times: Cybersecurity trends for 2024 with TransUnion, Forter, WatchGuard, Vouched, FIDO Alliance, Fusion](https://fidoalliance.org/fintech-times-cybersecurity-trends-for-2024-with-transunion-forter-watchguard-vouched-fido-alliance-fusion/): FIDO Alliance's Andrew Shikiar emphasises the need for enterprises to adapt cybersecurity strategies due to rising AI-driven social engineering threats and a push for greater cyber-transparency. Traditional methods like company-wide phishing training may become inadequate. Shikiar suggests reducing reliance on passwords and adopting passkeys, either synced or device-bound, as a more secure and user-friendly authentication approach. - [Forbes: Forget passwords, this new tech is nearly hacker-proof, 1Password says](https://fidoalliance.org/forbes-forget-passwords-this-new-tech-is-nearly-hacker-proof-1password-says/): Since the adoption of passkeys in September, 1Password has reported that more than 700,000 passkeys have been created and saved by their users, which doubled the end-of-year expectations. Currently, 334,000 1Password users are trying passkey technology, 79% of them being consumers and 21% of them being business customers. - [Security Magazine: Top cybersecurity predictions in 2024](https://fidoalliance.org/security-magazine-top-cybersecurity-predictions-in-2024/): Aside from eliminating the need to remember passwords, integrating passkeys offers numerous advantages for enterprises by unlocking devices seamlessly and with ease. This gives users the ability to use the same biometric verification method across multiple devices and accounts which not only enhances security but simplifies the login process. - [Target Uses FIDO Authentication to Secure the Workforce](https://fidoalliance.org/target-uses-fido-authentication-to-secure-the-workforce/): Target is a retailer with locations across the U.S as well as online ecommerce operations. Target also provides loyalty and credit card services to its customers. - [SURF Uses FIDO2 to Protect Users in the Netherlands](https://fidoalliance.org/surf-uses-fido2-to-protect-users-in-the-netherlands/): SURF is the shared IT organization for research institutes and universities in the Netherlands. The organization helps to connect over 100 different institutions across the country.  - [How CZ.Nic uses FIDO Authentication ](https://fidoalliance.org/how-cz-nic-uses-fido-authentication/): The Company:  - [How CVS Health Uses FIDO to Secure Its Users](https://fidoalliance.org/how-cvs-health-uses-fido-to-secure-its-users/): CVS Health is a U.S. healthcare organization that includes multiple operating divisions including retail with CVS Pharmacy, which has nearly 10,000 locations across America. CVS Health also includes a large healthcare insurance business that integrates assets from Aetna. - [heise:有密码和无密码的现代身份验证](https://fidoalliance.org/heise-modern-authentication-with-and-without-a-password/) - [heise: Modern authentication with and without a password](https://fidoalliance.org/heise-modern-authentication-with-and-without-a-password/): The online workshop Modern Authentication with and without a password is about modern alternatives and what role PKI certificates, FIDO and passkeys play. Participants learn to manage certificates, use certificate-based authentication and implement security concepts in real scenarios. - [BGR: 1Password launches sign-in for public test ahead of official release](https://fidoalliance.org/bgr-1password-launches-sign-in-for-public-test-ahead-of-official-release/): As 1Password opens the passkey feature for public beta testing, users will no longer need their “Secret Keys”. Passkeys offer heightened security through facial recognition (and fingerprints), along with recovery codes for added security measures in case of device loss. - [Security Info Watch: 4 cyber-attack prevention strategies your organization must implement](https://fidoalliance.org/security-info-watch-4-cyber-attack-prevention-strategies-your-organization-must-implement/): Phishing-resistant passkeys offer enhanced security (unlike passwords) and prevent attackers from bypassing security measures. Major companies like Microsoft, Apple, and Google are endorsing passkeys to bolster user security, with Google even making them the default option for personal accounts. - [Authority Magazine – Medium: Jason Rebholz Of Corvus Insurance: How AI Is Disrupting Our Industry, and What We Can Do About It](https://fidoalliance.org/authority-magazine-medium-jason-rebholz-of-corvus-insurance-how-ai-is-disrupting-our-industry-and-what-we-can-do-about-it/): In an interview discussing AI's impact on the industry, Jason Rebholz from Corvus Insurance underscores the threat to user credentials targeted by attackers. He recommends securing identities using passkeys or FIDO2 technologies and adopting zero-trust principles to prevent these incidents. - [Statistics Sources](https://fidoalliance.org/statistics-sources/): The FIDO Alliance maintains a large database of industry statistics related to legacy authentication methods, as well as successes companies have achieved by deploying FIDO. The statistics on the Alliance homepage come from these sources:  - [Blog: FIDO APAC Summit 2023: Pioneering Simpler and Stronger Authentication in Asia-Pacific](https://fidoalliance.org/blog-fido-apac-summit-2023-pioneering-simpler-and-stronger-authentication-in-asia-pacific/): From August 28th to 30th, 2023, the FIDO Alliance convened industry leaders, government representatives, and cybersecurity experts from the Asia-Pacific region at the FIDO APAC Summit 2023. The summit, hosted by Vietnam’s Ministry of Information and Communication in collaboration with the Vietnam Authority of Information Security and VinCSS, a subsidiary of VinGroup, took place in Nha Trang, Vietnam. The summit, which took place in Vietnam to mirror the nation’s dynamic developments, aimed to foster discussions and strategies around the advancement of phishing-resistant FIDO (Fast Identity Online) authentication. - [Tagesspiegel Background: Man against machine against man](https://fidoalliance.org/tagesspiegel-background-man-against-machine-against-man/): The goal of cybersecurity should not be to become better than the hackers' AI. Rather, a security mechanism must be found that cannot be switched off by AI. The Fido Alliance, a non-profit trade association of several tech companies, including 1Password, wants to reduce dependence on passwords by introducing new, open standards. - [IT Pro: Passkeys, a passwordless authentication solution supported by major tech companies, provide a secure alternative using public key cryptography](https://fidoalliance.org/it-pro-passkeys-a-passwordless-authentication-solution-supported-by-major-tech-companies-provide-a-secure-alternative-using-public-key-cryptography/): Built on the WebAuthentication standard, they eliminate traditional password challenges. Despite corporate adoption hurdles, the FIDO Alliance claims readiness, with 92% expressing confidence in passkey security benefits. Challenges include compatibility issues with platforms like Microsoft Entra ID and limited support from browsers. Adoption may be slower in heavily regulated industries requiring higher security standards. - [WSJ: 23andMe Hack Is a Wake-Up Call for Your Password Habits](https://fidoalliance.org/wsj-23andme-hack-is-a-wake-up-call-for-your-password-habits/): The recent 23andMe breach, exposing personal information belonging to 6.9 million people, underlines the dangers of password reuse as the hackers used stolen passwords from other sites to gain unauthorized access to their accounts. Security experts warn against password reuse and advocate for alternative measures like passkeys to enhance security. - [Medium: Exploring the World of FIDO: Life Without Passwords](https://fidoalliance.org/medium-exploring-the-world-of-fido-life-without-passwords/): The FIDO Alliance is a pioneer in digital security and is redefining authentication through SYM and ASYM encryptions. The consortium is revolutionizing the user authentication process by going beyond passwords (with passkeys) and emphasizing the importance of safeguarding public and private keys to secure digital identities. - [FIDO Authentication Adoption Soars as Passwordless Sign-ins with Passkeys Become Available on More than 7 Billion Online Accounts in 2023](https://fidoalliance.org/fido-authentication-adoption-soars-as-passwordless-sign-ins-with-passkeys-become-available-on-more-than-7-billion-online-accounts-in-2023/): Momentum continues in Japan with notable passkey deployments, while SBI Sumishin Net Bank announces membership and Mercari is appointed to Board of Directors  - [Securing the Edge and Connected Devices with FDO: an Authenticate Virtual Summit](https://fidoalliance.org/securing-the-edge-and-connected-devices-with-fdo-an-authenticate-virtual-summit/): Join Dell, IBM, Intel, Red Hat and more for education and guidance on leveraging FIDO Device Onboard to foster trust in the edge and IoT space - [GB News: If you’re using a password on this list, change it now – hackers could break into your account in seconds](https://fidoalliance.org/gb-news-if-youre-using-a-password-on-this-list-change-it-now-hackers-could-break-into-your-account-in-seconds/): The most common passwords of 2023, including "123456" and "admin," have been exposed, leaving millions vulnerable to hacking. Cybersecurity researchers, in collaboration with NordPass, warn users to adopt unique and secure passwords. Hackers can breach accounts with weak passwords in seconds. The study, analyzing 4.3TB of leaked data, highlights the importance of password managers and mentions the promising role of FIDO (Fast Identity Online) Alliance in developing passkeys as a secure alternative. Despite advancements, the transition away from traditional passwords is expected to take time. - [Biometric Update: Digital IDs mean manageable and critical change, FIDO tells US federal security leaders](https://fidoalliance.org/biometric-update-digital-ids-mean-manageable-and-critical-change-fido-tells-us-federal-security-leaders/): FIDO Alliance webinar aimed at U.S. federal data-security officials to promote digital authentication while reassuringthem not to panic. It emphasizes that new anti-phishing measures are forthcoming, flexible, and won't replace existingpersonal ID verification (PIV) methods. The webinar and accompanying white paper suggest narrowing downauthentication methods to counter phishing, integrating FIDO authentication within the government's zero truststrategy, and conducting pilots for suitable authenticators while implementing digital ID risk assessments (DIRAs) toovercome cultural barriers in adoption. The panelists stressed the importance of considering FIDO authentication as areplacement for vulnerable authentication methods rather than PIVs and CACs. - [Inside Cybersecurity: FIDO Alliance emphasizes need for agency feedback on implementing authentication standard](https://fidoalliance.org/inside-cybersecurity-fido-alliance-emphasizes-need-for-agency-feedback-on-implementing-authentication-standard/): FIDO Alliance seeks increased government involvement to develop comprehensive guidelines for implementing aphishing-resistant authentication standard within federal agencies. Co-chaired by Teresa Wu of IDEMIA, the workinggroup released an initial white paper and plans further collaboration with government entities to shape FIDOauthenticator implementation in the US government. This initiative responds to the Office of Management and Budget'scall for phishing-resistant multifactor authentication (MFA) by 2024, providing an alternative to the Personal IdentityVerification (PIV) standard in certain scenarios, focusing on cloud environments and temporary access needs, aiming tosupplement rather than replace PIV authentication. - [Blog: FIDO Alliance Publishes Guidance for U.S. Government Agency Deployment of FIDO Authentication](https://fidoalliance.org/blog-fido-alliance-publishes-guidance-for-u-s-government-agency-deployment-of-fido-authentication/): The U.S. government has embraced FIDO authentication, and is now looking for further guidance around how to implement this technology into the government’s existing PIV-centric ecosystem used to manage enterprise access for government employees and contractors.  - [Gemini Protects Users with FIDO Authentication](https://fidoalliance.org/case-study-gemini-protects-users-with-fido-authentication/): Gemini is a cryptocurrency exchange and custodian, founded by Tyler and Cameron Winklevoss in 2014. Gemini enables its users to transact both via a website as well as mobile apps to buy, sell and store cryptocurrency assets. - [Security Insider: Consumers are demanding password alternatives](https://fidoalliance.org/security-insider-consumers-are-demanding-password-alternatives/): For the third time, the FIDO Alliance's annual online authentication barometer provides insights into the global use and acceptance of various forms of authentication. - [Dark Reading: MGM and Caesars Attacks Highlight Social Engineering Risks](https://fidoalliance.org/dark-reading-mgm-and-caesars-attacks-highlight-social-engineering-risks/): In a byline, FIDO Alliance executive director Andrew Shikiar discusses the recent cyberattacks on MGM Resorts International and Caesars Entertainment which showcased the widespread effects data breaches can have on an organization. These attacks, as well as so many other high-profile breaches over the past few years, happened because of continued reliance on legacy sign-in credentials like passwords and SMS one-time passcodes that can be easily given away and reused. - [helpnetsecurity: Bitwarden launches passkey management for passwordless authentication across accounts](https://fidoalliance.org/helpnetsecurity-bitwarden-launches-passkey-management-for-passwordless-authentication-across-accounts/): Bitwarden has launched passkey management, enabling every user to create, manage, and store passkeys in their vaults. Users can now quickly and securely log into passkey-enabled websites through the Bitwarden web extension. The synchronized passkeys are encrypted in users’ vaults for a more convenient passwordless login experience. - [CHIP: What is a passkey? Easily explained](https://fidoalliance.org/chip-what-is-a-passkey-easily-explained/): Anyone who wants to log into apps or websites usually uses a password to identify themselves. With a passkey, the login works without a password. - [DevClass: A further push for passkeys: Android Credential Manager generally available from November 1st](https://fidoalliance.org/devclass-a-further-push-for-passkeys-android-credential-manager-generally-available-from-november-1st/): Google’s Diego Zavala, product manager on the authentication team, insists that “Passkeys are the future of online authentication,” citing improved security and convenience versus traditional passwords. Apps that already use Credential Manager to support passkeys include Uber and Whatsapp. - [CNET: Passkeys have come to Amazon. Here’s what you need to know](https://fidoalliance.org/cnet-passkeys-have-come-to-amazon-heres-what-you-need-to-know/): Last week, Amazon announced that it would be hopping on the Passkey train. This means that you'll now be able to use passkeys to log in to some of your Amazon accounts (we'll get to which ones later). The tech giant joins a slew of other companies who are saying goodbye to passwords and opting for passkeys instead. - [The EU organizations ENISA and ETSI refer to FIDO as authentication standard for eIDAS2](https://fidoalliance.org/the-eu-organizations-enisa-and-etsi-refer-to-fido-as-authentication-standard-for-eidas2/): During the past years, FIDO has continued its expansion as an authentication standard among eIDAS compliant identification solutions across the EU. Back in 2020, FIDO was deployed as part of an eID scheme by the Czech domain register CZ.NIC’s identity provider MojeID, and FIDO’s eID scheme was recognized as LoA Substantial and High by the Czech ministry of interior. The year after, the Norwegian trust service provider Buypass deployed FIDO2 as an authentication standard for an eIDAS eID scheme of LoA Substantial and High; this solution has been accredited by the Norwegian digitalization agency and is now being rolled out in the Norwegian healthcare sector. In April 2023, the FIDO Alliance published a white paper that describes how FIDO can be used for the EUDI Wallet under the proposed eIDAS2 regulation. So FIDO is currently gaining momentum as an authentication standard in the EU. - [Siècle Digital: Generative AI: a revolution that is forcing businesses to rethink the fight against phishing](https://fidoalliance.org/siecle-digital-generative-ai-a-revolution-that-is-forcing-businesses-to-rethink-the-fight-against-phishing/): In this byline Andrew looks at the rise of generative AI and the increase in the threat of phishing, making attacks almost undetectable. For Andrew, AI-based malware tools such as FraudGPT are generating sophisticated phishing campaigns. Instead of simply detecting phishing emails, businesses need to rethink security, with a focus on eliminating passwords. He believes that passwordless authentication, such as passkeys, offers better protection, making credentials invulnerable to attack. - [Caschys Blog: FIDO study shows: passwords to be replaced by better alternatives in the next few years](https://fidoalliance.org/caschys-blog-fido-study-shows-passwords-to-be-replaced-by-better-alternatives-in-the-next-few-years/): FIDO study shows: passwords to be replaced by better alternatives in the next few yearsA study conducted by the FIDO Alliance (Fast IDentity Online) and LastPass shows that passwords in companies will largely be replaced by secure alternatives in the next few years. According to the survey, most IT executives believe that by 2028, less than 25 percent of logins will be through passwords. Already, 95 percent of respondents are using passwordless alternatives such as passkeys to increase security. The majority of IT managers plan to manage passkeys via third-party password managers. - [InfoSecurity: Rising AI-Fueled Phishing Drives Demand for Password Alternatives](https://fidoalliance.org/infosecurity-rising-ai-fueled-phishing-drives-demand-for-password-alternatives/): Phishing attacks are rising in frequency and sophistication, with AI-driven techniques and deepfake voice and video used to trick victims, according to a FIDO Alliance survey. Passwords without two-factor authentication are still common, despite their vulnerability, while biometrics and FIDO-enabled methods like passkeys are gaining favor as more secure alternatives. - [Media Post: The Password Plague: Consumers Are Abandoning Purchases Out Of Frustration](https://fidoalliance.org/media-post-the-password-plague-consumers-are-abandoning-purchases-out-of-frustration/): Email teams being challenged with high cart abandonment rates should push back — the real problem is not bad personalization or copy, but passwords. People are fed up with them. And their behavior reflects it, judging by the 2023 Online Authentication Barometer, a global study by the Fido Alliance, conducted by Sapio Research. U.S. consumers abandon a purchase and stop accessing an online service because they can’t remember their passwords 4.76 times per day on average, up from 3.71 in 2022 — a 28.30% increase. - [IT Brew: FIDO passkeys beat passwords in phishing fight](https://fidoalliance.org/it-brew-fido-passkeys-beat-passwords-in-phishing-fight/): In the fight against a growing number of text-, phone-, and email-based phishing scams, speakers at the FIDO Alliance’s Authenticate Conference in California this week made a case for passwordless security options like the passkey over the oft-hacked password. “Any enterprise that’s using passwords or legacy forms of MFA is taking a gamble they will eventually lose,” Andrew Shikiar, executive director of the industry group known as the FIDO Alliance, told attendees. - [The Wall Street Journal: Google and Apple Want You to Log In With Passkeys. Here’s What That Means.](https://fidoalliance.org/the-wall-street-journal-google-and-apple-want-you-to-log-in-with-passkeys-heres-what-that-means/): Passwords are inherently flawed, so tech companies are turning to more secure logins that just require your face or fingerprint. - [Amazon is making it easier and safer for you to access your account with passwordless sign-in](https://fidoalliance.org/amazon-is-making-it-easier-and-safer-for-you-to-access-your-account-with-passwordless-sign-in/): Amazon is rolling out passkey support on browsers and mobile shopping apps, offering customers an easier and safer way to sign in to their Amazon accounts. Customers can now set up passkeys in their Amazon settings, allowing them to easily use the same face, fingerprint, or PIN used to unlock their device. Passkey support is available today for all Amazon customers using browsers and is gradually rolling out on the iOS Amazon Shopping app with support coming soon on the Android Amazon Shopping app. - [The 2023 Workforce Authentication Report: Embracing the Passwordless Future](https://fidoalliance.org/the-2023-workforce-authentication-report-embracing-the-passwordless-future/): Businesses are readily embracing the passwordless road ahead. Which direction is your organization going? - [Businesses are Ready to Ditch Passwords, Says New Report from FIDO Alliance and LastPass](https://fidoalliance.org/businesses-are-ready-to-ditch-passwords-says-new-report-from-fido-alliance-and-lastpass/): 89% of IT leaders expect passwords will represent less than a quarter of their organization's logins within five years or less - [FIDO Alliance study reveals growing demand for password alternatives as AI-fuelled phishing attacks rise](https://fidoalliance.org/fido-alliance-study-reveals-growing-demand-for-password-alternatives-as-ai-fuelled-phishing-attacks-rise/): Increased desire for biometrics and awareness of passkeys increases imperative on service providers to enable stronger, more user-friendly sign-ins - [FIDO Alliance study reveals growing demand for password alternatives as AI-fuelled phishing attacks rise](https://fidoalliance.org/barometer-2023/): Increased desire for biometrics and awareness of passkeys increases imperative on service providers to enable stronger, more user-friendly sign-ins - [Simpler and Stronger Online Authentication in APAC: Dialogue on Challenges and Opportunities](https://fidoalliance.org/simpler-and-stronger-online-authentication-in-apac-dialogue-on-challenges-and-opportunities/): Joon Hyuk Lee - APAC Market Development Director, FIDO Alliance - [CNN Business: Google looks to do away with passwords, making ‘passkeys’ the default option](https://fidoalliance.org/the-green-sheet-the-extraordinary-life-of-a-payment-security-checkpoints-2/): Google is looking to make passwords obsolete by prompting users to create passkeys to unlock accounts and devices with a fingerprint, face scan or pin number. The FIDO Alliance, a security consortium that counts many tech firms as members, previously developed standards for passkeys. - [FIDO Device Onboard (FDO) Certification Program is Launched to Enable Faster, More Secure, Deployments of Edge Nodes and IoT Devices](https://fidoalliance.org/fido-device-onboard-fdo-certification-program-is-launched-to-enable-faster-more-secure-deployments-of-edge-nodes-and-iot-devices/): FIDO Alliance FDO Certification program will allow users to mix and match FDO solutions from different vendors with confidence - [Informatik aktuell: FIDO Passkeys 2 – in the future without a password](https://fidoalliance.org/informatik-aktuell-fido-passkeys-2-in-the-future-without-a-password/): The FIDO Alliance is committed to making the Internet and its use easier to use and yet more secure through stronger authentication than is currently the case. The members of the FIDO Alliance include many large and well-known tech companies. Above all, the companies Apple, Google and Microsoft (mentioned in alphabetical order, no rating) are driving forward the efforts surrounding FIDO passkeys. - [TechRadar: BitWarden adds passwordless SSO](https://fidoalliance.org/techradar-bitwarden-adds-passwordless-sso/): Bitwarden has now added Single Sign-On (SSO) support for trusted devices on its enterprise tiers, which allows users to access their vaults without a password. - [Smashing Security: 339: Bitcoin boo-boo, deepfakes for good, and time to say goodbye to usernames?](https://fidoalliance.org/smashing-security-339-bitcoin-boo-boo-deepfakes-for-good-and-time-to-say-goodbye-to-usernames/): Podcast episode where FIDO Passkeys are mentioned and linked to. - [The Green Sheet: The extraordinary life of a payment – Security checkpoints](https://fidoalliance.org/the-green-sheet-the-extraordinary-life-of-a-payment-security-checkpoints/): Andrew Shikiar is quoted in the lead story of The Green Sheet: “Simply put, verification is the process of confirming someone’s identity. Authentication is the process of recognizing someone’s identity,” he said. “The easiest way to think about it is that you verify someone’s identity less often—usually at the point of account creation—to confirm they are who they say they are. You then authenticate them at subsequent sign-ins to confirm the person logging in is the person who created the account.” - [Bleeping Computer: Okta – Hackers target IT help desks to gain Super Admin, disable MFA](https://fidoalliance.org/bleeping-computer-okta-hackers-target-it-help-desks-to-gain-super-admin-disable-mfa/): Identity and access management company Okta released a warning about social engineering attacks targeting IT service desk agents at U.S.-based customers in an attempt to trick them into resetting multi-factor authentication (MFA) for high-privileged users. To protect admin accounts from external actors, Okta recommends enforcing phishing-resistant authentication using Okta FastPass and FIDO2 WebAuthn. - [Security Magazine: Embracing a company culture of cybersecurity starts at the top](https://fidoalliance.org/security-magazine-embracing-a-company-culture-of-cybersecurity-starts-at-the-top/): Andrew’s byline where he discusses how cybersecurity needs to be a top-down movement, simplifying the process for employees so they do not end up with password fatigue. The culture change should come from leadership, working with the IT team and stakeholders, to ensure better cybersecurity. - [Forbes: Cyber Autumn: Captivating Cybersecurity Conferences to Dive Into This October 2023](https://fidoalliance.org/forbes-cyber-autumn-captivating-cybersecurity-conferences-to-dive-into-this-october-2023/): Authenticate 2023 is the go-to event for everything related to user authentication. Hosted by the FIDO Alliance, this unique conference is set to take place from October 16-18, 2023, at the Omni La Costa Resort in Carlsbad, CA, just north of San Diego. The conference is designed to give CISOs, business leaders, product managers, and security experts the know-how, tools, and best practices they need to implement state-of-the-art authentication across a range of applications. - [The Verge: X Wants Permission to Start Collecting Your Biometric Data and Employment History](https://fidoalliance.org/the-verge-x-wants-permission-to-start-collecting-your-biometric-data-and-employment-history/): X Wants Permission to Start Collecting Your Biometric Data and Employment HistoryAccording to findings from app developer Steve Moser, X plans on rolling out support for passkeys, which can use your device’s fingerprint, facial recognition, or PIN to log in to your account. However, the FIDO Alliance — a nonprofit organization that advocates for the use of passkeys — says biometric data and processing “continues to stay on the device and is never sent to any remote server.” - [SC Media: 3 trends shaping cybersecurity: Passwordless authentication, securing the supply chain and AI](https://fidoalliance.org/sc-media-3-trends-shaping-cybersecurity-passwordless-authentication-securing-the-supply-chain-and-ai/): Passwordless authentication is one of those concepts that is finally having its day in the sun after Apple, Google and Microsoft came onboard last year, expanding their support for the passwordless sign-in standard created by the FIDO Alliance and the World Wide Web Consortium. “The work that the FIDO Alliance has done to roll out passkeys, really positioning them as a strong way for consumers to start using and leveraging that strong PKI authentication, I think that is a really good step forward,” said Josh Cigna, enterprise solutions architect at Yubico. - [IEEE Spectrum: Google Develops Quantum-Safe Security Keys](https://fidoalliance.org/ieee-spectrum-google-develops-quantum-safe-security-keys/): Google has developed a quantum-resilient way of implementing the FIDO2 security key standard, an increasingly popular method of authentication that’s used as an alternative to passwords. David Turner, senior director of standards development at FIDO Alliance, which manages password-free authentication standards, said post-quantum changes to security keys are expected to come with challenges. - [TechRadar: LinkedIn and X are planning to ditch passwords](https://fidoalliance.org/techradar-linkedin-and-x-are-planning-to-ditch-passwords/): Two of the biggest social media sites, X (formerly Twitter) and LinkedIn, are reportedly soon set to support passkeys, a way for users to log in to their accounts without using a password. According to discoveries made by iOS developer Steve Mosher, the two services contain code that suggest they will soon be compatible with the new technology, whose standards are governed by the FIDO alliance as set out in the FIDO2 specifications. - [Infosecurity Magazine: Microsoft warns of adversary-in-the-middle uptick on phishing platform](https://fidoalliance.org/infosecurity-magazine-microsoft-warns-of-adversary-in-the-middle-uptick-on-phishing-platform/): Microsoft has observed a proliferation of adversary-in-the-middle (AiTM) techniques deployed through phishing-as-a-service (PhaaS) platforms, the company explained in a series of tweets posted on August 28, 2023. “This emphasizes the importance of MFA through methods like Microsoft Authenticator, FIDO2 security keys and certificate-based authentication in securing identities,” the company said. - [Cybersecurity Dive: Government investigation puts spotlight on password insecurity](https://fidoalliance.org/cybersecurity-dive-government-investigation-puts-spotlight-on-password-insecurity/): When the U.S. Department of the Interior recently conducted an internal investigation into password security, the findings described a situation ripe for exploitation by enterprising cybercriminals. In his Washington Post column, Greenblatt illustrates how his department needs to move away from passwords. We can bolster security with passwordless authentication in the form of passkeys. It’s impossible to access a passkey-protected account without physical access to the end-user device.  - [Computerworld: Managed Apple IDs, iCloud, and the shadow IT connection](https://fidoalliance.org/computerworld-managed-apple-ids-icloud-and-the-shadow-it-connection/): One new addition will be the ability to sync iCloud Keychain, Apple’s de facto password and passkey management utility. It integrates with Apple’s biometric services, Touch ID and Face ID. This is a major potential boon for enterprises, particularly those adopting passkeys to replace passwords. - [Infosecurity Magazine: Why it’s time to kick the password habit](https://fidoalliance.org/infosecurity-magazine-why-its-time-to-kick-the-password-habit/): Andrew Shikiar discusses why passwords are so hard to give up, and why they should be replaced with passkeys for more security. - [Biometric Update: Authenticate 2023](https://fidoalliance.org/biometric-update-authenticate-2023/): It’s time to modernize your authentication! Organizations around the globe are embracing a new way to authenticate with FIDO standards, moving past passwords and legacy forms of multifactor authentication to provide users with passkeys for phishing-resistant sign-ins.  - [HelpNet Security: Anticipating the next wave of IoT cybersecurity challenges](https://fidoalliance.org/helpnet-security-anticipating-the-next-wave-of-iot-cybersecurity-challenges/): Ensuring a seamless integration of IoT with cybersecurity requires a strategic approach by technology leaders. Emphasizing secure bootstrapping, employing advanced, scalable onboarding standards such as FIDO onboarding device, and meticulously building a trusted supply chain are essential. Beyond these, it’s about creating a vigilant ecosystem where every component is not just included but examined for security integrity. - [FIDO Alliance: FIDO Alliance details agenda for Authenticate 2023, featuring keynote from Rachel Tobac, noted White Hat Hacker and SocialProof Security CEO](https://fidoalliance.org/fido-alliance-fido-alliance-details-agenda-for-authenticate-2023-featuring-keynote-from-rachel-tobac-noted-white-hat-hacker-and-socialproof-security-ceo/): 3-day program for FIDO Alliance's flagship event on the future of user authentication includes 90+ sessions; Early Bird registration available through August 18 - [CyberSecurity Asean: FIDO APAC Summit Keynotes and Sponsors Announced](https://fidoalliance.org/cybersecurity-asean-fido-apac-summit-keynotes-and-sponsors-announced/): The FIDO Alliance today provided an updated list of speakers and sponsors for its first-ever FIDO APAC Summit, the premier event dedicated to advancing and promoting phishing-resistant FIDO authentication in the region. Co-hosted by the Ministry of Information and Communications (Vietnam), the summit will take place in Vinpearl Nha Trang, Vietnam, on 28 – 30 August 2023, and centers on the theme of “Connecting for a Safer Digital Future”. - [Biometric Update: Biometric authentication accuracy bar rises, assurance levels evolve in NIST guidance](https://fidoalliance.org/biometric-update-biometric-authentication-accuracy-bar-rises-assurance-levels-evolve-in-nist-guidance/): Biometrics performance requirements have been upgraded and identity assurance levels revised in the latest draft update to the U.S. National Institute of Standards and Technology’s Digital Identity Guidelines. NIST reviewed the changes so far, the numerous comments submitted about them, and possible further revisions in a recent webinar. - [Computer Weekly: Going passwordless in online shopping](https://fidoalliance.org/computer-weekly-going-passwordless-in-online-shopping/): In the last few years, the FIDO Alliance, an open industry association, has helped businesses and users authenticate with maximum security and minimum friction. The WebAuthn standard provides the technological foundation by enabling brands to authenticate users with public key cryptography instead of a password. - [Webinar: Inside Intuit’s FIDO Journey](https://fidoalliance.org/webinar-inside-intuits-fido-journey/): Intuit is the global financial technology platform that powers prosperity for more than 100 million consumers and businesses around the world using TurboTax, Credit Karma, QuickBooks and Mailchimp. To execute on a user-centric focus, Intuit’s customer authentication products team, led by Rakan Khalid, Intuit Group Product Manager, Identity, justifies and prioritizes development of new authentication capabilities based on user research, security trends and technology advancements in the industry. This has led to an overarching strategy that emphasizes secure and convenient authentication experiences on its platform. - [FIDO Alliance Details Agenda for Authenticate 2023, Featuring Keynote from Rachel Tobac, Noted White Hat Hacker & SocialProof Security CEO](https://fidoalliance.org/fido-alliance-details-agenda-for-authenticate-2023-featuring-keynote-from-rachel-tobac-noted-white-hat-hacker-socialproof-security-ceo/): 3-day program for FIDO Alliance’s flagship event on the future of user authentication includes 90+ sessions; Early Bird registration available through August 18   - [FIDO APAC Summit Keynotes and Sponsors Announced](https://fidoalliance.org/fido-apac-summit-keynotes-and-sponsors-announced/): The exclusive event on 28-30 August in Vietnam will feature content and insights, provided by cybersecurity experts—including a former convicted hacker—that focus on best practices for passwordless authentication implementations.  - [Heise: We have just reached the turning point](https://fidoalliance.org/heise-we-have-just-reached-the-turning-point/): Andrew Shikiar is Executive Director of the FIDO Alliance, which developed the Passkeys login process. In an interview with c't, he answers all the questions that came to us during testing. - [Teiss: The rise and rise of passkeys in the tech industry](https://fidoalliance.org/teiss-the-rise-and-rise-of-passkeys-in-the-tech-industry/): Andrew Shikiar, Executive Director and CMO at FIDO Alliance asks in his byline: why are we still being passive-aggressive about passwords? - [Connect-living: Keys instead of passwords: This is how a secure login with an access key works](https://fidoalliance.org/connect-living-keys-instead-of-passwords-this-is-how-a-secure-login-with-an-access-key-works/): Phishing and other attacks usually have one goal: passwords. So the world could be a better place without passwords. There have already been several attempts to bury the passwords. All have failed - due to the complexity, the costs for hardware keys, for example, or the inconvenient use. The new approach with FIDO2 and Passkeys sounds more promising. By the way, FIDO stands for Fast Identity Online. - [News-24: How passkeys will open the door to a more secure and passwordless future](https://fidoalliance.org/news-24-how-passkeys-will-open-the-door-to-a-more-secure-and-passwordless-future/): More than 24 billion usernames and passwords were available on the dark web last year, a 65% increase since 2020, according to research by Digital Shadows, a digital risk protection company. To this end, the cybersecurity industry is striving to adopt solutions that would eliminate the need for passwords altogether. The latest technology uses what is known as passkeys. - [B2B Cybersecurity: Effortless authentication with passkeys](https://fidoalliance.org/b2b-cybersecurity-effortless-authentication-with-passkeys/): Passkeys are easier to use than many traditional authentication methods. They are also resistant to phishing, which allows users to consistently and securely log in to supported websites. The passwordless technology, first introduced in 2022, is based on industry standards from the World Wide Web Consortium (W3C) and the FIDO Alliance and is supported by Apple, Google, Microsoft, Paypal, eBay and others. - [Biometricupdate.com: 1Password, Microsoft move to biometric authentication](https://fidoalliance.org/biometricupdate-com-1password-microsoft-move-to-biometric-authentication/): 1Password and Microsoft are among vendors moving to passwordless login, switching to phishing-resistant biometric passkeys. In a blog post, 1Password announced a private beta test for passkey account access on iOS and iPadOS. - [9TO5Mac: 1Password will soon let users unlock password vaults with passkeys](https://fidoalliance.org/9to5mac-1password-will-soon-let-users-unlock-password-vaults-with-passkeys/): Popular password manager 1Password teased in June that native support for passkeys is coming to the iPhone and iPad app with iOS 17. Now 1Password is taking another big step toward a world without traditional passwords, this time replacing the key to users’ password vaults. Soon, 1Password users will be able to unlock their vaults using just a passkey. - [IT Brew: Enterprises and developers play leading role in passwordless future](https://fidoalliance.org/it-brew-enterprises-and-developers-play-leading-role-in-passwordless-future/): Many industry pros are increasingly channeling their inner Bill Gates in 2004 and predicting the decline of the password. The PW prognosticating demonstrates some confidence in the IT world that a passwordless infrastructure is now sufficiently in place. “The most notable shift over the past couple of years has been that every major platform vendor is now supporting open standards for passwordless authentication that are in their flagship operating systems. So, this means for the first time that virtually every modern computing device has the capability to support passwordless authentication,” said Andrew Shikiar, executive director and chief marketing officer at FIDO.  - [Engadget: What the hell are passkeys and why are they suddenly everywhere?](https://fidoalliance.org/engadget-what-the-hell-are-passkeys-and-why-are-they-suddenly-everywhere/): Passkeys promise a future without passwords, where we access our accounts as easily as we unlock our phones, with a much higher level of security. “It's the closest to something that can be scaled to get rid of passwords that we've ever seen,” said Megan Shamas, senior director of marketing at industry association FIDO Alliance. A passkey is a digital authentication credential that is securely stored on your device. Instead of what Shamas called a “shared secret” method of passwords, passkeys are a unique key pair for every online service you use bound to the domain.  - [heise: Passwordless login to GitHub: Passkeys in beta](https://fidoalliance.org/heise-passwordless-login-to-github-passkeys-in-beta/): GitHub takes another step to replace passwords as a login method and brings passkeys into public beta. Passkeys are the FIDO Alliance’s latest move to simplify secure logins on the Internet - they are intended to solve many of the everyday problems that U2F and FIDO2 hardware tokens bring with them. - [Cashy’s Blog: TikTok now also supports passkeys for login on iOS](https://fidoalliance.org/cashys-blog-tiktok-now-also-supports-passkeys-for-login-on-ios/): The short video platform TikTok has announced that it will also be possible to log in with passkeys – on iOS devices. At the same time, it is confirmed that TikTok has now become a member of the FIDO Alliance. Passkeys replace traditional passwords and use encrypted biometric data already stored on your device. They are not processed directly by third-party apps - not even by TikTok. - [B2B Cyber Security: Best practices for zero trust](https://fidoalliance.org/b2b-cyber-security-best-practices-for-zero-trust-2/): Replacing traditional MFA with strong, passwordless authentication methods allows security teams to build the first layer of their Zero Trust architecture. Replacing passwords with FIDO-based passkeys that use asymmetric cryptography, and combining them with secure device-based biometrics, creates a phishing-resistant MFA approach. - [ComputerWeekly: The management level in companies must actively live IT security](https://fidoalliance.org/computerweekly-the-management-level-in-companies-must-actively-live-it-security/): FIDO Alliance's Andrew Shikiar shares his view on how cyber security is often viewed as a purely technical issue. In this article, he underlines how important security should be firmly integrated into the corporate culture, especially from the management level. - [Silicon: Passwordless: an innovative approach to securing access](https://fidoalliance.org/silicon-passwordless-an-innovative-approach-to-securing-access/): Most of the major players in the sector (Microsoft, Google and Apple in particular) have started to join forces on the subject to think about the technical solutions thanks to which Passwordless could be achieved in future years. FIDO Alliance, WebAuthn and proposed authentication factors, find out what Passwordless is all about. - [MobileID World: FIDO white papers explain how to use passkeys in the enterprise](https://fidoalliance.org/mobileid-world-fido-white-papers-explain-how-to-use-passkeys-in-the-enterprise/): The FIDO Alliance has published a new set of papers aimed at offering guidance on how passkeys can be used across different enterprise environments.  - [B2B Cyber Security: Best practices for zero trust](https://fidoalliance.org/b2b-cyber-security-best-practices-for-zero-trust/): Replacing traditional MFA with strong, passwordless authentication methods allows security teams to build the first layer of their Zero Trust architecture. Replacing passwords with FIDO-based passkeys that use asymmetric cryptography, and combining them with secure device-based biometrics, creates a phishing-resistant MFA approach.  - [Gov Info Security: Feds urge healthcare providers, vendors to use strong MFA](https://fidoalliance.org/gov-info-security-feds-urge-healthcare-providers-vendors-to-use-strong-mfa/): HHS OCR is the latest federal agency pushing for more widespread adoption of multifactor authentication. Cybersecurity and Infrastructure Security Agency Director Jen Easterly last October during an address at a FIDO Alliance conference also urged technology vendors to "forcefully nudge" users into MFA.  - [Intuit’s ROI from Passwordless Customer Authentication](https://fidoalliance.org/case-study-intuits-roi-from-passwordless-customer-authentication/): Business Situation - [FIDO Alliance Publishes Guidance for Deploying Passkeys in the Enterprise](https://fidoalliance.org/fido-alliance-publishes-guidance-for-deploying-passkeys-in-the-enterprise/): Half-day virtual Authenticate Summit to educate on how passkeys can fit into a variety of enterprise environments - [Toyota Motor Corporation turns to FIDO Authentication for Enhanced Login in Japan](https://fidoalliance.org/toyota-motor-corporation-turners-to-fido-authentication-for-enhanced-login-in-japan-2/): As the “CASE” trend is gaining ground in the automotive industry, Toyota Motor Corporation, a leader and evolving company in the industry, is changing its model from a “car company” to a “mobility company”. In the area of “C: Connected,” Toyota is working to realize its vision of “Mobility for All - Freedom and Enjoyment of Mobility for All People,” and is developing a number of new services, including a “digital key” that allows the use of smartphones as keys, as well as a website and smartphone applications, for a wide range of users. - [FIDO Alliance Opens Registration for Its First-Ever Asia-Pacific Summit 2023 in Vietnam](https://fidoalliance.org/fido-alliance-opens-registration-for-its-first-ever-asia-pacific-summit-2023-in-vietnam/): The event will gather industry leaders, cybersecurity experts, and government representatives across the region to explore the latest developments in authentication technologies. - [heise online: Passwordless login: Apple ID automatically receives a passkey from iOS 17](https://fidoalliance.org/heise-online-passwordless-login-apple-id-automatically-receives-a-passkey-from-ios-17/): Apple is pushing the Passkey train, which is intended to replace passwords. The passkey setup for iCloud & Co takes place automatically in Apple operating systems. - [Route Fifty: Passwordless security gains ground](https://fidoalliance.org/route-fifty-passwordless-security-gains-ground/): In what it called the “beginning of the end of the password,” Google last month began rolling out its own passkeys, an effort that could help agencies go passwordless and embrace a “zero trust” approach with layers of authentication required. Google’s move could create a “positive snowball effect” away from passwords, said Andrew Shikiar, executive director of the FIDO Alliance, which works to develop open authentication standards.  - [Updated FIDO Alliance Specifications Adopted as ITU International Standards](https://fidoalliance.org/updated-fido-alliance-specifications-adopted-as-itu-international-standards/): MOUNTAIN VIEW, Calif., June 16, 2023 –  The FIDO Alliance announced today that two of its specifications, FIDO UAF 1.2 and CTAP 2.1, are recognized as international standards by the International Telecommunication Union’s Telecommunication Standardization Sector (ITU-T). This milestone establishes these standards as official ITU standards (ITU-T Recommendations) for the global infrastructure of information and communication technologies (ICT). - [PNC Uses FIDO Authentication to Reduce Security Risks, Improve User Experience](https://fidoalliance.org/pnc-uses-fido-authentication-to-reduce-security-risks-improve-user-experience/): Why PNC Opted for FIDO - [FIDO Alliance Opens Registration for Authenticate 2023](https://fidoalliance.org/fido-alliance-opens-registration-for-authenticate-2023/): Conference to feature expert-driven content on replacing passwords with passkeys; early bird discounts available through August 18 - [Axiad Blog: FIDO Series Part 1: What is FIDO Passkey and Why is it Important?](https://fidoalliance.org/axiad-fido-series-part-1-what-is-fido-passkey-and-why-is-it-important/): Cybercrime is an enormous problem in today’s world and continues to grow at an exponential rate. In fact, according to Cybersecurity Ventures, the cost of cybercrime is predicted to hit $8 trillion in 2023 and will grow to a whopping $10.5 trillion by 2025. - [heise: Password: goodbye](https://fidoalliance.org/heise-password-goodbye/): Passkeys could replace the password. You are safe and the technology is in almost all operating systems and browsers. Now the providers are in demand.  - [PYMNTS: Delegated authentication helps speed the shift to passwordless future](https://fidoalliance.org/pymnts-delegated-authentication-helps-speed-the-shift-to-passwordless-future/): According to Jonathan Van der Merwe, group lead product manager at Entersekt, one of the biggest stumbling blocks toward a passwordless future is the technological and behavioral hesitations that come with it. Van der Merwe suggests that moving away from static passwords toward one-time passwords (OTPs), in-app authentication and fast identity online (FIDO) is the way forward. “Moving on to newer technologies like FIDO, which allows for federated authentication ID within the application that you’re using to authenticate yourself, is effectively using the application using your device, whether that’s a laptop, a PC, or a mobile device,” he told PYMNTS.  - [The Federal: Explainer: What are passkeys, how to get them, why they’re safer than passwords](https://fidoalliance.org/the-federal-explainer-what-are-passkeys-how-to-get-them-why-theyre-safer-than-passwords/): Goodbye passwords, passkeys are here. Passwords are all set to be deleted and relegated into the recycle bin, as a more secure alternative has now been developed. Known as ‘passkeys’, they are the new more convenient and safer way to sign into your accounts across all your computing devices, including smartphones, sans your password.  - [DocuSign Blog](https://fidoalliance.org/docusign-blog/): Passkeys are the next evolution of login credentials. They replace hard-to-remember passwords and verify anyone’s identity with biometric information, providing an easier and more secure way to access apps and websites. Thanks to our partnership with Google, DocuSign customers can now take a step toward a passwordless future by using passkeys to log in on mobile devices and web browsers.  - [Leaders: The slow phaseout of passwords](https://fidoalliance.org/leaders-the-slow-phaseout-of-passwords/): On the dark web, cybercriminals have developed markets where passwords are bought and sold. Ransomware attacks are often performed using stolen passwords, Axios reports. Passkeys are generally considered more secure than passwords because hackers would need both the user’s information and the information from the company. If 1Password’s beta testing is successful, its current business model will fade into obscurity, and modern-day passwords will be a relic of a past, less secure age. - [Security Brief: The FIDO Alliance releases UX guidelines all about passkeys](https://fidoalliance.org/security-brief-the-fido-alliance-releases-ux-guidelines-all-about-passkeys/): The FIDO Alliance has released new user experience (UX) guidelines to help accelerate deployment and adoption of passkeys. The FIDO Alliance UX Guidelines for Passkey Creation and Sign-ins aim to help online service providers design a better, more consistent user experience when signing in with passkeys, the company states.  - [SC Media: New passkey milestones ‘ready for prime time,’ says FIDO Alliance leader](https://fidoalliance.org/sc-media-new-passkey-milestones-ready-for-prime-time-says-fido-alliance-leader/): At the 2023 Identiverse conference, the nonprofit standards organization FIDO Alliance unveiled its new user experience guidelines for passkeys, which are generated and stored securely on users’ devices after those individuals register for a web application or service via their biometric data or a PIN. Among the various benefits: Users do not have to remember any credentials, nor are they prone to losing them via phishing scams. Moreover, passkeys can be synched across multiple user devices without having to re-enroll each time.  - [Security Intelligence: CISA, NSA Issue New IAM Best Practice Guidelines](https://fidoalliance.org/security-intelligence-cisa-nsa-issue-new-iam-best-practice-guidelines/): The Cybersecurity and Infrastructure Security Agency (CISA) and the National Security Agency (NSA) recently released a new 31-page document outlining best practices for identity and access management (IAM) administrators. The most secure types of MFA include fast identity online (FIDO) and public key infrastructure (PKI).  - [TechRadar.pro: Bitwarden now lets you create passkeys for your business apps](https://fidoalliance.org/techradar-pro-bitwarden-now-lets-you-create-passkeys-for-your-business-apps/): Bitwarden - in our view the best free password manager around - has announced Bitwarden Passwordless.dev, a toolkit to allow developers to integrate passkeys into consumer websites and enterprise applications. - [Biometric Update: Consumers ready for passwordless technology and prefer biometrics; FIDO Alliance report](https://fidoalliance.org/biometric-update-consumers-ready-for-passwordless-technology-and-prefer-biometrics-fido-alliance-report/): FIDO Alliance has published a report examining how the behavior, patterns and adoption of authentication technologies reflect the consumers’ readiness for passwordless technologies. - [The Verge: 1Password is finally rolling out passkey management](https://fidoalliance.org/the-verge-1password-is-finally-rolling-out-passkey-management-2/): 1Password customers are finally gaining partial access to the passwordless future we’ve been promised. Starting from June 6th this year, anyone with a 1Password account will be able to use it to save and manage their passkeys — a biometric-based login technology that allows users to ditch passwords in favor of their device’s own authentication. To access the open beta, you’ll need to download the 1Password beta browser extension for Safari, Firefox, or Chromium-based browsers (which include Chrome, Edge, Arc, and Brave). Support for passkeys on mobile is still in development and unavailable at this time. - [PC Mag: How to Set Up Passkeys for Your Google Account](https://fidoalliance.org/pc-mag-how-to-set-up-passkeys-for-your-google-account-2/): Passkeys are easier to use and more secure than passwords, but getting started with them isn't simple. We tell you how to set up and use passkeys for Google on all your devices. - [Fintech Finance News: Virtual Arena: Authentication in the World of Payments](https://fidoalliance.org/fintech-finance-news-virtual-arena-authentication-in-the-world-of-payments/): Welcome back to another insightful Virtual Arena from FF News! In today’s episode, we’ll be taking a deep dive into the payments industry. As alternative payment methods and technologies continue to rise in prominence all over the world, the challenge of verifying the legitimacy of those payments only continues to grow. Today, we’ll be facing that challenge head-on with an in-depth discussion about authentication in the world of payments. - [Ars Technica: Passkeys may not be for you, but they <em>are</em> safe and easy—here’s why](https://fidoalliance.org/ars-technica-passkeys-may-not-be-for-you-but-they-are-safe-and-easy-heres-why/): My recent feature on passkeys attracted significant interest, and a number of the 1,100-plus comments raised questions about how the passkey system actually works and if it can be trusted. In response, I've put together this list of frequently asked questions to dispel a few myths and shed some light on what we know—and don't know—about passkeys. This FAQ will be updated from time to time to answer additional questions of merit, so check back regularly. This author will not be monitoring or responding to comments going forward but can still be contacted through email. - [IT Brew: At RSA, passkeys have the buzz](https://fidoalliance.org/it-brew-at-rsa-passkeys-have-the-buzz/): Google announced in early May that the company is moving accounts over to passkeys, a major move forward in the journey to a passwordless future. - [Webinar: How to use FIDO with the EUDI Wallet](https://fidoalliance.org/video-fido-alliance-webinar-how-to-use-fido-with-the-eudi-wallet/): The EU Digital Identity (EUDI) Wallet, which is a core component of the emerging eIDAS2 regulation, is an area where the FIDO Alliance can provide support through its standards and credentials on authentication. The FIDO Alliance European Working Group and its EUDI Wallet subgroup have been actively supporting the EUDI Wallet initiative since 2021. This FIDO Alliance webinar will describe the FIDO EUDI Wallet subgroup and the potential technical solutions where FIDO may be used as an authentication standard for the EUDI Wallet. - [Wired: The war on passwords enters a chaotic new phase](https://fidoalliance.org/wired-the-war-on-passwords-enters-a-chaotic-new-phase-2/): There was never a question that it would take years to transition the world away from passwords. The digital authentication technology, though deeply flawed, is pervasive and inveterate. Over the last five years, though, the secure-authentication industry association known as the FIDO Alliance has been making real progress promoting “passkeys,” a password-less alternative for signing into applications and websites. - [The Verge: 1Password is finally rolling out passkey management](https://fidoalliance.org/the-verge-1password-is-finally-rolling-out-passkey-management/): 1Password customers are finally gaining access to the passwordless future we’ve been promised. Starting from June 6th this year, anyone with a 1Password account will be able to save and manage their passkeys — a biometric-based login technology that allows users to ditch passwords in favor of their device’s own authentication. - [SC Magazine: The 2023 Identiverse Trends Report](https://fidoalliance.org/sc-magazine-the-2023-identiverse-trends-report/): Safety and security have long been at the heart of identity and access management, and indeed the trends report states that "indications are that there will be a renewed focus on access control, entitlements, and permissioning over the next few years." In keeping with the trend of the death of passwords equaling better authentication, the Identiverse report also celebrates the deployment of passkeys, the Apple-Google-Microsoft system that lets you log into websites with a smartphone instead of a password. We ourselves have had some trouble using passkeys — and the report hints at "the successes and learnings of early deployments" — but there's no denying that passkeys will be a major step toward a passwordless future. - [Find Biometrics: Identity News Digest](https://fidoalliance.org/find-biometrics-identity-news-digest/): About 57 percent of US consumers expressed interest in using passkeys to replace passwords, according to new survey data from the FIDO Alliance. According to FIDO Executive Director and CMO Andrew Shikiar, that points to rapidly growing excitement, given that only 39 percent of survey respondents said they were familiar with the passkey concept in a FIDO survey released last October. Passkeys essentially store complex passcodes for a user’s various online accounts on their mobile device, locking them behind a PIN or biometric scan. Google recently launched passkey support for its own Account login process, garnering considerable media attention in the process. - [PC Mag: How to set up passkeys for your Google account](https://fidoalliance.org/pc-mag-how-to-set-up-passkeys-for-your-google-account/): Passkeys are intended to be more secure and easier to use than passwords. Instead of typing in a password (or letting a password manager do it) and verifying with a multi-factor authentication method, passkeys only require a trusted device and either biometric or PIN verification. Part of why passkeys seem likely to replace passwords is that they're designed by a consortium called the FIDO Alliance and championed by Apple, Google, and Microsoft. These three companies have already baked support for passkeys into their browsers and ecosystems, which means that for the first time, there's a viable alternative to passwords. That said, passkeys have yet to see widespread adoption. - [The Wall Street Journal: Hate passwords? It’s time to try passkeys](https://fidoalliance.org/the-wall-street-journal-hate-passwords-its-time-to-try-passkeys/): I no longer need a password to sign into Google. From now on, it’s “Adios, passwords…Hello, passkeys!” Sort of. This new form of login is like a digital lock and key.  For sites and apps run by financial institutions and other slower-moving, ultracareful services, the shift will take more time, said Andrew Shikiar. He’s executive director of the FIDO Alliance, which creates the standards for online authentication technology such as passkeys. But there are already dozens of services where you can use passkeys to sign in. - [An Inflection Point in the Journey to Passwordless](https://fidoalliance.org/an-inflection-point-in-the-journey-to-passwordless/): Andrew Shikiar, FIDO Alliance Executive Director & CMO - [Wired: Google is rolling out password-killing tech to all accounts](https://fidoalliance.org/wired-google-is-rolling-out-password-killing-tech-to-all-accounts/): Google's announcement of its passkey rollout comes on the eve of World Password Day on Thursday. But passkey proponents are ramping up their efforts to make the occasion obsolete.  - [Video: Stronger Authentication; Stronger Identities: The State of the Industry’s Path to Passwordless](https://fidoalliance.org/video-stronger-authentication-stronger-identities-the-state-of-the-industrys-path-to-passwordless/): FIDO Alliance at Identity Management Day 2023 - [PC Mag: Misinformation, MFA Doubts, and AI: Everything We Saw at RSAC 2023](https://fidoalliance.org/pc-mag-misinformation-mfa-doubts-and-ai-everything-we-saw-at-rsac-2023/): The RSA Conference further proved that passwords are a problem. The solution, we're told, lies in using Passkeys, or cryptographic credentials that securely authenticate individuals without usernames or passwords and have multi-factor authentication (MFA) built-in. Several sessions at RSAC focused on the benefit of Passkeys, while also taking a look at the challenges still ahead.  - [CIO Review: Nok Nok Partners With Carahsoft to Provide Phishing-Resistant MFA Solutions to Federal, State and Local Government Agencies](https://fidoalliance.org/cio-review-nok-nok-partners-with-carahsoft-to-provide-phishing-resistant-mfa-solutions-to-federal-state-and-local-government-agencies/): Nok Nok, a leader in passwordless authentication for the world’s largest organizations, today announced a partnership with Carahsoft Technology Corp. The Nok Nok S3 Authentication Suite is the first passwordless authentication platform based on FIDO standards that includes full support for both device-bound and synced passkeys and compliance solutions - [Wealth Management: The Financial Industry’s 10 Most-Common Passwords](https://fidoalliance.org/wealth-management-the-financial-industrys-10-most-common-passwords/): A new analysis by password manager NordPass stresses that major companies open themselves up to security risks by using passwords that lack creativity. While password trends slightly vary each year across different audiences, the general take is that people continuously fail with their password management, and the world desperately needs to switch to new online authentication solutions such as passkeys. Various progressive businesses such as Google, Microsoft, Apple, PayPal, KAYAK and eBay have already adopted passkey technology and are offering their users password-less logins. It is thought that in no time at all, other online companies will start following this trend. - [Biometric Update: FIDO Alliance paper positions protocol for EU Digital Identity Wallet authentications](https://fidoalliance.org/biometric-update-fido-alliance-paper-positions-protocol-for-eu-digital-identity-wallet-authentications/): The EU Digital Identity Wallet represents a significant growth opportunity for FIDO authentication, according to a new white paper from the FIDO Alliance. The 45-page white paper on ‘Using FIDO for the EUDI Wallet’ was written by IDnow Senior Architect Sebastian Elfors from the proceedings of the FIDO subgroup on the EUDI Wallet to help government agencies weigh the use of FIDO for the EUDI Wallet under the eIDAS2 regulation.  - [Dark Reading: Twitter’s 2FA is a call for passkey disruption](https://fidoalliance.org/dark-reading-twitters-2fa-is-a-call-for-passkey-disruption/): Despite exciting progress toward more secure and usable factors, the best MFA mechanism for consumers really isn't MFA at all — it's passkeys. Passkeys are a FIDO authenticator with the advantage of being backed up to the cloud, so if you lose your device or buy a new one, all you must do is sign into your iCloud or Google Play account to recover your passkeys. Passkeys use public key cryptography and device biometrics, making them resistant to many known attacks, and are easy for the user. - [The Fintech Times: Are passwords a thing of the past? A passwordless future: 1Password Report](https://fidoalliance.org/the-fintech-times-are-passwords-a-thing-of-the-past-a-passwordless-future-1password-report/): There is a strong appetite amongst consumers for easier-to-use login experiences; according to human-centric security and privacy company 1Password – which has released its ‘Preparing for a Passwordless Future’ report. Andrew Shikiar, executive director and CMO of the FIDO Alliance, said: “Passwordless technology brings great benefits for companies and their customers alike—making it easier to securely access online services while greatly reducing fraud and user frustration. This has been the mission of the FIDO Alliance since day one, with authentication experts from hundreds of companies, including 1Password, collaborating to make this vision a reality with passkey sign-ins.” - [Wired: The war on passwords enters a chaotic new phase](https://fidoalliance.org/wired-the-war-on-passwords-enters-a-chaotic-new-phase/): Over the last five years, though, the secure-authentication industry association known as the FIDO Alliance has been making real progress promoting “passkeys,” a password-less alternative for signing into applications and websites. - [White Paper: Using FIDO for the EUDI Wallet](https://fidoalliance.org/white-paper-using-fido-for-the-eudi-wallet/): This white paper describes the eIDAS2 ecosystem and how to use the FIDO standard with the EU Digital Identity (EUDI) Wallet. - [The Green Sheet: Passwordless future within reach, experts say](https://fidoalliance.org/the-green-sheet-passwordless-future-within-reach-experts-say/): FIDO Alliance held a virtual conference to assess recent advancement in creating simpler, stronger, authentication methods. The half-day event included panel discussions and fireside chats with experts from Google, Microsoft, Amazon and leading global brands that support FIDO's mission to create secure, scalable alternatives to passwords. In opening remarks, Andrew Shikiar, executive director of FIDO Alliance, stated that FIDO deployments have helped companies reduce fraud, lower operational costs and boost employee productivity. He additionally noted that companies are looking at top-line benefits of getting users online faster with greater satisfaction and reduced shopping cart abandonment. - [AARP: Fraud fighters are working to keep scam “epidemic” at bay](https://fidoalliance.org/aarp-fraud-fighters-are-working-to-keep-scam-epidemic-at-bay/): Impressive new technology to fight fraud is emerging from businesses. The tech industry association called the FIDO Alliance is working toward replacing passwords — a key vulnerability — with more secure technologies, including biometrics. Executive Director Andrew Shikiar says this could be done for most online passwords within five years. - [Digital Transactions: Why the password is going extinct](https://fidoalliance.org/digital-transactions-why-the-password-is-going-extinct/): Usernames and passwords have been the most common authentication method for digitally accessing an account. However, passwords are vulnerable to compromise through a variety of attack vectors. “Passwords are fundamentally flawed, because they can be hacked, forgotten, and stolen,” says Andrew Shikiar, executive director and chief marketing officer for the FIDO Alliance. “It’s also tough to enter passwords on keyboardless devices. Plus, more than 80% of data breaches can be tracked back to passwords.” - [Futura Sciences: AI breaks most passwords in less than a minute: here are the ones that stand up](https://fidoalliance.org/futura-sciences-ai-breaks-most-passwords-in-less-than-a-minute-here-are-the-ones-that-stand-up/): Researchers from the cybersecurity company Home Security Heroes have trained an AI to decipher millions of passwords. It took less than a minute to find most of them. But the AI stumbles for some passwords. Passkeys are a way to strengthen security. - [Compare the Cloud: The passwordless future](https://fidoalliance.org/compare-the-cloud-the-passwordless-future/): It’s nearly two decades since Bill Gates predicted the passing of the traditional username and password, warning that this archaic security combo simply wasn’t up to the task of keeping information safe and secure in the long term. Passwords will not be around forever and if we are ever to get serious about cyber security and the protection of data, we have to find another way. That’s one of the main reasons why passwordless authentication is gaining so much popularity as a more secure and convenient alternative to traditional passwords. And it seems the industry agrees. Tech giants Apple, Google, and Microsoft announced last May that they would support FIDO2 — authentication specifications based on public key cryptography and international standards — to enable passwordless authentication across devices.  - [Recap: Authenticate Virtual Summit: Authentication in Financial Services and Commerce](https://fidoalliance.org/recap-authenticate-virtual-summit-authentication-in-financial-services-and-commerce/): By: FIDO Staff - [SK Telecomm announces adoption of passkeys for online users in Korea](https://fidoalliance.org/sk-telecom-announces-adoption-of-passkeys-for-online-users-in-korea/): By Joon Hyuk Lee, APAC Market Development Director, FIDO Alliance - [Tech Radar: This identity management firm is the first big player to ditch passwords](https://fidoalliance.org/tech-radar-this-identity-management-firm-is-the-first-big-player-to-ditch-passwords/): ForgeRock has become the first identity management platform to make the leap into the brave new world of passwordless security. ForgeRock has been implementing passwordless solutions for more than a decade in the consumer realm, and its Identity Platform has deployed passwordless solutions for mobile and web apps. The company already supports FIDO2 WebAuthn  standards and passkeys, the foremost technologies currently used in passwordless authentication which are supported by big tech firms such as Apple, Google, Amazon and Meta. - [WEB.de: AI fraud with a stolen voice](https://fidoalliance.org/web-de-ai-fraud-with-a-stolen-voice/): Online providers need to check if and when they use convenient but technically easily surmountable authentication options. Strong access security is offered by the FIDO2 standard, for example, which even allows secure passwordless access. - [Blog NT: NordPass announces support for passkeys](https://fidoalliance.org/blog-nt-nordpass-announces-support-for-passkeys/): Passkeys are the future of digital security. Password managers such as 1Password, Dashlane and LastPass have already announced support for this new technology. NordPass joins this list this week with support for Passkeys in its application. - [Biometric Update: HYPR turns smartphones into FIDO2 virtual security keys for passwordless authentication](https://fidoalliance.org/biometric-update-hypr-turns-smartphones-into-fido2-virtual-security-keys-for-passwordless-authentication/): Decentralized authentication firm HYPR has unveiled a new software tool that enables companies to use smartphones as FIDO2 virtual security keys for passwordless authentication. - [Beta Kit: How 1Password plans to build a passwordless future](https://fidoalliance.org/beta-kit-how-1password-plans-to-build-a-passwordless-future/): Now in a key 18-month window, 1Password plans to ramp up its shift to passkeys in 2023. - [Journal du Net: Digital accessibility: Why CIOs should make it a priority](https://fidoalliance.org/journal-du-net-digital-accessibility-why-cios-should-make-it-a-priority/): In this byline, Andrew Shikiar explains how simple and safe digital accessibility is an essential human right today. - [L’Eclaireur FNAC: How password managers are preparing for a future … without passwords](https://fidoalliance.org/leclaireur-fnac-how-password-managers-are-preparing-for-a-future-without-passwords/): Passwordless authentication has the potential to continue to grow in 2023. In any case, the tech giants, Microsoft, Google and Apple in the lead, within the FIDO Alliance, are doing everything to ensure that the adoption happens as soon as possible. To quickly summarize what we had already explained previously, authentication without passwords, or passwordless , has, as its name suggests, the purpose of allowing you to connect to sites and services without passwords. - [ComputerWeekly: Accessible authentication: What companies need to consider  ](https://fidoalliance.org/computerweekly-accessible-authentication-what-companies-need-to-consider/): In this byline, Andrew Shikiar, executive director and CMO of the FIDO Alliance explains the importance of accessible, secure authentication for all. - [Communications of the ACM: Passkeys unlock a new era for authentication](https://fidoalliance.org/communications-of-the-acm-passkeys-unlock-a-new-era-for-authentication/): Until recently, replacing passwords has ranked somewhere between tricky and impossible. Passkeys completely eliminate passwords, and while they won’t end cyberattacks, they represent a far more convenient and secure framework to navigate the digital world. “Legacy frameworks, including some forms of two-factor authentication, depend on a human-readable and shared secret. This makes them highly susceptible to attack and relatively easy to bypass,” explains Andrew Shikiar, executive director of the FIDO Alliance. - [SC Media: What should Musk do to better secure Twitter users after 2FA goes away?](https://fidoalliance.org/sc-media-what-should-musk-do-to-better-secure-twitter-users-after-2fa-goes-away-2/): While Twitter CEO Elon Musk has defended the move to ban 2FA for non-subscribers as a way to protect user security, most leaders aren’t buying it. “Just from a purely pragmatic standpoint, this is basically stripping away the lowest threshold of 2FA out there without any sort of viable or easy replacement,” said Andrew Shikiar, executive director of the FIDO Alliance. As Shikiar sees it, Twitter could have told users that they’re removing OTP but educating users on passkeys, which are safer and built into Android and iOS devices. - [SC Media: GitHub to roll out 2FA for all contributors starting March 13](https://fidoalliance.org/sc-media-github-to-roll-out-2fa-for-all-contributors-starting-march-13/): GitHub will begin its official rollout of two-factor authentication for developers who contribute code on the platform, starting March 13. GitHub added that it will support SMS text messages as a second factor, while testing FIDO Alliance passkeys internally to improve the security posture. “It is true that SMS 2FA can be easily phished by hackers as it relies on knowledge-based credentials. But GitHub recognizes these risks and strongly recommends using security keys and TOTPS wherever possible for greater security – will continue to offer SMS for 2FA – which is better than removing the option entirely,” said Andrew Shikiar, executive director of the FIDO Alliance. - [Yahoo! JAPAN announces support for passkeys across available platforms](https://fidoalliance.org/yahoo-japan-announces-support-for-passkeys-across-available-platforms/): By Andrew Shikiar, Executive Director and CMO, FIDO Alliance  - [SC Media: What should Musk do to better secure Twitter users after 2FA goes away?](https://fidoalliance.org/sc-media-what-should-musk-do-to-better-secure-twitter-users-after-2fa-goes-away/): In just two weeks, the ban on SMS two-factor authentication for non-subscribers on Twitter will go into effect, a move blasted by the majority of the security community. - [Tech Target: GitHub 2FA plan adds SMS, account lockout safeguards](https://fidoalliance.org/tech-target-github-2fa-plan-adds-sms-account-lockout-safeguards/): GitHub reaffirmed this week that it is testing passkeys from the FIDO Alliance industry association, which is developing "open standards that are more secure than passwords and SMS OTPs, simpler for consumers to use, and easier for service providers to deploy and manage." Passkeys use public key cryptography standards to authenticate client devices that are protected using biometrics, such as smartphones, eliminating password-based authentication altogether. - [Ghacks: How to configure two-step login via FIDO2 WebAuthn in Bitwarden](https://fidoalliance.org/ghacks-how-to-configure-two-step-login-via-fido2-webauthn-in-bitwarden/): Bitwarden password manager users who want to step up the security may configure two-step login via FIDO2 WehAuthn. The feature is not available for all users or in all Bitwarden apps. This article is designed for Bitwarden users who want to understand what FIDO2 WebAuthn is, how it differs from traditional two-factor authentication systems, and how to set it up on Bitwarden. - [The Mover: Expect the Unexpected: Top cybersecurity predictions for 2023](https://fidoalliance.org/the-mover-expect-the-unexpected-top-cybersecurity-predictions-for-2023/): Due to rapid developments in both safe and harmful technology, cybersecurity is among the most volatile industries. However, we can still identify certain trends affecting the industry. From passwordless solutions broadly available to consumers, to the first real-life cases of automotive hacking, all of these are likely to shape the cybersecurity landscape in 2023. 2022 marks the year when the passwordless future idea experienced its first big wins, and 2023 is expected to be even more fruitful. Many progressive companies are likely to adopt the new passkeys technology, supported by the FIDO (Fast Identity Online) Alliance. Tech giants such as Microsoft, Apple, and Google have already announced their commitment to delivering passwordless logins and even introduced their first efforts to consumers. - [ComputerWeekly: How ForgeRock is tackling identity management](https://fidoalliance.org/computerweekly-how-forgerock-is-tackling-identity-management/): ForgeRock CEO Fran Rosch has set the identity and access management software supplier on a path to deliver a frictionless identity experience without compromising security or privacy. The article mentions how FIDO standards can tackle the bad experiences users can have with classic authentication systems. - [Sciences et Avenir: The dream of a passwordless Internet](https://fidoalliance.org/sciences-et-avenir-the-dream-of-a-passwordless-internet/): The Passkey system used by Apple or Google enables simple and secure online authentication. However, other studies by cyber security experts are less concerned with removing passwords than with strengthening them with additional methods. - [IAVC World: Cloud & Security: What IT resellers and CSPs need to do now](https://fidoalliance.org/iavc-world-cloud-security-what-it-resellers-and-csps-need-to-do-now/): For many years, Microsoft has offered the possibility to reliably protect accesses from takeovers using multi-factor authentication (MFA) and Fast Identity Online (FIDO). In addition to MFA and FIDO2, Microsoft has recently started offering authentication using certificates in Azure AD. With FIDO Passkey, passwordless authentication can even be realised in Azure AD. - [Dashlane Blog: Dashlane Passkey Support Coming to Android](https://fidoalliance.org/dashlane-blog-dashlane-passkey-support-coming-to-android/): If you use a dedicated password manager, such as Dashlane, you’ll probably expect it to manage your passkeys for you, just as it does with your passwords. Unlike passwords, the mechanism passkeys use is more sophisticated under the hood, though this isn’t apparent in the user experience; passkeys are actually much simpler than passwords to create and use.  Dashlane has been at the forefront of passkey support since passkeys were announced last year. In August, Dashlane introduced integrated passkey support in our security-first password manager and unveiled the first in-browser passkey solution. - [Politico Pro: Call for Regs Exposes Divides in White House and On Hill](https://fidoalliance.org/politico-pro-call-for-regs-exposes-divides-in-white-house-and-on-hill/): Senator Wyden is urging the Senate sergeant at arms to mandate that lawmakers and Hill staff use an industry-standard security practice to access sensitive Senate networks, per a Friday letter shared first with MC. “Thousands of Senate employees who currently use less-secure forms of MFA must be re-issued new, phishing-resistant FIDO tokens and the Senate must stop supporting methods of MFA that are vulnerable to phishing,” reads the letter. - [Tech Radar: Android 14 might get rid of passwords for good](https://fidoalliance.org/tech-radar-android-14-might-get-rid-of-passwords-for-good/): As Dashlane puts it, "Passkeys are phishing-resistant credentials based on FIDO standards and are the future of online authentication, designed as a more secure and user-friendly replacement for passwords." FIDO is the alliance that sets the standards for passwordless technologies, and passkeys need to comply with its WebAuthn specifications. It has the backing of all the big tech players - Apple, Google, Microsoft, Meta, Amazon and so on. - [Tech Radar: This year’s newest and most dangerous cyber attack techniques](https://fidoalliance.org/tech-radar-this-years-newest-and-most-dangerous-cyber-attack-techniques/): There is continued movement away from using multiple use passwords and towards adopting multifactor authentication (MFA), passkeys, FIDO 2 authentication and other additional layers of security. Companies like Apple and Google are also developing their own authentication token systems. - [ChannelPartner: Cloud and Security 2023](https://fidoalliance.org/channelpartner-cloud-and-security-2023/): For many years, Microsoft has been offering the option of reliably protecting access from takeovers using multi-factor authentication (MFA) and Fast Identity Online (FIDO). In addition to MFA and FIDO2, Microsoft has recently also offered authentication using certificates in Azure AD, which opens up new possibilities for using cloud services. - [L’Eclaireur Fnac: Dashlane is moving forward with passkeys and becoming more transparent](https://fidoalliance.org/leclaireur-fnac-dashlane-is-moving-forward-with-passkeys-and-becoming-more-transparent/): Dashlane was one of the first tools to support passkeys for the FIDO Alliance. The famous password manager is making some changes in its strategy and intends to expand its access to passkeys. - [Global Security Mag: FIDO Alliance announces its “Authenticate 2023” conference](https://fidoalliance.org/global-security-mag-fido-alliance-announces-its-authenticate-2023-conference/): The FIDO Alliance is pleased to announce the return of Authenticate, the only industry conference dedicated to all aspects of user authentication – including a focus on FIDO-based sign-ins. - [Cloudflare embraces FIDO to help its own security](https://fidoalliance.org/cloudflare-embraces-fido-to-help-its-own-security/): THE CHALLENGE:Improving Employee Access with Zero Trust - [Professional Security Magazine Online: Password posers](https://fidoalliance.org/professional-security-magazine-online-password-posers/): It is hard to imagine a world without passwords. They remain the most-used authentication method for consumers according to the Fast IDentity Online (FIDO) Alliance’s annual Online Authentication Barometer, despite the fact that passwords almost universally fail at keeping accounts secure and preserving a smooth user experience. The death of the password will be a huge relief for users, removing the need to remember or type passwords and enabling better user experiences. For organisations, the upsides are just as powerful, with a passwordless future offering better improved security, reduced risk of data breaches and lower support costs. As we enter the new year, 2023 seems set to be the year when passwords finally become an endangered species. - [Schieb: Passkey instead of password: FIDO Keys](https://fidoalliance.org/schieb-passkey-instead-of-password-fido-keys/): Passwords are actually obsolete: they are insecure, impractical and easy to crack/steal. There have long been better methods of securing online accounts. Above all: Passkeys. - [L’Éclaireur Fnac: How Password Managers Are Preparing for a Future…Without Passwords](https://fidoalliance.org/leclaireur-fnac-how-password-managers-are-preparing-for-a-futurewithout-passwords/): Passwordless authentication has the potential to continue to grow in 2023. In any case, the tech giants, Microsoft, Google and Apple in the lead, within the FIDO Alliance, are doing everything to ensure that the adoption happens as soon as possible. To quickly summarize what we had already explained previously, authentication without passwords, or passwordless , has, as its name suggests, the purpose of allowing you to connect to sites and services without passwords. - [FIDO Alliance Announces Authenticate 2023 Conference](https://fidoalliance.org/fido-alliance-announces-authenticate-2023-conference/): Premier authentication conference returns for fourth year; call-for-speakers open - [CNBC: Why passkeys from Apple, Google, Microsoft may soon replace your passwords](https://fidoalliance.org/cnbc-why-passkeys-from-apple-google-microsoft-may-soon-replace-your-passwords/): The death of the internet password has been proclaimed many times, but this time, it may actually be coming sooner than you think. Its replacement? The passkey. - [Tech Times: Apple, Google, and Microsoft are Pushing Passkeys: Password-less Future?](https://fidoalliance.org/tech-times-apple-google-and-microsoft-are-pushing-passkeys-password-less-future/): As major tech giants like Apple, Microsoft, and Google take the lead in fully integrating passkey technology into their platforms, passwords may become a thing of the past. Passkeys offer a more secure and convenient way of accessing online accounts and services without the risk of hackers or easy-to-remember passwords. - [Android Headlines: 1Password is going passwordless with ‘Passkeys’](https://fidoalliance.org/android-headlines-1password-is-going-passwordless-with-passkeys/): After the whole LastPass fiasco, many users are wary of entrusting their sensitive information to online password managers. But the era of password-protected vaults may soon be a thing of the past, as leading tech companies, including 1Password, are pushing for a new form of authentication technology that is more secure than passwords called passkeys. The company recently announced plans to support passkeys in the summer of 2023, allowing users to log in to accounts without using a master password. - [Gizchina: GOODBYE PASSWORDS; HELLO PASSKEYS FROM APPLE, GOOGLE, AND MICROSOFT](https://fidoalliance.org/gizchina-goodbye-passwords-hello-passkeys-from-apple-google-and-microsoft/): Internet passwords death may have been proclaimed many times before. But this time, with Apple, Google, and Microsoft going big on passkeys, you might soon have to say goodbye to passwords. - [FIDO Alliance Awards Winner and Top Finalists of Developer Challenge – India](https://fidoalliance.org/fido-alliance-awards-winner-and-top-finalists-of-developer-challenge-india/): By Joon Hyuk Lee, APAC Market Development Director, FIDO Alliance - [Biometric Update: Transparency can drive digital ID equity, policy forum panelists say](https://fidoalliance.org/biometric-update-transparency-can-drive-digital-id-equity-policy-forum-panelists-say/): An event last week on ‘Identity, Authentication and the Road Ahead’ held by the Better Identity Coalition, the FIDO Alliance and the Identity Theft Resource Center held a panel discussion among biometrics experts on equity and bias concerns in identity proofing. - [Tech Republic: Unphishable mobile MFA through hardware keys](https://fidoalliance.org/tech-republic-unphishable-mobile-mfa-through-hardware-keys/): Passwords are a mess, MFA can be more of a stopgap than a solution to phishing and running your own public key infrastructure for certificates is a lot of work. The long-term goal is to move to passwordless credentials that can’t be phished. - [Intelligent CISO: Passing on passwords in 2023 (finally)](https://fidoalliance.org/intelligent-ciso-passing-on-passwords-in-2023-finally/): Passwords are often an organisation’s weakest link. On World Password Day (May 5), Apple, Google and Microsoft jointly announced that they were building in support for passwordless sign-in, leveraging FIDO2, across all of the desktop, browser and mobile platforms that they control. Crucially, they have all emphasised cross-platform functionality will be a high priority in the development of FIDO2-based passwordless features. With the help of its community of identity, security and biometrics experts, the FIDO Alliance has developed and promoted free, open standards that have taken passwordless authentication to the next level. - [CyberWire: NIST on phishing resistance](https://fidoalliance.org/cyberwire-nist-on-phishing-resistance/): According to NIST Special Publication DRAFT 800-63-B4, a phishing-resistant authenticator offers “the ability of the authentication protocol to detect and prevent disclosure of authentication secrets and valid authenticator outputs to an impostor relying party without reliance on the vigilance of the subscriber.” Two examples of phishing-resistant authenticators are PIV cards for US Federal employees and FIDO authenticators paired with W3C’s Web Authentication API for the private sector. - [Solutions Review: Identity Management and Information Security News for the Week of February 3; Radiant Logic, Guardz, Legrand, and More](https://fidoalliance.org/solutions-review-identity-management-and-information-security-news-for-the-week-of-february-3-radiant-logic-guardz-legrand-and-more/): Axiad, a passwordless solutions provider, announced it has been appointed to the FIDO Alliance Board of Directors. Karen Larson, Axiad’s Senior Director, Strategic Partnerships and Alliances will serve as Axiad’s Primary Board Delegate. In her new role as a FIDO Alliance Board Member, Larson will help set direction for the alliance focused specifically on the authentication needs of the enterprise and public sector. - [Business Today: Making the Internet safer and better for all – including our seniors](https://fidoalliance.org/business-today-making-the-internet-safer-and-better-for-all-including-our-seniors/): Andrew Shikiar highlights growing cyber threats and e-scams amongst seniors online. As one of the least technologically savvy groups, the elderly is also one of the most vulnerable – and targeted – demographics by online scammers. To achieve a more secure Internet for everyone, we must ensure that the elderly’s needs and preferences are considered. Fortunately, there are readily available standards and best practices to help service providers guide users in adopting passwordless authentication.  - [Tech Radar Pro: <em>Apple says these are the best security keys around now</em>](https://fidoalliance.org/tech-radar-pro-apple-says-these-are-the-best-security-keys-around-now/): Whatever security key you choose, it must be FIDO certified, Apple says. Apple has revealed what it believes are the best security keys to add an extra layer of protection to your digital world.  The recent release of iOS 16.3 saw Apple add security key compatibility to its iPhone and iPad devices - as well as to its laptops and desktops with the macOS 13.2 update. Now, in a support document, the company has selected its recommendations for the best physical security keys to use with its devices, which comply with FIDO standards - the foremost alliance on credential security that most of big tech are signed up to. - [B2B Cybersecurity: Do companies need a Chief Zero Trust Officer?](https://fidoalliance.org/b2b-cybersecurity-do-companies-need-a-chief-zero-trust-officer/): The FIDO Alliance provides that you can log in anywhere without a password. Face or fingerprint login is used instead of the old username/password combination. A FIDO login key, sometimes called a “passkey,” makes it easier for users and harder for attackers. - [CSO: What are passkeys?](https://fidoalliance.org/cso-what-are-passkeys/): The FIDO Alliance is the main body behind defining specifications for passkeys. All major cloud service providers and Passkey infrastructure providers are members. In cooperation with the W3C, FIDO introduced the WebAuthn API. - [NIST: Phishing Resistance – Protecting the keys to your kingdom](https://fidoalliance.org/nist-phishing-resistance-protecting-the-keys-to-your-kingdom/): Phishing refers to a variety of attacks that are intended to convince you to forfeit sensitive data to an imposter. These attacks can take a number of different forms; from spear-phishing (which targets a specific individual within an organization), to whaling (which goes one step further and targets senior executives or leaders). Furthermore, phishing attacks take place over multiple channels or even across channels; from the more traditional email-based attacks to those using voice – vishing – to those coming via text message – smishing. Regardless of the type or channel, the intent of the attack is the same – to exploit human nature to gain control of sensitive information (citation 1). These attacks typically make use of several techniques including impersonated websites, attacker-in-the-middle, and relay or replay to achieve their desired outcome. - [Cybersecurity Policy Forum: Identity, Authentication and the Road Ahead](https://fidoalliance.org/cybersecurity-policy-forum-identity-authentication-and-the-road-aheadcybersecurity-policy-forum/): 2023 brings a new year and a new Congress – but America is still struggling with many of the same old problems when it comes to digital identity and authentication. Passwords keep getting phished, new account fraud keeps growing, and companies and consumers continue to struggle to prove that they are not a proverbial “dog on the Internet.” It’s becoming a major policy concern – and policymakers are considering a number of new initiatives to better protect people and combat these trends. - [Recap: 2023 Identity, Authentication and the Road Ahead #IDPolicyForum](https://fidoalliance.org/recap-2023-identity-authentication-and-the-road-ahead-idpolicyforum/): By: FIDO staff - [GlobeNewswire: NordPass will store passkeys and offer passwordless authentication](https://fidoalliance.org/globenewswire-nordpass-will-store-passkeys-and-offer-passwordless-authentication/): LONDON, Jan. 26, 2023 (GLOBE NEWSWIRE) -- On Thursday, NordPass, the password management company, announced its plans to provide passwordless online authentication solutions to its users in the upcoming months. With an increasing number of websites supporting passkey technology, the company's customers will soon be able to keep their passkeys in NordPass and access it with biometrics only. - [Security Boulevard: Are you using a FIDO Certified authenticator?](https://fidoalliance.org/security-boulevard-are-you-using-a-fido-certified-authenticator/): Multi-factor authentication (MFA) gets touted as a significant security improvement over traditional “username + password” authentication. However, not all MFA processes are created equal. As the opportunities narrow for cybercriminals to pick off the low-hanging fruit of password-only systems, they’ve turned their focus to weak MFA. - [Next Impact: Passwordless Authentication: BitWarden Acquires Passwordless.dev](https://fidoalliance.org/next-inpact-passwordless-authentication-bitwarden-acquires-passwordless-dev/): Even if the movement will take years, sooner or later the future will be without passwords. Many companies are investing in this transition, including large ones. Last year we saw the proclamation of passkeys, led by the Apple-Google-Microsoft triad, under the aegis of the FIDO Alliance. - [CSO: How passkeys are changing authentication](https://fidoalliance.org/cso-how-passkeys-are-changing-authentication/): Well-implemented passkeys can improve the user experience and make it harder for cybercriminals to launch phishing and other attacks. - [XDA Developers: Here’s how FIDO security keys will keep your Apple ID secure](https://fidoalliance.org/xda-developers-heres-how-fido-security-keys-will-keep-your-apple-id-secure/): FIDO security keys are an additional layer of protection for your Apple ID, and here's how they keep it secure. The most recent update for iOS, iPadOS, and macOS brought a number of improvements and other changes, but one that stands out is the introduction of support for FIDO Certified security keys for Apple IDs. Apple has since detailed how these keys work with your Apple ID, and how you can use them to secure your account. - [Payments Journal: 2023 Predictions: Authentication, Digital Identity, and In-Car Payments](https://fidoalliance.org/payments-journal-2023-predictions-authentication-digital-identity-and-in-car-payments/): As the number of devices and connected services rise, our lives are becoming increasingly digitized. Keeping up with this evolving landscape is vital, and 2023 promises to bring with it a host of new use cases and innovations. New technologies are coming to market that provide a greatly enhanced user experience that doesn’t compromise on security. Innovative solutions such as SoftPOS are challenging traditional payment methods, while account-to-account (A2A) payments have the potential to shake up the entire payments ecosystem. - [Silicon: Authentication: “Apple ID + FIDO key” option enabled](https://fidoalliance.org/silicon-authentication-apple-id-fido-key-option-enabled/): Using a FIDO key as a second authentication factor on an Apple account is now possible, under certain conditions. - [CISO Series: Cyber Security Headlines: Bypassing patches, ChatGPT polymorphic malware, Bitwarden goes passwordless](https://fidoalliance.org/ciso-series-cyber-security-headlines-bypassing-patches-chatgpt-polymorphic-malware-bitwarden-goes-passwordless/): Bitwarden acquires Passwordless.dev - This marks the first acquisition for the open-source password management platform, obtaining the Swedish startup PAsswordless.dev. The company specializes in tools for developers to integrate passwordless authentication. Bitwarden supports some passwordless authentication already, including biometrics and the use of FIDO security keys. - [Forbes: Thousands Of PayPal Accounts Hacked—Is Yours One Of Them?](https://fidoalliance.org/forbes-thousands-of-paypal-accounts-hacked-is-yours-one-of-them/): According to a PayPal notice of security incident dated January 18, attackers got unauthorized access to the accounts of thousands of users between December 6 and 8, 2022. The total number of accounts that were accessed by threat actors using a credential stuffing attack is reported as being 34,942. While accepting that PayPal is seemingly doing the best it can for the customers involved in this security incident by recommending password changes, Jasson Casey, chief technology officer at Beyond Identity insists that "passwords - whether unique or complex - are fundamentally flawed." Instead, Casey says, organizations should be moving to phishing-resistant credentials such as the FIDO Alliance standard blueprints. - [B2B Cyber Security: Cybersecurity Trends for 2023](https://fidoalliance.org/b2b-cyber-security-cybersecurity-trends-for-2023/): Perhaps the FIDO Alliance’s passkey solution is the first truly effective method to mitigate social engineering attacks. This is because the passkey for authentication on the respective website is based on the device unlocking method used by the user. - [Sky News: ‘Passkeys’ mean you ‘never need to know a password’](https://fidoalliance.org/sky-news-passkeys-mean-you-never-need-to-know-a-password/): Image Matrix Tech Editor Djuro Sen says “passkeys”, developed by FIDO, means you “never need to know a password”. “It essentially removes the fact of using a password and you just use your device, your phone or something else, mostly your phone, to log in to say, through this example, eBay,” Mr Sen told Sky News Australia. “This uses a type of cryptography that has a public key and a private key.” - [Financial IT: 2023 Predictions: Authentication, Digital Identity and In-Car Payments](https://fidoalliance.org/financial-it-2023-predictions-authentication-digital-identity-and-in-car-payments/): On major trend from 2022 is the continued evolution of the fraud industry. A combination of active and passive authentication can ensure that the payments flow is secure while limiting the impact on the customer experience. Major global payment schemes are introducing new regulations that will see banks recognize the authentication work done on the merchant side. This means that merchants are able to leverage industry authentication standards like FIDO Alliance to create their own checkout journey to reduce the friction between the customer and merchant services. This helps combat both fraud and cart abandonment, helping to deliver higher sales conversion rates and a better return on investment. - [Ça m’intéresse: 2023, year of the end of passwords?](https://fidoalliance.org/ca-minteresse-2023-year-of-the-end-of-passwords/): Often criticized and victim of security flaws, the password system could soon be replaced by a more reliable technology: passkey. - [IT-Business: Netwrix Password Secure: How to ensure secure password management in companies](https://fidoalliance.org/it-business-netwrix-password-secure-how-to-ensure-secure-password-management-in-companies/): The Yubico Security Key is based on the authentication method of the FIDO Alliance and the World Wide Web Consortium (W3C) for mobile devices and browsers. Using the FIDO2 algorithm (Fast Identity Online) it is possible to identify yourself to online services with verified hardware. - [Information Age: Cybersecurity predictions for 2023](https://fidoalliance.org/information-age-cybersecurity-predictions-for-2023/): Andrew Shikiar, executive director of FIDO Alliance, thinks that we’ll see a lot more high-profile, sophisticated attacks which bypass legacy multi-factor authentication (MFA) in 2023. <...> Andrew Shikiar, executive director of FIDO Alliance, predicts the metaverse will become a growing target for hackers, with MFA becoming a stronger imperative as attacks increase in volume and sophistication. <...> Being sent OTP text messages as part of multi-factor authentication will be seen as not fit for purpose once organisations understand how hackable they are, says Andrew Shikiar, executive director of FIDO Alliance. - [TEISS: Cyber-security in 2023](https://fidoalliance.org/teiss-cyber-security-in-2023-2/): Andrew Shikiar at FIDO Alliance gives his predictions for what can we expect from the cyber-security industry in 2023. - [InfoSecurity: Point/Counterpoint: Are We Moving to a Passwordless Future?](https://fidoalliance.org/infosecurity-point-counterpoint-are-we-moving-to-a-passwordless-future/): Yes: Andrew Shikiar. You might think you’ve heard it all before, right? A passwordless age is the cyber utopia we all yearn for but promises of totally wiping out passwords feels far-fetched and far off. After all, how do you go about unpicking a thread so tightly woven into your daily life? Eradicating passwords will take time, but recent industry news and progress is showing we can confidently say the future is passwordless – and getting nearer.  - [The Green Sheet: Fierce authentication for an omnichannel threatscape](https://fidoalliance.org/the-green-sheet-fierce-authentication-for-an-omnichannel-threatscape/): The ability to transact across all channels has opened opportunities and threats, expanding retail and hospitality playing fields and creating a broader attack surface for fraudsters. Now more than ever it is important to understand how to properly protect your company. While at Authenticate, Andrew Shikiar explains the FIDO journey and its 2022 achievements including passkey, stating that he believes, “we have an opportunity with authentication to be a bridge of the digital divide and not another wedge.” - [Transaction Trends (US): ETA Expert Insights: FIDO Designs Faster Deployments](https://fidoalliance.org/transaction-trends-us-eta-expert-insights-fido-designs-faster-deployments/): FIDO was founded in 2012 by PayPal, Lenovo, and Nok Labs. They are working to change authentication through open standards that are more secure than passwords, more straightforward for consumers, and more accessible for service providers to deploy and manage. FIDO’s latest innovation, passkey, provides fast, easy, secure sign-ins to websites and apps across multiple devices. Passkey users can sign in with a biometric, PIN or security key rather than a username and password, FIDO representatives noted, and without having to re-enroll devices or accounts each time, they sign in. - [SDxCentral (US): FIDO Pushes Password Replacement as MFA Bypass Attacks to Surge in 2023](https://fidoalliance.org/sdxcentral-us-fido-pushes-password-replacement-as-mfa-bypass-attacks-to-surge-in-2023/): The FIDO Alliance expects to see more high-profile cyberattacks targeting cloud service providers that bypass traditional multi-factor authentication (MFA), which will push more major brands to adopt the passkey password replacement in 2023. - [WIRED: The Password Isn’t Dead Yet. You Need a Hardware Key](https://fidoalliance.org/wired-the-password-isnt-dead-yet-you-need-a-hardware-key/): After years of work, the tech industry finally took major steps in 2022 toward a long-promised passwordless future. The move is riding on the back of a technology called “passkeys” that are built on FIDO standards. Operating systems from Apple, Google, and Microsoft now support the technology, and many other platforms, browsers, and services have adopted it or are in the process of doing so. As much as you might wish it, though, passwords aren't going to disappear anytime soon, thanks to their sheer ubiquity. And amid all the buzz about passkeys, hardware tokens are still an important protection option. - [ITPro.: The IT Pro Podcast: Going passwordlessITPro.:](https://fidoalliance.org/itpro-the-it-pro-podcast-going-passwordlessitpro/): Passwords: they can be tricky at the best of times. Proper password hygiene is one of the most important factors in endpoint security, as it keeps sensitive data secure and prevents threat actors from getting into important systems.  - [Biometric Update: PayEye dual biometrics win FIDO certification with zero PAD errors](https://fidoalliance.org/biometric-update-payeye-dual-biometrics-win-fido-certification-with-zero-pad-errors/): Polish fintech provider PayEye has obtained its FIDO Biometric Component Certification and proven highly resistant to presentation attacks, according to a news release. - [Payments Journal: On-Demand Webinar: Go Beyond Fraud Prevention with Identity](https://fidoalliance.org/payments-journal-on-demand-webinar-go-beyond-fraud-prevention-with-identity/): When companies use identity data effectively, they deliver a highly personalized, frictionless journey that offers the right products to the right customers at the right time. They’re also able to optimize fraud prevention while minimizing any irritation for customers.  - [Biometric Update: FIDO offers guidance for government service use as countries deploy blockchain, biometrics](https://fidoalliance.org/biometric-update-fido-offers-guidance-for-government-service-use-as-countries-deploy-blockchain-biometrics/): Governments around the world continue to develop digital identity capabilities to give residents easier access to public services, and the FIDO Alliance has published a white paper to help them do so in phishing-resistant ways. The paper comes as a pair of alternative approaches to digital identity for government services are implemented, in Turkey and Bangladesh. - [CSO: Why it might be time to consider using FIDO-based authentication devices](https://fidoalliance.org/cso-why-it-might-be-time-to-consider-using-fido-based-authentication-devicescso/): Every business needs a secure way to collect, manage, and authenticate passwords. Unfortunately, no method is foolproof. Storing passwords in the browser and sending one-time access codes by SMS or authenticator apps can be bypassed by phishing. Password management products are more secure, but they have vulnerabilities as shown by the recent LastPass breach that exposed an encrypted backup of a database of saved passwords. For organizations with high security requirements, that leaves hardware-based login options such as FIDO devices. - [Teiss: Cyber-security in 2023 ](https://fidoalliance.org/teiss-cyber-security-in-2023/): Andrew Shikiar at FIDO Alliance gives his predictions for what can we expect from the cyber-security industry in 2023. The last twelve months online haven’t been short of action – good and bad. From high-profile breaches and widespread smishing attacks to metaverse speculation and Twitter drama. Not forgetting, of course, the major news in March that saw public backing of new passwordless log-in technology (FIDO passkeys) from some of the world’s largest platform vendors – admittedly we were extra excited about this one…  - [Webinar: Making FIDO Deployments Accessible to Users with Disabilities](https://fidoalliance.org/webinar-making-fido-deployments-accessible-to-users-with-disabilities-2/): In achieving FIDO Alliance's mission of more secure and password-free authentication, we must ensure the needs and preferences of people with disabilities – an estimated 15% of the world's population – are taken into account.  - [Webinar: Making FIDO Deployments Accessible to Users with Disabilities](https://fidoalliance.org/webinar-making-fido-deployments-accessible-to-users-with-disabilities/): In achieving FIDO Alliance's mission of more secure and password-free authentication, we must ensure the needs and preferences of people with disabilities – an estimated 15% of the world's population – are taken into account.  - [Videos: FIDO Alliance Public Seminar in Korea](https://fidoalliance.org/videos-fido-alliance-public-seminar-in-korea/): On December 6, 2022, the FIDO Alliance Public Seminar in Korea was held at the SK Telecom Pangyo Office. This seminar provided global updates, in-depth training on passkeys, and the latest local FIDO deployment case studies. - [White Paper: FIDO for e-Government Services](https://fidoalliance.org/white-paper-fido-for-e-government-services/): The global COVID-19 pandemic closed offices and forced governments to rapidly move services online, if they weren’t already, to serve its citizens. Although usernames and passwords are easy to deploy and easy for citizens to use, they leave systems and users vulnerable to cyberattacks. They are especially vulnerable to phishing attacks designed to steal login credentials and compromise legacy multi-factor authentication (MFA) tools like those using one-time passwords (OTP) and push notifications. With phishing attacks on the rise, it is imperative for governments to support “phishing-resistant” MFA technology that is also accessible, efficient, and cost-effective. - [heise: Passkeys: What makes them tick and how they work](https://fidoalliance.org/heise-passkeys-what-makes-them-tick-and-how-they-work/): Passwords: previous attempts to replace them have consistently failed. The Fast Identity Online Alliance (FIDO) and the World Wide Web Consortium W3C made a promising push in 2018 with the FIDO2 standard. - [Tech Target: 4 key elements of successful IoT device onboarding](https://fidoalliance.org/tech-target-4-key-elements-of-successful-iot-device-onboarding/): FIDO: New help on the way: - [ZDNet France: What if we replaced the “security by obscurity”, dependent on passwords, with “security by community”?](https://fidoalliance.org/zdnet-france-what-if-we-replaced-the-security-by-obscurity-dependent-on-passwords-with-security-by-community/): Security by obscurity is an outdated approach, not suited to today’s cyberattacks, nor to today’s digital world, according to Andrew Shikiar, Executive Director and CMO of the FIDO Alliance. - [Momentum for FIDO in Japan Grows as Major Companies Commit to Passwordless Sign-ins with Passkeys](https://fidoalliance.org/momentum-for-fido-in-japan-grows-as-major-companies-commit-to-passwordless-sign-ins-with-passkeys/): Yahoo! JAPAN, KDDI and NTT DOCOMO have adopted or committed to passkeys - [Authenticate Summit Recap: The FIDO Fit in IoT](https://fidoalliance.org/authenticate-summit-recap-the-fido-fit-in-iot/): By: FIDO Staff - [FIDO Alliance Provides Guidance on Making FIDO Deployments Accessible to People with Disabilities](https://fidoalliance.org/fido-alliance-provides-guidance-on-making-fido-deployments-accessible-to-people-with-disabilities/): By Christina Hulka, executive director and COO of the FIDO Alliance - [Infosecurity Magazine: November’s M&A News Roundup](https://fidoalliance.org/infosecurity-magazine-novembers-ma-news-roundup/): On November 3, 1Password announced the acquisition of passwordless authentication company Passage. The move will enable 1Password to accelerate the adoption of passkeys for developers, businesses and their customers. The deal follows 1Password joining the open industry association FIDO Alliance earlier in 2022. - [Silicon: Cybersecurity: automation, to the delight of attackers?](https://fidoalliance.org/silicon-cybersecurity-automation-to-the-delight-of-attackers/): Automation stands out as one of the major trends in the predictions that cybersecurity market players are issuing for 2023. - [Global Security Mag: FIDO Alliance Predictions 2023](https://fidoalliance.org/global-security-mag-fido-alliance-predictions-2023/): Andrew Shikiar, Executive Director and CMO of the FIDO Alliance delivers his authentication and cybersecurity predictions for the year 2023. - [ChannelPartner: How Apple’s password alternative works in practice](https://fidoalliance.org/channelpartner-how-apples-password-alternative-works-in-practice/): Passkeys are not an Apple invention: The new standard, also called WebAuthn, is backed by the so-called FIDO Alliance and the W3C. However, it is supported by the three platforms Android, Windows and iOS/macOS, and Apple, Google and Microsoft are working together on this. Passkeys are intended to completely replace passwords and enable simple and secure login to websites and applications. - [Raconteur 2022 Report: Authentication & Digital Identity](https://fidoalliance.org/raconteur-authentication-digital-identity/): Insight: Sharing cybersecurity successes and failures leads to improvement – Andrew Shikiar, executive director and CMO at the FIDO Alliance, explains why a culture of secrecy surrounding cybersecurity is holding back progress - [FIDO Alliance Announces Authenticate Virtual Summit focused on Securing IoT](https://fidoalliance.org/fido-alliance-announces-authenticate-virtual-summit-focused-on-securing-iot/): Industry experts to share insights into how FIDO and related technologies can bring passwordless authentication to IoT - [L’Eclaireur FNAC: Passkey: towards the end of passwords in 2023?](https://fidoalliance.org/leclaireur-fnac-passkey-towards-the-end-of-passwords-in-2023-3/): The FIDO Alliance is developing an alternative authentication system that will eliminate complex passwords that are difficult to remember. We explain how. - [ZDNet: Phishing-resistant multifactor authentication](https://fidoalliance.org/zdnet-phishing-resistant-multifactor-authentication/): Multifactor authentication (MFA) can be compromised by phishing. The key is to make MFA more resistant. There are several ways to implement phishing-resistant MFA, the most common approach is called FIDO. - [Tech Radar: Apple’s announcement could spell the end for passwords – and the beginning for biometrics](https://fidoalliance.org/tech-radar-apples-announcement-could-spell-the-end-for-passwords-and-the-beginning-for-biometrics/): Apple’s Passkey technology uses established industry standards from the FIDO Alliance, which Apple helped develop and is working with other technology companies and service providers around the world to reduce the collective reliance on passwords. The FIDO Alliance passwordless login standards are already supported by billions of devices and all modern web browsers. - [Heise: PayPal: Passkey instead of password for Apple users](https://fidoalliance.org/heise-paypal-passkey-instead-of-password-for-apple-users/): PayPal is the first major service to jump on the FIDO passkey bandwagon: iPhone users will be able to log in to the payment service without a password. Users of Apple devices are able to exchange their password with the service for a passkey. The login is then carried out via a public key encryption procedure in accordance with the FIDO standard, the password stored by the user becomes superfluous. - [Teiss: Security by obscurity keeps us password-dependent](https://fidoalliance.org/teiss-security-by-obscurity-keeps-us-password-dependent-2/): We need security, by community. Andrew Shikiar of the FIDO Alliance calls on more businesses to see that sharing is caring when it comes to cyber security. - [Financial IT: FIDO Alliance study reveals password usage still dominates financial services – and is proving costly](https://fidoalliance.org/financial-it-fido-alliance-study-reveals-password-usage-still-dominates-financial-services-and-is-proving-costly/): The FIDO Alliance published its second annual Online Authentication Barometer, which gathers insights into the state of online authentication in 10 countries across the globe. New to the Barometer this year, the FIDO Alliance has begun tracking authentication in the metaverse and plans to incorporate the utilization of technologies like passkeys in future editions of the report. - [Dark Reading: Microsoft’s Certificate-Based Authentication enables phishing resistant MFA](https://fidoalliance.org/dark-reading-microsofts-certificate-based-authentication-enables-phishing-resistant-mfa/): Microsoft has removed a key obstacle facing organizations seeking to deploy phishing-resistant multifactor authentication (MFA) by enabling certificate-based authentication (CBA) in Azure Active Directory. This comes as experts anticipate advanced phishing attacks will rise next year. “I think social engineering and MFA bypass attacks will continue to grow in 2023, where some other major service providers suffer meaningful breaches like we did this year,” Andrew Shikiar says. - [Axios: 1 big thing: passkeys enter the mainstream](https://fidoalliance.org/axios-1-big-thing-passkeys-enter-the-mainstream/): Poor password hygiene is the root cause of more than 80% of data breaches, according to the FIDO Alliance. Efforts to ditch easy-to-guess, phrase-based passwords are gaining more traction with the adoption of passkeys, paving the way for the passwordless future cybersecurity pros dream of. Growing passkey adoption requires widespread availability, industry collaboration and regulatory support, says FIDO Alliance executive director Andrew Shikiar. - [Intelligent CISO: Biometric technology revolutionises identity space](https://fidoalliance.org/intelligent-ciso-biometric-technology-revolutionises-identity-space/): The use of biometric technology has taken off in recent years which could largely be down to loopholes in password security becoming more apparent. Biometrics represents the most convenient and easy form of Multi-Factor Authentication and is therefore very well placed to increase security. It’s easy to combine biometric patterns, fingerprint combined with facial, for example, and to complete it with other authentication method – as per FIDO Alliance standards. - [Security Insider: The future of user authentication: password methods on the brink of extinction?](https://fidoalliance.org/security-insider-the-future-of-user-authentication-password-methods-on-the-brink-of-extinction/): For some time now, the ‘big three’ - Google, Apple and Microsoft - have been working together with the FIDO Alliance to implement a new, cross-platform login standard: the ‘Passkey’ system. - [IBS Intelligence: <strong>Financial services still use passwords – and it’s costing them</strong> ](https://fidoalliance.org/ibs-intelligence-financial-services-still-use-passwords-and-its-costing-them/): The FIDO Alliance published its second annual Online Authentication Barometer, which gathers insights into the state of online authentication in 10 countries across the globe. New to the Barometer this year, the Alliance has begun tracking authentication in the metaverse. - [Business Leader: <strong>Post-pandemic security: 79% IT decision-makers want company password manager implemented</strong>](https://fidoalliance.org/business-leader-post-pandemic-security-79-it-decision-makers-want-company-password-manager-implemented/): According to the Bitwarden survey, roughly half of respondents deploy or have plans to deploy password-less technology. Of that percentage, 66% have one-to-two user groups or multiple teams using password-less technology, and 13% have deployed to their entire organisation. Of those that have made the switch, 51% are or would consider implementing ‘something you are’ password-less authentication. Half (47%) say they are very familiar with the FIDO2 password-less authentication standard and consider it important to their company’s password-less experience. - [Tagesspiegel Background: Cyber attacks: Pressure on insurance market grows](https://fidoalliance.org/tagesspiegel-background-cyber-attacks-pressure-on-insurance-market-grows/): The Cyber Risk Outlook 2023 of the American rating agency Moodys analyses the most important risk developments for companies and investors in the field of cyber security on a global level. The introduction of FIDO is apparently encountering hurdles. Apps and websites need time to adapt to FIDO passkeys. - [L’Eclaireur FNAC: Passkey: towards the end of passwords in 2023?](https://fidoalliance.org/leclaireur-fnac-passkey-towards-the-end-of-passwords-in-2023-2/): The FIDO Alliance is developing an alternative authentication system that will eliminate complex passwords that are difficult to remember. We explain how. - [Financial IT: FIDO Alliance study reveals password usage still dominates financial services – as is proving costly](https://fidoalliance.org/financial-it-fido-alliance-study-reveals-password-usage-still-dominates-financial-services-as-is-proving-costly/): The FIDO Alliance published its second annual Online Authentication Barometer, which gathers insights into the state of online authentication in 10 countries across the globe. New to the Barometer this year, the FIDO Alliance has begun tracking authentication in the metaverse and plans to incorporate the utilization of technologies like passkeys in future editions of the report. - [Teiss: Security by obscurity keeps us password-dependent](https://fidoalliance.org/teiss-security-by-obscurity-keeps-us-password-dependent/): We need security by community. Andrew Shikiar of the FIDO Alliance calls on more businesses to see that sharing is caring when it comes to cyber security. - [Giga: PayPal Passkeys: How the login works](https://fidoalliance.org/giga-paypal-passkeys-how-the-login-works/): With “Passkeys”, the payment service introduces a new, secure login method that allows you to log in to PayPal without a password. - [L’Eclaireur FNAC: Passkey: towards the end of passwords in 2023?](https://fidoalliance.org/leclaireur-fnac-passkey-towards-the-end-of-passwords-in-2023/): The FIDO Alliance is developing an alternative authentication system that will eliminate complex passwords that are difficult to remember. We explain how. - [Video: The Future of Passwords is Passwordless](https://fidoalliance.org/video-the-future-of-passwords-is-passwordless/): Online security experts, featuring CISA, FIDO Alliance, Google and Microsoft discuss why the future of passwords is no passwords. - [FIDO Alliance study reveals global password usage is down – yet its continued dominance is proving costly](https://fidoalliance.org/fido-alliance-study-reveals-global-password-usage-is-down-yet-its-continued-dominance-is-proving-costly-2/): FIDO Alliance’s second annual Online Authentication Barometer reveals the habits, trends and adoption of authentication technologies - [Tech Radar: PayPal is doing away with passwords for some users](https://fidoalliance.org/tech-radar-paypal-is-doing-away-with-passwords-for-some-users/): PayPal has added support for passwordless login using the FIDO Alliance’s passkey authentication for users with Apple devices. The company announced that it would begin to offer support for passkeys on Apple devices - including iPhones, iPads, and Mac - on its website, giving customers a simple and secure way to log in without the need to remember complex passwords. - [Computer BILD: PayPal Passkeys: Log in easily and securely without a password](https://fidoalliance.org/computer-bild-paypal-passkeys-log-in-easily-and-securely-without-a-password/): To make logins on the internet more secure, several companies worldwide have joined forces and founded the FIDO Alliance, including Microsoft, Apple, Google, Visa, Mastercard, Amazon, Samsung - and PayPal. - [IT Social: Double authentication is slowly taking hold](https://fidoalliance.org/it-social-double-authentication-is-slowly-taking-hold/): The FIDO Alliance Barometer notes that password entry has decreased overall in all use cases studied. But they are still the most common authentication method. - [Authenticate 2022: Day 3 Recap](https://fidoalliance.org/authenticate-2022-day-3-recap/): By: FIDO Staff - [Authenticate 2022: Day 2 Recap](https://fidoalliance.org/authenticate-2022-day-2-recap/): By: FIDO Staff - [FIDO Alliance study reveals global password usage is down – yet its continued dominance is proving costly](https://fidoalliance.org/barometer-2022/): FIDO Alliance’s second annual Online Authentication Barometer reveals the habits, trends and adoption of authentication technologies - [FIDO Alliance study reveals global password usage is down – yet its continued dominance is proving costly](https://fidoalliance.org/fido-alliance-study-reveals-global-password-usage-is-down-yet-its-continued-dominance-is-proving-costly/): FIDO Alliance’s second annual Online Authentication Barometer reveals the habits, trends and adoption of authentication technologies - [CPO Magazine: Targeted Phishing Attacks That Overtook MFA – Setting up a Better Security Defense](https://fidoalliance.org/cpo-magazine-targeted-phishing-attacks-that-overtook-mfa-setting-up-a-better-security-defense/): Last month two companies, Twilio and Cloudflare, were attacked by cyber criminals. While it may be tempting to dismiss these attacks as simply being the latest in a long list of high-profile attacks that have occurred over the last few years, there were several aspects about the Twilio and Cloudflare attacks that made them stand out. The cyber attackers used new and advanced phishing techniques against these companies which are likely to be used again in the future. - [VentureBeat: Google introduces passwordless authentication to Chrome and Android with passkeys](https://fidoalliance.org/venturebeat-google-introduces-passwordless-authentication-to-chrome-and-android-with-passkeys/): Password-based security is an oxymoron. With over 15 billion exposed credentials leaked on the dark web, and 54% of security incidents caused by credential theft, passwords simply aren’t effective at keeping out threat actors.  - [Cybersecurity Dive: What is phishing-resistant multifactor authentication? It’s complicated.](https://fidoalliance.org/cybersecurity-dive-what-is-phishing-resistant-multifactor-authentication-its-complicated/): Multifactor authentication can bear weaknesses that render its efficacy moot. A common response and answer to the most problematic forms of MFA, though the details are limited at best, is phishing-resistant MFA. - [All About Security: FIDO Alliance introduces new certification program](https://fidoalliance.org/all-about-security-fido-alliance-introduces-new-certification-program/): The FIDO Alliance has expanded its range of certification programs: With the new Document Authenticity (DocAuth) Certification Program, it is targeting the increasing need for powerful solutions for secure and easy-to-use online identity verification. Providers can use the standardized test procedure to check whether their document verification solutions are able to identify the authenticity of identity documents and their correspondence with the user. The certification also validates that the solutions are fit for commercial use and meet the performance criteria set out in the FIDO Alliance's DocAuth requirements catalogue. In addition, service providers can use the program as a benchmark for evaluating solution providers. In this way you can ensure that the solutions meet globally established standards and prevent malicious actors from creating accounts with forged or stolen documents. Several providers have already started the certification process; the first FIDO DocAuth certified products are expected to be available in early 2023. - [White Paper:  Guidance for Making FIDO Deployments Accessible to Users with Disabilities ](https://fidoalliance.org/white-paper-guidance-for-making-fido-deployments-accessible-to-users-with-disabilities/): In achieving FIDO Alliance’s mission of more secure and password-free authentication, we must ensure the needs and preferences of people with disabilities—an estimated 15% of the world’s population—are taken into account. This white paper is intended to provide guidance on planning FIDO deployments accessible to users with a wide range of disabilities.  - [FIDO Alliance Announces Document Authenticity Certification Program for Remote Verification](https://fidoalliance.org/fido-alliance-announces-document-authenticity-certification-program-for-remote-verification/): Mountain View, Calif., October 13, 2022- The FIDO Alliance today announced the latest addition to its range of certification programs to address the rising need for stronger, simpler online identity verification: the Document Authenticity (DocAuth) Certification Program. The program allows vendors to certify that their mobile document verification solutions accurately determine if a government-issued identity document is authentic, matches the presented user, and complies with the performance criteria set forth in FIDO Alliance’s Document Authenticity (DocAuth) Requirements. Multiple vendors have started the certification process and the first FIDO DocAuth Certified products are anticipated to be available in early 2023. - [The Top Cyber Attacks Still Scaring us this Halloween – and How to Stop Them](https://fidoalliance.org/the-top-cyber-attacks-still-scaring-us-this-halloween-and-how-to-stop-them/): This Cybersecurity Awareness Month, we’re raising awareness of the most frightening social engineering attacks and how we can banish these monsters to the past… - [Identity-based cyberattacks are the leading cause of security breaches. Here’s how to stop them.](https://fidoalliance.org/identity-based-cyberattacks-are-the-leading-cause-of-security-breaches-heres-how-to-stop-them/): Businesses are facing a surge in attacks using stolen identity credentials — now the largest source of breaches. While there’s no cure-all, experts recommend a strategy involving the adoption of stronger authentication and authorization systems, as well as tools to provide better visibility into identity-based attacks and “shadow IT” use. - [Securing the future of IoT with AI biometric technology](https://fidoalliance.org/securing-the-future-of-iot-with-ai-biometric-technology-2/): The world needs an IoT future, so It’s time to forget your password – for good. A new breed of AI-powered biometric security measures is required. - [Tech Business News: Cloudflare Makes Hardware Security Keys Accessible for Millions of Customers](https://fidoalliance.org/cloudflare-makes-hardware-security-keys-accessible-for-millions-of-customers/): Cloudflare Democratizes Spoof-Proof Security; Makes Hardware Security Keys More Accessible Than Ever for Millions of Customers Because it’s Good for the Internet... - [2K warns users their info has been stolen following breach of its help desk](https://fidoalliance.org/2k-warns-users-their-info-has-been-stolen-following-breach-of-its-help-desk/): Game company 2K on Thursday warned users to remain on the lookout for suspicious activity across their accounts following a breach last month that allowed a threat actor to obtain email addresses, names, and other sensitive information provided to 2K's support team. - [NordPass joins FIDO Alliance to help change people’s habits when it comes to passwords](https://fidoalliance.org/nordpass-joins-fido-alliance-to-help-change-peoples-habits-when-it-comes-to-passwords/): NordPass, Nord Security’s password management company, announced that it had joined the FIDO Alliance, a global coalition working to provide open and free authentication standards to help reduce the world’s reliance on passwords. - [Securing the future of IoT with AI biometric technology](https://fidoalliance.org/securing-the-future-of-iot-with-ai-biometric-technology/): The world needs an IoT future, so It’s time to forget your password – for good. A new breed of AI-powered biometric security measures is required - [SC Magazine: Five ways security teams can respond to the Uber breach](https://fidoalliance.org/sc-magazine-five-ways-security-teams-can-respond-to-the-uber-breach/): How should security leaders respond to the Uber breach? Traditional MFA doesn't work, so put your company on a FIDO U2F or a passwordless FIDO2 journey. - [ComputerWorld: NCSC publishes cyber guidance for retailers](https://fidoalliance.org/computerworld-ncsc-publishes-cyber-guidance-for-retailers/): The UK’s National Cyber Security Centre (NCSC) has published explicit guidance designed to support retailers, hospitality providers and utility services in protecting both themselves and their customers from the growing impact of cyber-crime. The guidance emphasizes the need to add extra layers of security on top of passwords, such as multi-factor authentication, OAuth 2.0 or single sign-on, FIDO2, or one-time passcodes. - [Journal du net: How FIDO keys will accelerate a password-free future](https://fidoalliance.org/journal-du-net-how-fido-keys-will-accelerate-a-password-free-future/): The FIDO Alliance is an open standard that allows users to authenticate themselves via a highly secure, phishing-resistant and easy-to-implement cryptographic login. - [NZZ Magazine: The end of the password search](https://fidoalliance.org/nzz-magazine-the-end-of-the-password-search/): Apple is not cooking up its own security soup when implementing passkeys. The passkey integration is based on the open standard WebAuthn of the FIDO Alliance. - [Webinar: Optimizing User Experiences with FIDO Security Keys](https://fidoalliance.org/webinar-optimizing-user-experiences-with-fido-security-keys-2/): This webinar will provide essential education for any organization that wants to implement phishing-resistant authentication with FIDO security keys. - [Webinar: Optimizing User Experiences with FIDO Security Keys](https://fidoalliance.org/webinar-optimizing-user-experiences-with-fido-security-keys/): This webinar will provide essential education for any organization that wants to implement phishing-resistant authentication with FIDO security keys. - [UploadMagazin: Passkeys and FIDO: The future without passwords explained](https://fidoalliance.org/uploadmagazin-passkeys-and-fido-the-future-without-passwords-explained/): The future without passwords is explained in this German feature piece, exploring why passkeys are outdates, who FIDO is and how passkeys work. The piece concludes that while there may be some limitations with passkeys, it’s undeniable that passkeys offers a means forward and a positive note for the industry. - [Security Insider: What is FIDO?](https://fidoalliance.org/security-insider-what-is-fido/): This piece in a top tier German security magazine offers an overview of the FIDO Alliance and accompanies a podcast episode on the topic hosted with Rolf Lindemann, an active FIDO Alliance Board Member and Co-Chair of numerous working groups, that explores how FIDO will replace passwords with passkeys. - [Help Net Security: IoT: The huge cybersecurity blind spot that’s costing millions](https://fidoalliance.org/help-net-security-iot-the-huge-cybersecurity-blind-spot-thats-costing-millions-2/): This contributed byline from Andrew Shikiar, executive director and CMO of FIDO Alliance, details cybersecurity blind spots generated by growing IoT technology adoption. To address these issues, the FIDO Alliance launched FIDO Device Onboard (FDO) in 2021 to tackle two main problems: deployment efficiency and security at the point of onboarding. The main feature of FDO is fully automated device onboarding, which considerably speeds up the previously manual process. FDO also replaces generic password credentials with highly secure cryptographic keys, making the devices considerably more robust against attack. - [The Times: The Times view on the magic of ‘passkeys’: Open Sesame](https://fidoalliance.org/the-times-the-times-view-on-the-magic-of-passkeys-open-sesame/): Teams from Apple, Google, Microsoft, Amazon, Meta (the owner of Facebook, Instagram and other social media platforms) and other leading technology groups have worked together to develop a passkey, unique to each user, that can unlock apps and provide access to websites, eventually across all platforms. Passkeys were launched by Apple yesterday in the latest version of its operating system, iOS16. - [The Times: Using your face as a password is easy as abc123](https://fidoalliance.org/the-times-using-your-face-as-a-password-is-easy-as-abc123/): Apple, Google and Microsoft put aside rivalries to work together on the passkey, along with a group called the Fido (Fast Identity Online) alliance, so that they can be used on different devices, browsers and operating systems. - [BFM Tech&CO: How does the “passkey” work, the authentication system that will bury passwords?](https://fidoalliance.org/bfm-techco-how-does-the-passkey-work-the-authentication-system-that-will-bury-passwords/): The end of forgotten or stolen passwords? Apple is launching “passkeys” today, a new identification system that should make the use of cryptic passwords to guarantee the security of one’s accounts a thing of the past. In practice, logging in anywhere will be as easy as unlocking your screen: every site that offers to use passkeys will ask the user if they want to use them to authenticate. It will then be necessary to use the usual method of unlocking the phone (PIN code, pattern, fingerprint or facial recognition) to validate the connection, explains the Fast Identity Online Alliance (FIDO Alliance), which is behind this process. - [WELT: This technology should soon make the password superfluous](https://fidoalliance.org/welt-this-technology-should-soon-make-the-password-superfluous/): Even the best password can be intercepted or stolen. Instead, “Fido 2” can make logging on with a computer or smartphone secure - and without a password at all. Apple, Google and Co. already use the IT standard. And even older PCs can be upgraded. - [Süddeutsche Zeitung: This is how Apple wants to make passwords superfluous](https://fidoalliance.org/suddeutsche-zeitung-this-is-how-apple-wants-to-make-passwords-superfluous/): Apple has shown it to everyone again. In early May 2022, Apple, Google and Microsoft jointly declared that passwordless login with security keys was coming “sometime in 2023”. Now the iPhone company has packed its version of the login - Apple calls it “Passkeys” - directly into its new mobile operating system iOS 16. It has been available to users since Monday. This is how Apple wants to make passwords superfluous. - [Washington Examiner: Farewell, passwords: How Passkeys will change digital privacy ](https://fidoalliance.org/washington-examiner-farewell-passwords-how-passkeys-will-change-digital-privacy/): When Apple releases iOS 16 in September, it will debut the highly anticipated Passkey, a new form of security authorization that will allow users to sign into accounts without having to use a password. This effort was announced in May as part of a joint press release by Google, Apple, and Microsoft promoting a "passwordless future" based on new support for FIDO credentials. FIDO credentials are built on a digital standard that uses public-key cryptography to communicate secure authorizations to a user’s account. - [Security Management: The Pernicious Problem of Passwords](https://fidoalliance.org/security-management-the-pernicious-problem-of-passwords-2/): While some experts continue to stress the use of password managers to solve the password problem, other developments might quash it entirely by killing the password altogether. This effort gained momentum when Apple, Google, and Microsoft committed to expanding their support for the FIDO standard to accelerate the availability of passwordless sign-ins. Users will soon be able to use two new capabilities for passwordless sign-ins. The first will let users automatically access their FIDO sign-in credentials on devices without re-enrolling their accounts. The second will let users enable FIDO authentication on their mobile devices to sign into an application or website on a nearby device, regardless of the operating system platform or browser they are using. - [Help Net Security: IoT: The huge cybersecurity blind spot that’s costing millions ](https://fidoalliance.org/help-net-security-iot-the-huge-cybersecurity-blind-spot-thats-costing-millions/): This contributed byline from Andrew Shikiar, executive director and CMO of FIDO Alliance, details cybersecurity blind spots generated by growing IoT technology adoption. To address these issues, the FIDO Alliance launched FIDO Device Onboard (FDO) in 2021 to tackle two main problems: deployment efficiency and security at the point of onboarding. The main feature of FDO is fully automated device onboarding, which considerably speeds up the previously manual process. FDO also replaces generic password credentials with highly secure cryptographic keys, making the devices considerably more robust against attack.  - [Wired: Apple’s Killing the Password. Here’s Everything You Need to Know](https://fidoalliance.org/wired-apples-killing-the-password-heres-everything-you-need-to-know/): Apple’s rollout of passkeys is one of the largest implementations of password-free technology to date and builds on years of work by the FIDO Alliance, an industry group made up of tech’s biggest companies. Apple’s passkeys are its version of the standards created by the FIDO Alliance, meaning they will eventually work with Google, Microsoft, Meta, and Amazon’s systems. - [Computerwoche BILD: Passwordless PC access: Tips and tools for a passwordless PC](https://fidoalliance.org/computerwoche-bild-passwordless-pc-access-tips-and-tools-for-a-passwordless-pc/): Passwords can be replaced. With the tools here, they are still in play, but fade into the background. Truly password-free web services are those that allow logging in via a special USB security key - keyword FIDO2 (Fast IDentity Online 2). The range of compatible web services is still rather thin. It is possible that FIDO replaces passwords or functions as a second factor (2FA, two-factor authentication). - [White Paper: FIDO Authentication in Digital Payment Security](https://fidoalliance.org/white-paper-fido-authentication-in-digital-payment-security/): The Indian Payments ecosystem is going through rapid change and advancement. The Reserve Bank of India (Digital Payment Security Controls) Directions 2020 were issued for regulated entities to set up a robust governance structure for such systems and implement common minimum standards of security controls for channels like internet, mobile banking, and card payments, among others. In this paper, we demonstrate how FIDO Authentication represents the best way for organizations to implement simpler, stronger authentication that meets Reserve Bank of India’s Master Direction on Digital Payment Control requirements, while also enhancing the user experience. - [Security Management: The Pernicious Problem of Passwords](https://fidoalliance.org/security-management-the-pernicious-problem-of-passwords/): A recent SpyCloud study showed that over 64% of people reuse their passwords. Some experts continue to stress the use of password managers to mitigate this issue, but this could be squashed by eliminating passwords all together. Going passwordless gained momentum in the second half of 2022 when Apple, Google and Microsoft committed to expanding their support for the FIDO standard. FIDO’s work has resulted in the development of FIDO Universal Second Factor (FIDO U2F), FIDO Universal Authentication Framework, and FIDO2- which have been embraced and further utilized by a few of the largest tech companies in the world. - [The New Stack: Why Developers Need Passwordless](https://fidoalliance.org/the-new-stack-why-developers-need-passwordless/): In recent years, developers have been the targets of multiple attacks due to their access to sensitive systems.  As the tech giants have begun their collaboration on making the user experience of passwordless better, users still need to register across all their devices. The solution to this is passkeys that allow users to easily and securely access passwordless systems across all devices. The FIDO2 Authentication standards are based on public key cryptography for authentication that is more secure than passwords and SMS one-time passwords. FIDO2 Authentication enables password-only logins to be replaced with secure and fast login experiences across websites and apps. - [Digital Journal: Google Chrome Soon to Offer Biometric Authentication Option on Desktops](https://fidoalliance.org/digital-journal-google-chrome-soon-to-offer-biometric-authentication-option-on-desktops/): To help businesses eliminate data risks and carve out a competitive advantage, Transmit Security, a leading provider of modular, orchestrated identity services, offers passwordless logins with FIDO authentication. According to Chrome Unboxed, Google will soon introduce biometric authentication to Chrome on Windows and MacOS. This new upgrade will provide users with a more secure option for authentication while viewing their saved passwords in Chrome. In light of this new move by Google, Transmit Security has released a guide to biometric authentication. - [The SCTE: Forget Password?](https://fidoalliance.org/the-scte-forget-password/): The recent announcement from the FIDO Alliance promises to do away with post-it notes, memorable words and password reset emails clogging up your inbox, as soon as next year. - [Computer Weekly: LastPass breach limited in scale and well-managed, say experts](https://fidoalliance.org/computer-weekly-lastpass-breach-limited-in-scale-and-well-managed-say-experts/): A cyber security breach that unfolded at LastPass – a provider of credential management services – appears to have affected only the firm’s developer environment, and is unlikely to rebound on users, according to community experts, who have praised the firm for its quick and transparent response to the incident. Many providers, including LastPass, are offering and migrating to passwordless logins which use more advanced security technologies such as FIDO2 security keys. This reduces friction for end-users and increases the overall account security. - [Tech Radar: The journey to passwordless – it’s a marathon, not a sprint](https://fidoalliance.org/tech-radar-the-journey-to-passwordless-its-a-marathon-not-a-sprint/): Our online lives are protected, first and foremost, by passwords. They are a part of our everyday lives and protect our sensitive information in the digital world. However, they aren’t a flawless system of protection, and our lives would certainly be easier without the need for them. Many reuse passwords across accounts or set up very weak ones, easily guessed ones, and the truth is we are under a constant threat of cyberattacks by increasingly savvier hackers. Current basics of online security must ensure there is a high standard of education and password hygiene. From there, there are tools to help reinforce the education, such as password managers, and Single Sign-On (SSO) or Multi-factor Authentication (MFA) options. For a passwordless world, however, there needs to be more. Fast Identity Online (FIDO) technologies support authentication mechanisms, such as biometric face and fingerprint ID and the addition of hardware security keys. - [BR24: Passkeys: Why we will soon no longer need passwords](https://fidoalliance.org/br24-passkeys-why-we-will-soon-no-longer-need-passwords/): The tech industry agrees: the days of the password are numbered. So-called “passkeys” are supposed to be a secure and simple alternative. The first services are now introducing them as a login option. - [Medienwoche: Passkeys and FIDO: The future without passwords explained](https://fidoalliance.org/passkeys-and-fido-the-future-without-passwords-explained/): Apple recently presented its version of “passkeys”, which are to replace passwords in the not too distant future. In doing so, the US company is not going its own way, but is relying on the open standard of the FIDO Alliance, which is also supported by other industry giants such as Microsoft, Google, Facebook (“Meta”) and Amazon. - [TechNative: Your top IT governance questions answered](https://fidoalliance.org/technative-your-top-it-governance-questions-answered/): Security threats are always changing and evolving causing us to shift gears into how we can better approach authentication. While there are plenty of authentication methods, the root of the security problem is the password. Traditional MFA solutions have proven to provide little additional assurance and leave companies vulnerable unless they make a change. By eliminating the password, we can eliminate the most common cyber-attack vector. Passwordless MFA (PMFA) is the only way to break this cycle. PMFA is phishing resistant and is core to the Zero Trust model which is part of FIDO2. CISA has endorsed FIDO2 as the gold standard for authentication. By eliminating the weakest part of the security chain, automated attacks are virtually eliminated.  - [Intelligent CISO: Experts discuss the changing role of the CISO and its impacts on management style](https://fidoalliance.org/intelligent-ciso-experts-discuss-the-changing-role-of-the-ciso-and-its-impacts-on-management-style/): The role of the Chief Information Security Officer (CISO) has notably changed since the COVID-19 pandemic. According to Dale Heath, Technology Lead at Rubrik A/NZ, “A holistic security approach – combining infrastructure, cloud and data security (or end-to-end Zero Trust security) – is required to help keep an organisation safe.”  “This means bringing together prevention, detection and investigation as well as ensuring data resilience, data observability and data recovery.”  The next plan of action is to go passwordless. The industry is on the cusp of replacing passwords and legacy Multi-Factor Authentication (MFA) methods with modern open authentication standards, like FIDO2. These standards will enable widespread adoption of phishing-resistant and usable security, and hopefully, will be able to help CISOs to eradicate an entire class of issues that have long been associated with passwords. - [Security Insider: Passwordless authentication](https://fidoalliance.org/security-insider-passwordless-authentication/): Two-factor authentication (2FA), Fast IDentity Online (FIDO), WebAuthn, Push-to-Approve or Token - what is future-proof and will prevail? Will passwordless authentication soon be the new standard? We explain. - [SC Magazine: How orchestration can accelerate the end of passwords](https://fidoalliance.org/sc-magazine-how-orchestration-can-accelerate-the-end-of-passwords/): The information industry is making a major push to improve identity and access management protocols so that users can obtain the answers they need swiftly and securely. More than 200 companies have joined the Fast Identity Online Alliance, or FIDO, to consolidate resources and support for passwordless authentication. As part of this movement, identity orchestration has emerged as a viable path for companies to put their passwordless plans into action. - [IT Pro: Signal confirms 1,900 of its users were hit by Twilio breach](https://fidoalliance.org/it-pro-signal-confirms-1900-of-its-users-were-hit-by-twilio-breach/): In the last few days, the encrypted messaging platform, ‘Signal’ confirmed a variety of their customers fell victim to the phishing attack on Twilio. It is estimated that 1,900 were affected by the breach via phone number and SMS verification links to “reset passwords” on a phony Twilio link. By posing as Twilio’s IT dept, the hackers were able to obtain victim’s login credentials. Unfortunately, it is still unclear who was behind this attack. Cloudflare also revealed they were subjected to a phishing attack around the very same time as Twilio, but was not breached as an end result owing to the corporation-vast use of hardware-centered, FIDO2-compliant multi-factor authentication (MFA) keys. - [it-daily: The future of password security is passwordless](https://fidoalliance.org/it-daily-the-future-of-password-security-is-passwordless/): To create even more secure, easier and faster login solutions for everyone, 1Password has spent nearly two decades making logins more convenient and recently joined the FIDO Alliance to create a better future for authentication. Because as technology advances, new authentication methods continue to emerge - even without a password. - [TechTarget: Passkey vs. password: What is the difference?](https://fidoalliance.org/techtarget-passkey-vs-password-what-is-the-difference/): Passwords may be a thing of the past as tech giants are moving to new passkey technology -- a passwordless login that is more secure and convenient. Passkeys were created with the Web Authentication API security standard that uses public key cryptography for access. Each key is unique and created with encrypted data for added security. Apple, Google and Microsoft are working with the FIDO Alliance and the World Wide Web Consortium (W3C) to ensure passkeys are implemented in ways that work across multiple platforms. - [SC Magazine: How passkeys pave the way for passwordless authentication](https://fidoalliance.org/sc-magazine-how-passkeys-pave-the-way-for-passwordless-authentication-2/): Fast Identity Online (FIDO) outlines secure authentication protocols that are available to all. Their goal is to normalize passwordless authentication and eliminate passwords from the user authentication equation. It may be a while before passwords disappear entirely, but more companies are beginning to see passwordless authentication as the secure, sustainable alternative. And passkey technology is helping pave the way. - [DataBreach Today: Hardware MFA Stops Attack on Cloudflare](https://fidoalliance.org/databreach-today-hardware-mfa-stops-attack-on-cloudflare/): Internet infrastructure company Cloudflare says the same attackers that went after Twilio also sent Cloudflare employees malicious SMS messages with links to phishing sites dressed up as an official company website. Despite employees at both companies taking the bait, Cloudflare said attackers were unable to snatch the full logon credentials of its workers because the company's second layer of authentication isn't time-limited one-time codes. Instead, every employee at the company is issued a FIDO2-compliant security key from a vendor like YubiKey. Although the attackers siphoned the credentials, the hard key authentication requirement stopped them from snatching a soft token that fooled employees otherwise would have entered into the phishing site. - [MarketWatch: Are passwords a thing of the past? ](https://fidoalliance.org/marketwatch-are-passwords-a-thing-of-the-past/): MarketWatch’s Best New Ideas in Money podcast explores innovations in economics, policy, and finance technology. This episode features insights from Andrew Shikiar, executive director & CMO of the FIDO Alliance, as he discusses the broad industry push to passwordless authentication and the technology working to kill the password.  - [American Banker: What banks can learn from phishing attacks on Cloudflare, Twilio](https://fidoalliance.org/american-banker-what-banks-can-learn-from-phishing-attacks-on-cloudflare-twilio/): Threat actors targeted two major tech firms with nearly identical phishing schemes last week. In one case, attackers gained access to data for approximately 125 customers. In the other, they tricked three employees but did not gain any system access to their systems. FIDO2-compliant security keys are cited as a “linchpin mechanism” in Cloudflare’s defense. - [Microsoft News: Passwordless is here and at scale](https://fidoalliance.org/microsoft-news-passwordless-is-here-and-at-scale/): Microsoft’s blog post explores Accenture’s journey as they adopted passwordless authentication. - [Associations Now: Tech Talk: 30 Technology Terms Everyone Should Know](https://fidoalliance.org/associations-now-tech-talk-30-technology-terms-everyone-should-know/): Passkey - - [Security Boulevard: What is a Zero Trust Environment? | HYPR](https://fidoalliance.org/security-boulevard-what-is-a-zero-trust-environment-hypr/): An effective Zero Trust environment requires an authentication system that can be relied upon to form a strong, solid foundation. With passwords and other shared credentials, the weakest links in any authentication system, Zero Trust MFA must fully eliminate these from the authentication process. The government has recognized this, with the Cybersecurity and Infrastructure Security Agency calling Fast Identity Online (FIDO) protocols the “gold standard” of MFA. - [Tech Target: Why 2023 is the year of passwordless authentication](https://fidoalliance.org/tech-target-why-2023-is-the-year-of-passwordless-authentication-2/): Passwords are a form of knowledge-based authentication. For a user to prove they are who they claim to be, they need a secret -- the password -- that has been previously stored by the service. Multifactor authentication (MFA) is a technique designed to strengthen the authentication process by adding possession-based authentication to knowledge-based authentication. A service can only authenticate a user when they prove they have knowledge of the shared secret in addition to something they have or are. Eliminating shared secrets removes the intrinsic weakness of password-based authentication and MFA. A secure form of possession-based authentication is the best alternative. Passwordless authentication based on FIDO standards is considered the archetype. FIDO passwordless authentication is based on public-key cryptography. - [Forbes: Why MFA Falls Short And What Can Be Done About It](https://fidoalliance.org/forbes-why-mfa-falls-short-and-what-can-be-done-about-it/): Stu Sjouwerman, founder, and CEO of KnowBe4 Inc shares his thoughts on how MFAs fell short in data security. A Verizon research report says that 82% of all cyberattacks fall on human error (stolen credentials, phishing, misuse). For a hacker to successfully gain access to credentials they need some level of human involvement to get around MFA defences. Some common phishing techniques include, MiTM attacks, SIM-swapping attacks, “Pass-the-cookie” attacks, and MFA fatigue. The strongest forms of MFAs are based on FIDO2 standards that enables users to access resources through biometrics. The deployment of FIDO2 eliminates the risk of phishing attacks but ensuring users are well trained to identify cyberthreats is just as important if not more. - [ars Technica: Phishers who breached Twilio and targeted Cloudflare could easily get you, too](https://fidoalliance.org/ars-technica-phishers-who-breached-twilio-and-targeted-cloudflare-could-easily-get-you-too/): At least two security-sensitive companies—Twilio and Cloudflare—were targeted in a phishing attack by an advanced threat actor who had possession of home phone numbers of not just employees but employees' family members as well. - [TechRadar.pro: Cloudflare says it was almost fooled by a phishing attack](https://fidoalliance.org/techradar-pro-cloudflare-says-it-was-almost-fooled-by-a-phishing-attack/): Cloudflare employees were recently targeted by a “sophisticated” cyberattack, and even though some fell for the scheme, the DDoS protection company managed to successfully defend itself.  - [Cloudflare: The mechanics of a sophisticated phishing scam and how we stopped it](https://fidoalliance.org/cloudflare-the-mechanics-of-a-sophisticated-phishing-scam-and-how-we-stopped-it/): Yesterday, August 8, 2022, Twilio shared that they’d been compromised by a targeted phishing attack. Around the same time as Twilio was attacked, we saw an attack with very similar characteristics also targeting Cloudflare’s employees. While individual employees did fall for the phishing messages, we were able to thwart the attack through our own use of Cloudflare One products, and physical security keys issued to every employee that are required to access all our applications. - [CFPB: Insufficient data protection or security for sensitive consumer information](https://fidoalliance.org/cfpb-insufficient-data-protection-or-security-for-sensitive-consumer-information/): Can entities violate the prohibition on unfair acts or practices in the Consumer Financial Protection Act (CFPA) when they have insufficient data protection or information security? - [Tech Target: Why 2023 is the year of passwordless authentication](https://fidoalliance.org/tech-target-why-2023-is-the-year-of-passwordless-authentication/): Passwords are a form of knowledge-based authentication. For a user to prove they are who they claim to be, they need a secret -- the password -- that has been previously stored by the service. Multifactor authentication (MFA) is a technique designed to strengthen the authentication process by adding possession-based authentication to knowledge-based authentication. A service can only authenticate a user when they prove they have knowledge of the shared secret in addition to something they have or are. Eliminating shared secrets removes the intrinsic weakness of password-based authentication and MFA. A secure form of possession-based authentication is the best alternative. Passwordless authentication based on FIDO standards is considered the archetype. FIDO passwordless authentication is based on public-key cryptography. - [IT PRO: Cisco Talos confirms data breach after ransomware gang ‘forces’ incident disclosure](https://fidoalliance.org/it-pro-cisco-talos-confirms-data-breach-after-ransomware-gang-forces-incident-disclosure/): The effectiveness of hardware-based MFA keys was brought to light as both Twilio and Cloudflare were targeted with sophisticated phishing attacks, but only the latter prevented a full attack thanks to the company-wide use of FIDO keys in addition to MFA security prompts. - [Mittelstand heute: Passwordless – No password is more secure!](https://fidoalliance.org/mittelstand-heute-passwordless-no-password-is-more-secure/): Fast Identity Online (FIDO) is another method for Passwordless Authentication. FIDO2 stands for the second version of the open standard. Here, the password is replaced by a hardware token. The authentication mechanisms of the FIDO standard are stored on this token. - [Sicherheit.info: Apple abolishes the password – what companies must do now](https://fidoalliance.org/sicherheit-info-apple-abolishes-the-password-what-companies-must-do-now/): Apple is putting a groundbreaking security upgrade into practice, for the introduction of which it joined forces with other Internet giants such as Meta (formerly Facebook) and Google, as well as hardware manufacturers from Intel to Qualcomm, to form the “Fido Alliance” back in 2012. - [Momentum in APAC:  FIDO Tech Seminar in Korea and Passwordless Roundtable in Vietnam Recaps](https://fidoalliance.org/momentum-in-apac-fido-tech-seminar-in-korea-and-passwordless-roundtable-in-vietnam-recaps/): By Andrew Shikiar, Executive Director and CMO, FIDO Alliance - [SC Magazine: How passkeys pave the way for passwordless authentication](https://fidoalliance.org/sc-magazine-how-passkeys-pave-the-way-for-passwordless-authentication/): Fast Identity Online (FIDO) outlines secure authentication protocols that are available to all. Now, Microsoft, Google and Apple are doubling down on passkeys to support FIDO Alliance. Their goal is to normalize passwordless authentication and eliminate passwords from the user authentication equation. FIDO Alliance seeks to bring the idea of the "password" into modern times with stronger security -- by developing the FIDO protocols and setting a new standard. - [Mac4ever: Apple starts promoting Passkeys](https://fidoalliance.org/mac4ever-apple-starts-promoting-passkeys/): At WWDC 2022, Apple briefly mentioned the Passkeys feature, which will allow passwords to be replaced using the machines' biometric sensors. To do this, Apple will rely on the standard set up by the FIDO (Fast Identity Online) alliance in partnership with Google and Microsoft. - [Frandroid: Apple is preparing the future of the password and it will work even on Windows](https://fidoalliance.org/frandroid-apple-is-preparing-the-future-of-the-password-and-it-will-work-even-on-windows/): At WWDC 2022, Apple introduced us to the Passkeys feature, which will eliminate the need for traditional passwords. This addition, which we already had a glimpse of last year, is now revealed a little more. - [PYMNTS: Data Point: 68% of Consumers Want to Keep Passwords Off Their Apps](https://fidoalliance.org/pymnts-data-point-68-of-consumers-want-to-keep-passwords-off-their-apps/): Time to leave the passwords behind. Consumers are leaning that way — and would be happy to abandon that age-old, friction-filled relic that traces its genesis to the dawn of the Internet. The door is opening for authentication to increasingly be done by behavioral analytics. Advanced technologies parse how individuals wield their devices, how they type and enter data and leverage geolocation to help prove that people are who they say they are. The Fast Identity Online (FIDO) Alliance also promotes the processes where the devices themselves authenticate identities as the devices are unlocked. - [Tech Radar: Apple outlines its plans to get rid of passwords for good](https://fidoalliance.org/tech-radar-apple-outlines-its-plans-to-get-rid-of-passwords-for-good/): Apple has revealed more details on its plans to try and remove passwords with its new ‘passkey’ tool in an effort to increase online security, in collaboration with the FIDO Alliance. Passkeys are based on public key cryptography, which involves storing a private security key on your device. Because there’s no password to type, phishing and other scams will become far less frequent. - [MacWorld: 5 Mac OS Ventura Features You’ll Actually Use](https://fidoalliance.org/macworld-5-mac-os-ventura-features-youll-actually-use/): Apple are on the brink of a breakthrough with the new password feature in Mac OS Ventura's Safari. Keys replaces typed passwords with Touch ID on a Mac. On the iPhone or iPad, you can use Face ID. No more searching for the unique password you create for each internet account. Apple works with the FIDO Alliance so passwords also work on non-Apple devices. - [CISA Director Jen Easterly to Deliver Signature Keynote at FIDO Alliance’s Authenticate 2022 Conference ](https://fidoalliance.org/cisa-director-jen-easterly-to-deliver-signature-keynote-at-fido-alliances-authenticate-2022-conference/): FIDO Alliance announces agenda for its flagship event on the future of user authentication    - [Silicon: GoTrust Idem Key is the first FIDO Security Key able to access MojeID’s Czech government and high assurance EU eIDAS services ](https://fidoalliance.org/silicon-gotrust-idem-key-is-the-first-fido-security-key-able-to-access-mojeids-czech-government-and-high-assurance-eu-eidas-services/): Today, GoTrustID Inc. (GoTrust) announced that their Idem Keys with FIDO2 Security Level 2 certification are being used in the Czech Republic by CZ.NIC’s MojeID service to provide the highest level of eIDAS assurance for digital transactions throughout the entire EU. MojeID became the first eIDAS approved eID service that leverages the FIDO standards and certification program. This is a remarkable milestone that benefits Czech citizens by letting them utilize phishing resistant technology. - [The Stack: With FIDO2, is a passwordless future on the horizon?](https://fidoalliance.org/the-stack-with-fido2-is-a-passwordless-future-on-the-horizon/): Most breaches involve a stolen password or credential, but ironically enough, passwords are still a popular way to protect your online identity. A study conducted by Google revealed that 52% of people reuse the same password for multiple accounts, making it easy for hackers to guess your passwords. Thankfully, there has been a major shift towards a passwordless future with the development of FIDO2 by the FIDO Alliance and the World Wide Web Consortium (W3C).  - [borse.de: GoTrust Idem Key is the first FIDO security key that enables access to MojeID’s Czech government and high-security EU eIDAS services](https://fidoalliance.org/borse-de-gotrust-idem-key-is-the-first-fido-security-key-that-enables-access-to-mojeids-czech-government-and-high-security-eu-eidas-services/): GoTrustID Inc (GoTrust) today announced that Idem Keys with FIDO2 Security Level 2 certification will be used in the Czech Republic by CZ.NIC’s MojeID service to provide the highest level of eIDAS security for digital transactions across the EU. - [GIGA: Google Chrome: This important feature is years overdue](https://fidoalliance.org/giga-google-chrome-this-important-feature-is-years-overdue/): Google, Apple and Microsoft want to say goodbye to the principle of passwords altogether. Instead, a method jointly developed by the FIDO Alliance and the World Wide Web Consortium (W3C) is to be used. The FIDO method generates a key pair on devices that is linked to a fingerprint or other biometric factors. Logging on to a cell phone is then sufficient to access accounts on a computer. - [Netzpalaver: Phishing-resistant authentication methods](https://fidoalliance.org/netzpalaver-phishing-resistant-authentication-methods/): Many of the implemented authentication methods are not phishing-resistant, as the current case shows. One solution here is a FIDO-based authentication solution, which can best be implemented with a hardware-based security key that enables secure MFA by means of hardware tokens and whose MITM protection mechanisms from FIDO also take effect in the event of AiTM attacks. - [SC Magazine: Finding FIDO: What Fast Identity Online is, and how it works ](https://fidoalliance.org/sc-magazine-finding-fido-what-fast-identity-online-is-and-how-it-works/): The Fast Identity Online (FIDO) Alliance has a single purpose — to move the digital world beyond reliance on passwords. Ten years after its 2012 founding, the alliance has partly succeeded, although its next steps may require a radical change in the way we authenticate ourselves online. This article discusses what the FIDO Alliance has done so far, and where it's taking us next. - [Wall Street Journal: How to pass on your passwords when you die](https://fidoalliance.org/wall-street-journal-how-to-pass-on-your-passwords-when-you-die/): Apple, Google and Meta Platforms are among the tech companies that provide digital-legacy tools to let users bequeath account access to others, but millions of people are poised to change how they log into accounts as FIDO passwordless technology is rolled out. But those passkeys aren’t set up yet for sharing with heirs or next of kin. In the future, they could allow users to designate emergency contacts who can access your accounts through their own unique passkeys after verifying their identity. Alternatively, apps and websites may let you keep a traditional password as a backup.  - [Deutschlandfunk: The end of passwords](https://fidoalliance.org/deutschlandfunk-the-end-of-passwords/): The alternative to passwords is to be launched as early as the end of the year. That is the goal of the FIDO Alliance, whose members include companies such as Microsoft, Google and Apple, as well as authorities such as the German Federal Office for Information Security. The aim is to make log-ins as easy as unlocking a smartphone. - [TechRadar: You’ve heard passwordless sign-ins are coming. But what is FIDO? And why does it matter?](https://fidoalliance.org/techradar-youve-heard-passwordless-sign-ins-are-coming-but-what-is-fido-and-why-does-it-matter/): Senior Director of Marketing at FIDO Alliance, Megan Shamas, shares insights into the background behind the recent Apple, Google and Microsoft passwordless announcement, including the standards that support it, why FIDO exists, and the other industry stakeholders helping make passwordless a reality. - [Les Echos: Can we really do without passwords?](https://fidoalliance.org/les-echos-can-we-really-do-without-passwords/): Google, Apple and Microsoft have announced their support for FIDO, an initiative to completely replace passwords with biometric identification. The success of this initiative will depend above all on the service providers and websites. - [Silicon: Axiad Bolsters Executive Team to Help Accelerate Growth for Its Integrated Authentication Platform](https://fidoalliance.org/silicon-axiad-bolsters-executive-team-to-help-accelerate-growth-for-its-integrated-authentication-platform/): Axiad, a leading provider of enterprise-wide passwordless orchestration, today announced the addition of two new executives to accelerate the company’s growth. Joe Garber and Eric Tocatlian, both veterans of the identity security industry with over 20 years experience each, will lead sales and marketing as Chief Marketing Officer and Chief Revenue Officer, respectively.  Axiad supports the widest range of credentials including FIDO, mobile MFA, Windows Hello for Business, YubiKeys, smart cards, TPM and biometrics, and is trusted by public sector organizations and Fortune 500 companies across aerospace & defense, financial services, insurance, healthcare, oil & energy and more. - [it-daily: Passwordless safer on the road: Credential Stuffing](https://fidoalliance.org/it-daily-passwordless-safer-on-the-road-credential-stuffing/): The consistent use of FIDO standards makes it possible to completely eliminate the password on all channels of customer communication (mobile and desktop) while also improving the customer experience. - [Deutschlandfunk Kultur: FIDO Alliance: The end of passwords](https://fidoalliance.org/deutschlandfunk-kultur-fido-alliance-the-end-of-passwords/): The alternative to passwords is to be launched as early as the end of the year. That is the goal of the FIDO Alliance, whose members include companies such as Microsoft, Google and Apple, as well as authorities such as the German Federal Office for Information Security. - [Yahoo! JAPAN’s password-free authentication reduced inquiries by 25%, sped up sign-in time by 2.6x](https://fidoalliance.org/yahoo-japans-password-free-authentication-reduced-inquiries-by-25-sped-up-sign-in-time-by-2-6x/): As Yahoo! JAPAN offers e-commerce and other money-related services, there's a risk of significant damage to users in the event of unauthorized access or account loss. - [FIDO Alliance Announces the FIDO Developer Challenge – India](https://fidoalliance.org/fido-alliance-announces-the-fido-developer-challenge-india/): India-focused Developer Challenge Program Invites Local Teams to Leverage Public FIDO2 WebAuthn API to Showcase Creative Ideas Leveraging FIDO Authentication – Application Submission Deadline August 12, 2022 - [The Wall Street Journal: Apple Wants to End Passwords for Everything. Here’s How It Would Work](https://fidoalliance.org/the-wall-street-journal-apple-wants-to-end-passwords-for-everything-heres-how-it-would-work/): Passwords have been the longtime standard for securing online accounts, but they pose security risks. Despite expert advice to create complex, unique passwords for every account, people often use the same password, get tricked into signing into fake websites that log their information, or have their account details leaked in data breaches. Apple’s passkeys want to address those problems and replace passwords entirely. Its passkeys fall under a standard set by the Fast Identity Online Alliance, an industry association that includes over 250 other companies such as Microsoft Corp. and Alphabet Inc.’s Google. Called FIDO for short, the group has worked for nearly a decade to create a unified format for online authentication. - [S&P Global: Big Tech pushes forward with password-less authentication ](https://fidoalliance.org/sp-global-big-tech-pushes-forward-with-password-less-authentication/): A tech industry coalition including Apple Inc., Alphabet Inc. and Microsoft Corp. is working to expand adoption of a secure alternative to the common password. Under agreements struck this year, a new standard known as FIDO, short for Fast IDentity Online, will be built into major operating systems such as macOS, iOs, Windows 11, Chrome OS and Android in the coming months. Users will have the choice to opt in to the new protocols, which will allow them to log in securely without a password. - [CNET: Learn About Passkeys, the No-Password Login Tech Coming to iOS 16 and Android](https://fidoalliance.org/cnet-learn-about-passkeys-the-no-password-login-tech-coming-to-ios-16-and-android/): Apple recently showed off a new replacement for passwords coming in Safari and iOS. Apple revealed its version of passkeys at WWDC 2022 as a new authentication feature but Google and Microsoft helped develop the technology through the FIDO Alliance, a standards group that's worked for years to get companies to move beyond passwords, which announced passkeys in May. - [Geeky.news: Passwordless authentication: soon to be a reality?](https://fidoalliance.org/geeky-news-passwordless-authentication-soon-to-be-a-reality/): A future without a password is slowly taking shape. This perspective, while attractive, requires presenting options and, above all, challenges that companies may face. - [Biometric Update: Contactless fingerprint biometrics take another step towards mainstream adoption](https://fidoalliance.org/biometric-update-contactless-fingerprint-biometrics-take-another-step-towards-mainstream-adoption/): Contactless fingerprint biometrics have advanced to the point that they are ready for law enforcement applications, as shown by the latest NIST mFIT Challenge results, IB and Sciometrics executives tell Biometric Update. Their joint entry scored the best accuracy result, while Idemia and Telos took top overall marks in Phase 2 for a smartphone-based mobile application to match fingerprints against a database populated with templates derived from contact-based scans. - [tech.co: Apple Announces Decision to Ditch Passwords](https://fidoalliance.org/tech-co-apple-announces-decision-to-ditch-passwords/): Apple's new "Passkey" feature plans to replace passwords for good - and Google and Microsoft are right behind. - [WSJ: Apple Wants to End Passwords for Everything. Here’s How It Would Work](https://fidoalliance.org/wsj-apple-wants-to-end-passwords-for-everything-heres-how-it-would-work/): Goodbye, complex, hard-to-remember passwords. Hello, logging in with your face and fingerprints. Apple announced dozens of new features for the next versions of iOS, iPadOS, WatchOS and MacOS in its two-hour WWDC 2022 keynote—plus a redesigned MacBook Air! - [CHIP: The end of passwords: which technology is the future](https://fidoalliance.org/chip-the-end-of-passwords-which-technology-is-the-future/): What could lead to a truly password-free future are the current efforts of tech giants Apple, Google and Microsoft. They want to support logins via FIDO2 standard. Apple introduces support with Passkeys in iOS 16, for example. - [Win Future: Apple Passkey: Why everyone on the Internet will benefit from it](https://fidoalliance.org/win-future-apple-passkey-why-everyone-on-the-internet-will-benefit-from-it/): “Passkeys” are not an Apple-exclusive invention, even if it sounded like one at WWDC 2022. They are Apple’s internal branding for a new type of log-in credential developed by the FIDO Alliance. - [TapSmart: How and why Passkeys in IOS 16 will begin making passwords extinct](https://fidoalliance.org/tapsmart-how-and-why-passkeys-in-ios-16-will-begin-making-passwords-extinct/): At WWDC 2022, Apple formally introduced Passkeys, having earlier this year committed to expanding support for passwordless sign-in. Passkeys are an ambitious idea – nothing short of an attempt to eliminate passwords from tech. This isn’t an Apple-only objective either – the company is working alongside industry giants Google and Microsoft, supporting the FIDO Alliance standard. - [CNET: With iOS 16, Apple Can Add a New Polish to the iPhone](https://fidoalliance.org/cnet-with-ios-16-apple-can-add-a-new-polish-to-the-iphone/): The most important part of Apple's upcoming announcements on Monday may already be in your pocket. - [AWS: AWS IAM now supports WebAuthn and Safari browser for multi-factor authentication with security keys](https://fidoalliance.org/aws-aws-iam-now-supports-webauthn-and-safari-browser-for-multi-factor-authentication-with-security-keys/): AWS Identity and Access Management (IAM) now supports the Web Authentication (WebAuthn) standard for strong and phishing-resistant authentication across all supported browsers. WebAuthn is part of the FIDO2 set of specifications that succeed FIDO U2F API, enabling secure multi-factor authentication with security keys based on public key cryptography. - [Dark Reading: Biometric Data Offers Added Security — But Don’t Lose Sight of These Important Risks](https://fidoalliance.org/dark-reading-biometric-data-offers-added-security-but-dont-lose-sight-of-these-important-risks/): With rising fraud, businesses are seeking authentication methods that are security- and user-friendly. But with that comes a few complications. - [CIO: Stop Thinking Small: 100% of Your Customers Can Go Passwordless](https://fidoalliance.org/cio-stop-thinking-small-100-of-your-customers-can-go-passwordless/): Passwords have reached end of life. Is your organization prepared for passwordless authentication? Here’s how to reach a 100% customer adoption rate. - [01net: Understanding Multi-device FIDO, the standard designed to finally eliminate passwords](https://fidoalliance.org/01net-understanding-multi-device-fido-the-standard-designed-to-finally-eliminate-passwords/): The FIDO alliance launches a new authentication architecture that is much more suitable for users. However, adoption will not be an easy task. - [Cambridge Housing Authority’s Road to FIDO](https://fidoalliance.org/cambridge-housing-authoritys-road-to-fido/): The Challenge: - [Security Weekly: Where to Start Your Passwordless Journey? – Jackie Comp, Rolf Lindermann – ESW #274](https://fidoalliance.org/security-weekly-where-to-start-your-passwordless-journey-jackie-comp-rolf-lindermann-esw-274/): Migrating off passwords and legacy authentication is a journey. Jackie Comp and Rolf Lindermann of Nok Nok discuss the company’s journey to incorporate passwordless, next-generation authentication into their consumer apps, leveraging FIDO standards, resulting in improvements in onboarding, authentication success, speed and reduction in fraud. - [MarkTechPost: Now You Don’t Need To Present Your Credit Card At Checkout If You Bind Your Facial Images/ Hand Features To Your MasterCard Credit Card](https://fidoalliance.org/marktechpost-now-you-dont-need-to-present-your-credit-card-at-checkout-if-you-bind-your-facial-images-hand-features-to-your-mastercard-credit-card/): Mastercard has been a leader in using biometrics in stores and online for a long time as a safe way to verify identity. Instead of a password, the person is used instead. Biometrics have also been used to verify the identities of online shoppers through “selfie pay” and online, using standards like FIDO (Fast Identity Online). - [CIO.com: Seven Signs That Your Consumers are Ready for Passwordless Authentication](https://fidoalliance.org/cio-com-seven-signs-that-your-consumers-are-ready-for-passwordless-authentication/): Customer demand for passwordless authentication has grown exponentially since smartphones first began offering built-in biometric readers. In fact, Mastercard sponsored an Oxford University study of consumer sentiment that discovered just that. A staggering 93% of consumers preferred biometric authentication to passwords — and yet so many companies still force their customers to use risky, outdated login credentials. Meanwhile, the endorsement and development of passwordless authentication by tech mainstays like Microsoft and Apple are pushing companies to ditch passwords for good. With the support of the FIDO Alliance, an industry association dedicated to making a passwordless future possible, and services like Transmit Security’s BindID, it’s now easy for companies to go totally passwordless in a week or less. - [CIO Review: Microsoft Attempting To Remove The Passwords Login Concept](https://fidoalliance.org/cio-review-microsoft-attempting-to-remove-the-passwords-login-concept/): Passwords are one of the biggest concerns at present, occupying an average person’s time and effort in remembering them for various systems. It is almost a wearisome affair to remember passwords in bulk and many a time, people use the same passwords on different sites making it less secure. To solve this concern, FIDO (Fast Identity Online) was introduced, to reduce the world’s over-reliance on passwords. - [heise: Mastercard to introduce payment with face or hand scan](https://fidoalliance.org/heise-mastercard-to-introduce-payment-with-face-or-hand-scan/): Payment service provider Mastercard wants to usher in a “new era” of payment with pure biometric authentication - with a “wave” or “smile.” - [Google Watch Blog: Google wants to abolish passwords and replace them with passkeys – this is how the new FIDO system works](https://fidoalliance.org/google-watch-blog-google-wants-to-abolish-passwords-and-replace-them-with-passkeys-this-is-how-the-new-fido-system-works/): Google declared war on passwords many years ago and has been working on various solutions to get a handle on the password issue for users. With the recent announcement of Passkeys, which are supported by a very broad industry association, this could be implemented in no time. - [Electropages: Major tech companies looking to move away from passwords](https://fidoalliance.org/electropages-major-tech-companies-looking-to-move-away-from-passwords/): A recent announcement from major tech companies, including Apple, Google, and Microsoft, outlines plans to move away from password authentication in favour of FIDO.  - [The Verge: Apple, Google, and Microsoft will soon implement passwordless sign-in on all major platforms](https://fidoalliance.org/the-verge-apple-google-and-microsoft-will-soon-implement-passwordless-sign-in-on-all-major-platforms/) - [CNET: Apple, Google, Microsoft Back ‘FIDO’ Tech to Dump Passwords on Websites and Apps](https://fidoalliance.org/cnet-apple-google-microsoft-back-fido-tech-to-dump-passwords-on-websites-and-apps/) - [ZDNet: Google, Apple, Microsoft make a new commitment for a “passwordless future”](https://fidoalliance.org/zdnet-google-apple-microsoft-make-a-new-commitment-for-a-passwordless-future/) - [The Telegraph: Apple, Google and Microsoft expand use of thumb and face ID to replace passwords](https://fidoalliance.org/the-telegraph-apple-google-and-microsoft-expand-use-of-thumb-and-face-id-to-replace-passwords/) - [Computer Weekly: Why developers need to engineer-in FIDO two factor authentication now](https://fidoalliance.org/computer-weekly-why-developers-need-to-engineer-in-fido-two-factor-authentication-now/) - [World Password Day Had a Good Run. Now We’re Celebrating A Future with Less Passwords](https://fidoalliance.org/world-password-day-had-a-good-run-now-were-celebrating-a-future-with-less-passwords/): Andrew Shikiar, executive director and CMO, FIDO Alliance - [Apple, Google and Microsoft Commit to Expanded Support for FIDO Standard to Accelerate Availability of Passwordless Sign-Ins](https://fidoalliance.org/apple-google-and-microsoft-commit-to-expanded-support-for-fido-standard-to-accelerate-availability-of-passwordless-sign-ins/): Faster, easier and more secure sign-ins will be available to consumers across leading devices and platforms  - [CSO Magazine: 10 top anti-phishing tools and services ](https://fidoalliance.org/cso-magazine-10-top-anti-phishing-tools-and-services/): The biggest risk stemming from phishing attacks for most enterprises is system compromise ultimately resulting in financial or data loss (or even ransomware). As such the primary defense mechanism must be a strong form of multi-factor authentication (MFA) and authentication standards such as Fast Identity Online v2 (FIDO2) or Web Authentication (WebAuthn).  - [CIO.com: Passwordless MFA: The Single Way To Mitigate the Top 5 Threats to Your Customer Identities ](https://fidoalliance.org/cio-com-passwordless-mfa-the-single-way-to-mitigate-the-top-5-threats-to-your-customer-identities/): Consumers are increasingly targeted by cybercriminals that use various techniques in account takeover (ATO) attacks. These attacks threaten the security of their online accounts and personal data. The article details what consumers can do to prevent attacks including; W3C’s Web Authentication standard, otherwise known as WebAuthn. WebAuthn is part of a standard set of protocols called Fast Identity Online, or FIDO. Most modern mobile phones support FIDO today, along with an increasing number of tablets, laptops, and desktops. FIDO is mainstream, allowing for broad adoption in consumer-oriented use cases (i.e., Consumer Identity & Access Management, or CIAM). - [Nextgov: CISA’s Newest Advisor Could Soon Have Agencies Asking: ‘Does This Spark Joy?’](https://fidoalliance.org/nextgov-cisas-newest-advisor-could-soon-have-agencies-asking-does-this-spark-joy/): Another CISA advisor has referred to Bob Lord as a “digital Marie Kondo,” tidying up the Democratic National Committee by throwing out old software and unused tech. - [The Wall Street Journal: Technology Alliance Says it is Closer to Killing Off Passwords ](https://fidoalliance.org/the-wall-street-journal-technology-alliance-says-it-is-closer-to-killing-off-passwords/): The FIDO Alliance, whose members include Apple, Google and Microsoft, says it is readying a system that could let users ditch their online passwords. - [WIRED: A Big Bet to Kill the Password for Good](https://fidoalliance.org/wired-a-big-bet-to-kill-the-password-for-good-2/): After a decade of work, the FIDO Alliance says it’s found the missing piece in the bridge to a password-free future. - [Protocol: Protocol Enterprise Newsletter](https://fidoalliance.org/protocol-protocol-enterprise-newsletter/): The FIDO Alliance published an outline of technology that could help finally bring on the “passwordless” future we’ve all been promised, and it relies on cryptographic keys stored on a device behind a biometric lock. - [CSO Online: FIDO Enters the Consumer Identity Space](https://fidoalliance.org/cso-online-fido-enters-the-consumer-identity-space/): As consumer identity and remote working creates a fuzzy identity landscape, FIDO has turned its sights on fixing authentication for consumers. FIDO has a vision: an internet that is secure but has easy access to resources. The door will be open, but the latch is always on.  - [Canard PC: FIDO, Feeding Security](https://fidoalliance.org/canard-pc-fido-feeding-security/): FIDO Alliance, an industry association working on authentication standards to eliminate the use of passwords, has published a white paper outlining its latest work in this area. - [Financial IT: FIDO Alliance Announces Commerce Virtual Summit Amid Rising Online Payment Fraud and Authentication Challenges](https://fidoalliance.org/financial-it-fido-alliance-announces-commerce-virtual-summit-amid-rising-online-payment-fraud-and-authentication-challenges-2/): The FIDO Alliance announced its first Authenticate Virtual Summit of 2022: The FIDO Fit in Commerce: Examining the Present and Future of Authentication in Banking, Retail, Crypto and Blockchain. The summit features Signature Sponsors Daon, Keyless and Nok Nok. - [Latest updates from FIDO APAC Marketing Forum: FIDO Members from the Region Get Together to Learn from Each Other and Stay Alert](https://fidoalliance.org/latest-updates-from-fido-apac-marketing-forum-%ef%bf%bcfido-members-from-the-region-get-together-to-learn-from-each-other-and-stay-alert/): By Joon Hyuk Lee, APAC Market Development Director - [heise: FIDO takes a new approach at being a password killer](https://fidoalliance.org/heise-fido-takes-a-new-approach-at-being-a-password-killer/): The FIDO Alliance wants nothing less than to make the password superfluous. In practice, this has not been possible. Now things are supposed to get better - also thanks to the cloud. - [Developpez.com: A big bet to eliminate the need for passwords in the world](https://fidoalliance.org/developpez-com-a-big-bet-to-eliminate-the-need-for-passwords-in-the-world/): After a decade of thinking about eliminating passwords around the world, FIDO Alliance, believes it has finally identified the missing piece of the puzzle. On Thursday, the organisation released a white paper outlining FIDO's vision for solving the usability issues that have hindered password-free features from being widely adopted. - [Industry Today: FIDO Authentication Market to Surge at a Robust Pace In Terms Of Revenue Over 2031](https://fidoalliance.org/industry-today-fido-authentication-market-to-surge-at-a-robust-pace-in-terms-of-revenue-over-2031/): Transparency Market Research delivers key insights on the global FIDO authentication market. In terms of revenue, the global FIDO authentication market is estimated to expand at a CAGR of 10.7% during the forecast period, owing to numerous factors, regarding which TMR offers thorough insights and forecasts in its report on the global FIDO authentication market. - [Wired: A Big Bet to Kill the Password for Good](https://fidoalliance.org/wired-a-big-bet-to-kill-the-password-for-good/): After a decade of work, the FIDO Alliance says it’s found the missing piece in the bridge to a password-free future. - [IT Daily: Password Alternatives: The Path to a Passwordless Future?](https://fidoalliance.org/it-daily-password-alternatives-the-path-to-a-passwordless-future/): Some alternatives that either add another factor to the classic password or replace it entirely are already in use today. With FIDO, the FIDO Alliance has set itself the goal of simplifying authentication on the Internet and enabling completely password-free log-ins. - [Financial IT: FIDO Alliance Announces Commerce Virtual Summit Amid Rising Online Payment Fraud and Authentication Challenges](https://fidoalliance.org/financial-it-fido-alliance-announces-commerce-virtual-summit-amid-rising-online-payment-fraud-and-authentication-challenges/): The FIDO Alliance announces its first Authenticate Virtual Summit of 2022. Attendees will hear from industry experts on the authentication challenges facing all commerce stakeholders today, and learn about FIDO’s invaluable role in the industry.  - [Mobile ID World: FIDO Announces Authenticate Virtual Summit for End of March](https://fidoalliance.org/mobile-id-world-fido-announces-authenticate-virtual-summit-for-end-of-march/): The FIDO Alliance is gearing up for its first Authenticate Virtual Summit of 2022. The event will focus on authentication challenges in the commercial space and will address some of the benefits and drawbacks of different forms of authentication and explain how businesses can use FIDO technologies to meet shifting regulatory requirements. - [IT Daily: Paradigm shift Zero Trust: Three theses for the future of IAM](https://fidoalliance.org/it-daily-paradigm-shift-zero-trust-three-theses-for-the-future-of-iam/): The protection of sensitive company networks and critical infrastructures is increasingly in focus, also in view of a tense security situation. In many cases, cyber security concepts currently in use are being put to the test. - [Help Net Security: Swissbit iShield FIDO2 protects access to applications and online services](https://fidoalliance.org/help-net-security-swissbit-ishield-fido2-protects-access-to-applications-and-online-services/): Swissbit is adding a new product category to its security solutions portfolio. With iShield FIDO2, the industrial storage and security products specialist presents its first authenticator for the FIDO2 open authentication standard. - [Fintech Times: trinamiX Face Authentication Checks Skin vs Other Material as Well as 3D Depth](https://fidoalliance.org/fintech-times-trinamix-face-authentication-checks-skin-vs-other-material-as-well-as-3d-depth/): trinamiX Face Authentication fulfils the biometric security requirements defined by the International Internet Finance Authentication Alliance (IIFAA). After lately announcing the fulfilment of the FIDO Alliance and Android Biometric Security standards, the German tech company is now topping it off with their newest certification. - [Global Security Mag: 30-31 March: FIDO Alliance announces virtual summit](https://fidoalliance.org/global-security-mag-30-31-march-fido-alliance-announces-virtual-summit/): FIDO Alliance is pleased to announce its first Authenticate 2022 Virtual Summit: The FIDO Fit in Commerce: Exploring the present and future of authentication in banking, retail, crypto and blockchain. - [ZDNet France: Why should cloud providers take MFA more seriously?](https://fidoalliance.org/zdnet-france-why-should-cloud-providers-take-mfa-more-seriously/): A byline by Andrew Shikiar, secured by Tyto, featured in ZDNet France. The article discusses the vulnerability of passwords as an online security method and the way that MFA can protect users of any online service. But, the piece maintains that MFA is not enough and much remains to be done, especially on the Cloud Solution Provider (CSP) side. - [Charting an Accelerated Path Forward for Passwordless Authentication Adoption](https://fidoalliance.org/charting-an-accelerated-path-forward-for-passwordless-authentication-adoption/): Andrew Shikiar, executive director and CMO, FIDO Alliance - [White Paper: Multi-Device FIDO Credentials](https://fidoalliance.org/white-paper-multi-device-fido-credentials/): The FIDO standards, together with their companion WebAuthn specification, are on the cusp of an important new development: evolutionary changes to the standards proposed by the FIDO Alliance and the W3C WebAuthn community aim to markedly improve the usability and deployability of FIDO-based authentication mechanisms. As a result, FIDO-based secure authentication technology will for the first time be able to replace passwords as the dominant form of authentication on the Internet.  - [White Paper: Choosing FIDO Authenticators for Enterprise Use Cases ](https://fidoalliance.org/white-paper-choosing-fido-authenticators-for-enterprise-use-cases-2/): Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, the FIDO Alliance has established a series of best practices and how-to white papers that align the Alliance's goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within the enterprise.  - [FIDO Alliance Announces Commerce Virtual Summit Amid Rising Online Payment Fraud and Authentication Challenges](https://fidoalliance.org/fido-alliance-announces-commerce-virtual-summit-amid-rising-online-payment-fraud-and-authentication-challenges/): Players from across banking, retail, crypto and blockchain can gain expert insight into addressing authentication challenges with FIDO – from regulation and UX, to fraud and privacy - [Security-Insider: FIDO2 to replace password login](https://fidoalliance.org/security-insider-fido2-to-replace-password-login/): With the FIDO2 security standard an alternative is already available that enables password-free, encrypted and anonymous login to web services. - [Global Security Mag: NEOWAVE launches the Winkeo-C FIDO2 security key for fixed and mobile terminals](https://fidoalliance.org/global-security-mag-neowave-launches-the-winkeo-c-fido2-security-key-for-fixed-and-mobile-terminals/): NEOWAVE announces the launch of the WinkeoC FIDO2 security key. This new product allows strong and multi-factor authentication to online services and applications from fixed and mobile terminals (PC, smartphone and tablet) thanks to its USB Type-C interface. It’s a 100% French design and it is compliant with the ANSSI* General Security Guidelines (RGS) and European security regulations (eIDAS, RGPD, DSP2), placing it among the most reliable security keys on the market. - [Global Security Mag: FIDO Alliance Approves Zero Trust Strategy Finalized by Office of Management](https://fidoalliance.org/global-security-mag-fido-alliance-approves-zero-trust-strategy-finalized-by-office-of-management/): This article communicates FIDO’s advocacy of the new Zero Trust Strategy finalized by the US government, namely its citation of FIDO Alliance standards as a ‘best practice’ security tool.  - [TEISS: FIDO Alliance announces Authenticate Conference 2022](https://fidoalliance.org/teiss-fido-alliance-announces-authenticate-conference-2022/): FIDO Alliance announces the return of its Authenticate conference and the opening of its call for speakers, with the event set to take place virtually and in-person in Seattle, Washington 17-19 Oct 2022. - [Lifewire: SIM Swapping Attacks Are Soaring and You Need to Be on Guard](https://fidoalliance.org/lifewire-sim-swapping-attacks-are-soaring-and-you-need-to-be-on-guard/): This article explores the significant surge in SIM-swapping incidents, driven by an increasingly lucrative cyber underworld. Andrew Shikiar, executive director of the FIDO Alliance, explains why using SMS for multi-factor authentication may be to blame and explores other authentication methods consumers should consider for greater security online. - [Redmond: The FIDO Impetus to Passwordless Authentications](https://fidoalliance.org/the-fido-impetus-to-passwordless-authentications/): The time is ripe for organizations to implement "phishing-resistant multifactor authentication" via FIDO standards, says advocate Andrew Shikiar. Passwords can be guessed or exposed through phishing attacks. The FIDO Alliance's authentication standards aim to solve the widespread data breach problems associated with password use. Its FIDO2 standard is now integrated in most operating systems, Web browsers and physical security keys, offering resistance to the phished credentials problem. - [FIDO Alliance Announces Authenticate Conference 2022](https://fidoalliance.org/fido-alliance-announces-authenticate-conference-2022/): Premier authentication conference returns for third year; call-for-speakers open - [eSecurity Planet: White House Boosts Zero Trust with New Cybersecurity Strategy](https://fidoalliance.org/esecurity-planet-white-house-boosts-zero-trust-with-new-cybersecurity-strategy/): The Biden Administration is pushing federal agencies to adopt a zero-trust security architecture to protect themselves and their data from “increasingly sophisticated and persistent threat campaigns,” according to a new strategy issued this week by the Office of Management and Budget (OMB). - [Le Journal du Net: How multi-factor authentication has taken hold in business](https://fidoalliance.org/le-journal-du-net-how-multi-factor-authentication-has-taken-hold-in-business/): FIDO is mentioned in an article on multi-factor authentication technologies. The journalist emphasizes the importance of evolving these methods to make them more user-friendly, and cites a few devices such as Yubico that rely on the FIDO2 specification. - [Industry Today: FIDO Authentication Market Revenue Growth Predicted by 2031](https://fidoalliance.org/industry-today-fido-authentication-market-revenue-growth-predicted-by-2031/): A recent market study published by Future Market Insights (FMI) on the FIDO authentication market includes a global industry analysis for 2016-2020 and opportunity assessment for 2021-2031, and delivers a comprehensive assessment of the most important market dynamics. - [Global Security Mag: FIDO Alliance endorses the Zero Trust strategy finalised by the Office of Management and Budget (OMB)](https://fidoalliance.org/global-security-mag-fido-alliance-endorses-the-zero-trust-strategy-finalised-by-the-office-of-management-and-budget-omb/): The article picks up the Zero Trust strategy announcement, endorsed by the Alliance, aiming to implement stronger cybersecurity practices in government agencies. - [Media Alert: The FIDO Alliance Endorses The Office of Management and Budget’s Finalized Zero Trust Strategy](https://fidoalliance.org/media-alert-the-fido-alliance-endorses-the-office-of-management-and-budgets-finalized-zero-trust-strategy/): FIDO Authentication highlighted for updated phishing-resistant authentication requirements  - [Recap: Identity, Authentication, and the Road Ahead #IDPolicyForum](https://fidoalliance.org/recap-identity-authentication-and-the-road-ahead-idpolicyforum/): The intersection of identity and authentication is set to be very busy in 2022. - [FinTech Magazine: Delegated Authentication – Abandon Friction, Not the Cart](https://fidoalliance.org/fintech-magazine-delegated-authentication-abandon-friction-not-the-cart/): This opinion piece explores how eCommerce retailers can overcome the age-old headache of cart abandonment with delegated authentication - a solution made possible by FIDO – offering a compelling alternative to legacy authentication options like SMS OTPs. - [Wall Street Journal: Tech that will Change Your Life in 2022](https://fidoalliance.org/wall-street-journal-tech-that-will-change-your-life-in-2022/): Analyzing industry trends and insights from industry experts, this piece offers predictions for tech in 2022, featuring a comment from Andrew Shikiar on the fate of passwords in the upcoming year. - [The Green Sheet: Digital Commerce in 2022 – Part I](https://fidoalliance.org/the-green-sheet-digital-commerce-in-2022-part-i/): This article analyzes the four pillars of digital commerce—security, intelligence, agility and transparency—and their predicted impact on consumers, industry trends and regulatory landscapes in the coming year, with insights from Andrew Shikiar on authentication in 2022. - [Daily Swig: Cybersecurity conferences 2022: A rundown of online, in person, and ‘hybrid’ events](https://fidoalliance.org/daily-swig-cybersecurity-conferences-2022-a-rundown-of-online-in-person-and-hybrid-events/): An inclusion of Authenticate in October 2022: “Hosted by the FIDO Alliance, the event is dedicated to the who, what, why and how of user authentication – with a focus on the FIDO standards-based approach.” - [The Register: Salesforce mandates MFA by default](https://fidoalliance.org/the-register-salesforce-mandates-mfa-by-default/): This is the good news about today’s MFA environment – there is no shortage of options to choose from. For most organisations, this will mean using the smartphone as the core authenticator, either running an app or using some form of biometrics or FIDO2 WebAuthn. For privileged users, this might be backed up with the gold standard of a FIDO U2F hardware token. - [Verdict: Essential retail cybersecurity predictions to retain customers in 2022](https://fidoalliance.org/verdict-essential-retail-cybersecurity-predictions-to-retain-customers-in-2022/): FIDO Alliance's Executive Director and Chief Marketing Office cybersecurity predictions: “In 2022, we predict online merchants and financial services players to start scrutinizing legacy ‘step-up’ authentication methods – such as SMS OTPs and push notifications – and look to new payment and authentication industry innovations that cause less friction. Delegated authentication is one leading example, enabling merchants and wallet providers to combine their own authentication or log-in processes with the EMV 3DS request to approve purchases. This makes the UX for customers super simple, only requiring them to authenticate once to both login and authorise a payment, while offering the highest level of security and meeting 2FA requirements." Read more. - [Economie Matin: Delegated authentication – abandon the friction, not the basket](https://fidoalliance.org/economie-matin-delegated-authentication-abandon-the-friction-not-the-basket/): Delegate authentication byline from Alain Martin, Member of the Board of Directors and Co-President at the FIDO Alliance Europe. - [Informatique News: Strong authentication, the cornerstone of the Zero Trust model](https://fidoalliance.org/informatique-news-strong-authentication-the-cornerstone-of-the-zero-trust-model/): In Europe, the Zero Trust model moved from concept to reality for many enterprises during 2020, and then accelerated in 2021. COVID-19 precipitated the demise of traditional security models in an effort to prevent data compromise and mitigate the risk of supply chain attacks. - [The Voice of Fintech Podcast: FIDO – leading the way to a passwordless future with Andrew Shikiar, FIDO’s Executive Director](https://fidoalliance.org/the-voice-of-fintech-podcast-fido-leading-the-way-to-a-passwordless-future-with-andrew-shikiar-fidos-executive-director/): Andrew Shikiar, Executive Director of FIDO Alliance, sits down with Rudi Falat, Host of The Voice of Fintech podcast, to discuss how FIDO is leading the way to the passwordless future. - [Infosecurity: Interview: Andrew Shikiar on the Potential for a Passwordless Future](https://fidoalliance.org/infosecurity-interview-andrew-shikiar-on-the-potential-for-a-passwordless-future/): Infosecurity spoke to FIDO’s executive director and CMO, Andrew Shikiar, about how efforts to reduce reliance on passwords is progressing. - [Verdict Magazine: Is the Future of authentication passwordless](https://fidoalliance.org/verdict-magazine-is-the-future-of-authentication-passwordless-2/): Andrew's interview with Verdict's editor about passwordless future. - [CPO Magazine: What US$10M in Losses Each Day Tells Us About Cryptocurrency Account](https://fidoalliance.org/cpo-magazine-what-us10m-in-losses-each-day-tells-us-about-cryptocurrency-account/): Interest in cryptocurrency has continued to grow this year despite the somewhat gloomy economy. For instance, Bitcoin prices hit an all-time high of more than US$63,000 earlier this year. From institutional investors to students looking to get their first taste of investing, cryptocurrency adoption has risen by close to 900 percent in the past year, with Asia leading the charge. Read FIDO's Andrew Shikiar's (Exec Dir / CMO) article discussing how crypto exchanges need to allow users to secure their accounts using modern authentication standards to protect them from phishing attacks and account takeovers. - [Security-Insider: Account security is the responsibility of the user](https://fidoalliance.org/security-insider-account-security-is-the-responsibility-of-the-user/): A report from Twitter on account security points to a major problem affecting all online service providers: too few users use secure authentication methods, even though they are frequently offered. - [Finextra AND The Fintech Times: Worldline joins FIDO Alliance](https://fidoalliance.org/finextra-and-the-fintech-times-worldline-joins-fido-alliance/): Payments and transactional services provider Worldline is expanding its e-commerce payment solution into South Korea whilst bolstering its authentication process through a partnership with FIDO Alliance. - [World Business Outlook: Cybersecurity is vital in the digital phase](https://fidoalliance.org/world-business-outlook-cybersecurity-is-vital-in-the-digital-phase/): As the digital phase of survival has both advantages and disadvantages the risks held within the usage of digital products, make us a scape goat in the eyes of cyber criminals. The need to analyse such malicious acts is important for the digital platform to gain its trust among the masses. Thus, setting up Cybersecurity has emerged imperative for the protection of data from the hands of unauthorised actors. - [Verdict Magazine: Is the Future of authentication passwordless](https://fidoalliance.org/verdict-magazine-is-the-future-of-authentication-passwordless/): Is the future of authentication passwordless? - [Developpez: Cybercriminals are becoming less likely to use brute force attacks on long passwords](https://fidoalliance.org/developpez-cybercriminals-are-becoming-less-likely-to-use-brute-force-attacks-on-long-passwords/): Microsoft has invested in recent years in various solutions such as Windows Hello, Microsoft Authenticator, FIDO2 security keys and a palm vein authentication system, among others. Microsoft also previewed Azure Active Directory support for FIDO2 security keys in hybrid environments, as well as a new password-less wizard via the Microsoft 365 Administration Center. The company has also engaged with several security partners in the Microsoft Intelligent Security Association (MISA) to implement passwordless solutions. - [Finextra: Sift acquires biometric-based authentication provider Keyless](https://fidoalliance.org/finextra-sift-acquires-biometric-based-authentication-provider-keyless/): Keyless’ technology meets the Strong Authentication Compliance requirements of PSD2, is FIDO Certified, and helps online businesses more easily meet the requirements of GDPR. Sift will offer Keyless products to regulated businesses and online merchants around the world. - [Verdict: Is the future of authentication passwordless?](https://fidoalliance.org/verdict-is-the-future-of-authentication-passwordless/): Passwords – we struggle to remember them, but we can’t live without them. Or can we? A growing movement towards passwordless authentication – in which biometrics such as fingerprints or pin numbers stored on a device – is gaining traction. This piece interviews FIDO Alliance Executive Director, Andrew Shikiar, about how FIDO is making passwordless a reality.   - [My Chrome Book: Make two-factor authentication mandatory for every login in Google Workspace](https://fidoalliance.org/my-chrome-book-make-two-factor-authentication-mandatory-for-every-login-in-google-workspace/): The two-factor authentication, is the best thing that is currently done regarding the security of a Google account. It is based on two principles: what I know, i.e. a password, and what I have with me, i.e. an immaterial or material identification. To make this process more efficient, users can also use a FIDO key. - [2021 FIDO Developer Challenge: Outcomes and Winners](https://fidoalliance.org/2021-fido-developer-challenge-outcomes-and-winners/): By Joon Hyuk Lee, APAC Market Development Director, FIDO Alliance - [FIDO Alliance Announces Asia Pacific Authenticate Virtual Summit to Drive Further Adoption of Modern User Authentication](https://fidoalliance.org/fido-alliance-announces-asia-pacific-authenticate-virtual-summit-to-drive-further-adoption-of-modern-user-authentication/): Three-day event to provide global updates and local insights for multiple countries cross Asia Pacific  - [PLUSCARD uses FIDO as Innovative Alternative to App-based Payment Authentication](https://fidoalliance.org/pluscard-uses-fido-as-innovative-alternative-to-app-based-payment-authentication/): PLUSCARD, a full-service processor for 140 financial institutions across Germany, worked with Entersekt and its partner Netcetera to launch the first FIDO Certified alternative to app-based authentication in Europe in June 2021. The solution gives customers the option to use FIDO2 Security Keys to authenticate themselves for payments with online merchants leveraging the latest EMV 3DS protocol.  - [Solving the IoT Onboarding Challenge](https://fidoalliance.org/solving-the-iot-onboarding-challenge/): Learn about FIDO's track record of successful collaboration, the onboarding challenge (including hardware, devices, connectivity, and more), onboarding solutions for today, and much more. - [FIDO Masterclass](https://fidoalliance.org/fido-masterclass/): Learn how FIDO Authentication works, and why its a simpler, stronger login experience. Plus, learn about FIDO's progress – becoming part of the web's DNA, as well as supported cross-platforms, support by growing number of service providers, and much more. - [The State of Strong Authentication](https://fidoalliance.org/the-state-of-strong-authentication/): Passwordless Authentication – the next breakthrough in secure digital transformation. Learn about the best laid digital transformation plans. - [The Value of Certification](https://fidoalliance.org/the-value-of-certification/): Hear from FIDO's Dr. Rae Rivera about the value of product certification, including FIDO Certification Programs – updates and on the horizon, and much more. - [Authenticate 2021: Welcome Address](https://fidoalliance.org/authenticate-2021-welcome-address/): Join Andrew Shikiar, FIDO’s Executive Director & CMO, as he welcomes you to Authenticate 2021 and provides exciting new and progress reports from the FIDO Alliance and its stakeholders. - [IBS Intelligence: FIDO Alliance research tracks passwordless authentication in the UK](https://fidoalliance.org/ibs-intelligence-fido-alliance-research-tracks-passwordless-authentication-in-the-uk/): FIDO Alliance has launched its Online Authentication Barometer to track the uptake of secure authentication technologies among the general public. The Online Authentication Barometer provides baseline insights into the state of online authentication in 10 countries across the globe, with future releases of the barometer able to compare changes in behaviours and attitudes over time. - [FIDO Alliance Research Tracks Passwordless Authentication as It Moves Mainstream](https://fidoalliance.org/fido-alliance-research-tracks-passwordless-authentication-as-it-moves-mainstream/): New Online Authentication Barometer from the FIDO Alliance reveals consumer habits, trends and adoption of authentication technologies - [IT-Zoom: The Passwordless Decade Begins](https://fidoalliance.org/it-zoom-the-passwordless-decade-begins/): Authentication via password is neither convenient nor secure. Access technologies that actually manage without a password are considered the gold standard. - [TEISS: SMS Authentication: why it’s bad (and what to do instead)](https://fidoalliance.org/teiss-sms-authentication-why-its-bad-and-what-to-do-instead/): Twitter’s Account Security Report shows users still opt for SMS authentication. Andrew Shikiar at the FIDO Alliance explains why that’s bad and what to do instead. - [Global Security Mag: Technology protect against phishing, not training](https://fidoalliance.org/global-security-mag-technology-protect-against-phishing-not-training/): A byline from by Andrew Shikiar, Executive Director of the FIDO Alliance on the cyber risks linked to phishing and how to cope with it. - [InfoSecurity: Podcast](https://fidoalliance.org/infosecurity-podcast/): In the September episode of the IntoSecurity podcast, the Infosecurity editorial team take a deep dive into the topic of authentication. James Coker interviews Andrew Shikiar, Executive Director of Fast Identity Online, a leading advocate for the move to a passwordless future, and the the team discuss a handful of the latest and hottest cybersecurity headlines. - [Authenticate Virtual Summit: The Imperative for Strong Authentication for Government Services](https://fidoalliance.org/authenticate-virtual-summit-the-imperative-for-strong-authentication-for-government-services/): Authentication plays an increasingly important role in how governments are providing services around the world. - [White Paper: Choosing FIDO Authenticators for Enterprise Use Cases](https://fidoalliance.org/white-paper-choosing-fido-authenticators-for-enterprise-use-cases/): Secure access to online applications and services has evolved into a framework reliant on devices, public-key cryptography, and biometrics to replace the shared secrets of aging passwords. Since 2013, the FIDO Alliance has developed open and scalable advancements to eliminate phishing and other security attacks. To introduce these improvements and to educate employees throughout corporate management and IT security, the FIDO Alliance has established a series of best practices and how-to white papers that align the Alliance’s goals with the responsibilities and titles of technology professionals. This work is dedicated to eliminating passwords and securing the simple act of logging on within the enterprise. - [Silicon: Strong Authentication: AWS launches “operation FIDO”](https://fidoalliance.org/silicon-strong-authentication-aws-launches-operation-fido/): Has Amazon found a way to develop the use of multifactor authentication on its cloud services? The American group has in any case taken an initiative in this direction. It consists of providing FIDO keys free of charge. - [Silicon: Entersekt implements FIDO authentication to improve security, user experience and customer choice](https://fidoalliance.org/silicon-entersekt-implements-fido-authentication-to-improve-security-user-experience-and-customer-choice/): To bridge the gap between strong security on the one hand and a good user experience on the other, Entersekt has extended its authentication suite to include FIDO authentication. The FIDO2 certified solution is quick and easy to integrate into the customer journey. It provides an intuitive alternative to passwords and application-based authentication for online login and payments, and supports roaming and platform-based authenticators.  - [The Register: You. Shall. Not. Pass… word: Soon, you may be logging into websites using just your phone, face, fingerprint or token](https://fidoalliance.org/the-register-you-shall-not-pass-word-soon-you-may-be-logging-into-websites-using-just-your-phone-face-fingerprint-or-token/): The spec will allow people to authenticate themselves and log into internet accounts using a preferred device, through cryptographic keys derived from biometrics, mobile hardware, and/or FIDO2-compliant security keys. <...> The technology should allow websites to support low-friction authentication from visitors who have FIDO2 credentials associated with their desktop or mobile device. - [Finance Derivative: Cryptocurrency exchanges must tackle their cybersecurity issues](https://fidoalliance.org/finance-derivative-cryptocurrency-exchanges-must-tackle-their-cybersecurity-issues/): "However, alongside this growing interest in cryptocurrencies is a significant increase in cybersecurity risks. Investors need to be aware of these risks and the industry must do all it can to make cryptocurrency safer," says Andrew Shikiar, Executive Director and CMO, FIDO Alliance. - [Yahoo! JAPAN turns to FIDO Authentication for Enhanced Login](https://fidoalliance.org/yahoo-japan-turns-to-fido-authentication-for-enhanced-login/): Yahoo Japan Corporation is an internet company offering more than 100 services, including search engine, auction, news, weather, sport, email and shopping to the more than 51 million active users on its platform. - [FIDO Alliance Announces Speakers for Authenticate Virtual Summit, “The Imperative for Strong Authentication for Government Services”](https://fidoalliance.org/fido-alliance-announces-speakers-for-authenticate-virtual-summit-the-imperative-for-strong-authentication-for-government-services/): September 23 event features executives from Akamai, GSA, IRS, NHS, OneSpan, Yubico and more - [Amazon is Giving Free FIDO Security Keys to AWS Customers to Encourage Better Account Security](https://fidoalliance.org/amazon-is-giving-free-fido-security-keys-to-aws-customers-to-encourage-better-account-security/): By Andrew Shikiar, Executive Director & CMO, FIDO Alliance - [Biometric Update: Keyless achieves FIDO2 Certification for face biometrics technology](https://fidoalliance.org/biometric-update-keyless-achieves-fido2-certification-for-face-biometrics-technology/): Keyless has achieved FIDO2 Certification for its enterprise biometric security platform. The news comes after the firm joined the FIDO Alliance in March, and had its face biometrics technology certified for FIDO compliance last May by Fime. - [ITSocial: FIDO Alliance creates new integration standard to secure the Internet of Things](https://fidoalliance.org/itsocial-fido-alliance-creates-new-integration-standard-to-secure-the-internet-of-things/): The FIDO Alliance has announced the launch of the FIDO Device Onboard (FDO) protocol, a new open IoT standard that enables the secure connection of devices to management platforms in the cloud or on-premises. With this standard, the FIDO Alliance aims to address the security, cost and complexity challenges associated with the large-scale deployment of IoT devices. The goal is also to reduce the world's reliance on passwords through simpler and stronger authentication that prevents scalable attacks and account takeovers. - [Reseller News: How the FIDO Alliance Aims to make Passwords Obsolete](https://fidoalliance.org/reseller-news-how-the-fido-alliance-aims-to-make-passwords-obsolete/): Reseller News goes in depth on FIDO Alliance, its mission, and the specifications that websites and other service providers can use to move away from password-based security. Read this article to find out how the FIDO specs allow service providers to take advantage of biometric and other hardware-based security measures, either from hardware security keys or the biometric features built into most new smartphones and some PCs. - [Security Boulevard: Are We There Yet? Approaching a Passwordless Future with FIDO2](https://fidoalliance.org/security-boulevard-are-we-there-yet-approaching-a-passwordless-future-with-fido2/): This article explores the possibility of a passwordless world, what’s driving the passwordless push, barriers to its adoption, developments in technologies like FIDO2 and WebAuthn powering passwordless authentication, and business environment changes that are bringing it closer to reality. - [ComputerWorld: 5 Ways of Dealing with a Work-from-Home Business World](https://fidoalliance.org/computerworld-5-ways-of-dealing-with-a-work-from-home-business-world/): With many companies making longer-term plans for a work-from-home or hybrid environment, ComputerWorld highlights the importance of securing the at-home office and encourages the use of two-factor authentication, particularly with a FIDO Security Key. - [Share Talk: Tern PLC (TERN.L) Investment in FundamentalVR and Portfolio Update](https://fidoalliance.org/share-talk-tern-plc-tern-l-investment-in-fundamentalvr-and-portfolio-update/): During 2021, Device Authority has continued to accelerate its annual recurring revenue growth through its subscription base and its modularised licence platform, KeyScaler. This has been aided by Device Authority being part of the FIDO Alliance that has created a new onboarding standard to secure the IoT, together with further governmental pressure on major companies in a number of territories to increase cyber security. - [Silicon UK: The Future of Digital Identity](https://fidoalliance.org/silicon-uk-the-future-of-digital-identity/): The problem today is that no agreed set of standards exists. We have widely disparate views of what these should be. Everybody has their own favourites. In one camp, we have people who believe the future is a completely new set of digital identity technologies: blockchains, DIDs, new cryptographic algorithms, and the DIDComm protocol stack (which is really little more than S/MIME with onion routing), and those like myself who believe we should build the verifiable credential digital identity eco-system on today’s existing ubiquitous standardised protocols and cryptography, such as X.509, OpenID Connect, W3C Web Authentication (FIDO2) and JWTs. - [FIDO Alliance Announces Authenticate 2021 Agenda](https://fidoalliance.org/fido-alliance-announces-authenticate-2021-agenda/): SEATTLE, August 17, 2021 — Authenticate, the FIDO Alliance’s industry conference dedicated to the who, what, why and how of modern user authentication, today announced its full 2021 agenda. This three-day event, which takes place October 18-20 in Seattle and also with remote attendance options, will help educate attendees on business drivers, technical considerations, and overall best practices for deploying modern authentication systems.  - [Biometric Update: Nok Nok Labs Brings FIDO Authentication to Digital ID Card for Online Services and Payments](https://fidoalliance.org/nok-nok-labs-brings-fido-authentication-to-digital-id-card-for-online-services-and-payments/): Nok Nok Labs has formed a strategic collaborative partnership with CompoSecure Holdings, a premium financial payments card provider to develop digital ID card for online activity and payments, based on the FIDO protocol. - [FIDO Developer Challenge: Welcoming Teams to the Implementation Stage](https://fidoalliance.org/fido-developer-challenge-welcoming-teams-to-the-implementation-stage/): By Joon Hyuk Lee, APAC Market Development Director - [Sicherheit: Passwordless Authentication Receives Extensions](https://fidoalliance.org/sicherheit-passwordless-authentication-receives-extensions/): The FIDO Alliance has introduced enhancements to two of the core FIDO protocols for passwordless authentication. The new features and enhancements to Client To Authenticator Protocol (CTAP) v2.1 and Webauthn Level 2 significantly simplify the implementation of passwordless authentication in enterprises, allow secure e-commerce transactions in pop-up windows, and make login processes more convenient for users. - [Video: PSD2 Requirements and Regulatory Technical Standards](https://fidoalliance.org/video-psd2-requirements-and-regulatory-technical-standards/): FIDO Europe Video: PSD2 Requirements and Regulatory Technical Standards – Changing the authentication landscape with FIDO standards. - [Biometric Update: Passwordless authentication providers unveil digital ID partnerships and progress](https://fidoalliance.org/biometric-update-passwordless-authentication-providers-unveil-digital-id-partnerships-and-progress/): Passwordless authentication based on FIDO specifications, with and without biometrics, appears to be picking up steam. Nok Nok Labs has reviewed its first-half milestones, Versasec has joined FIDO, Identité is providing biometric technology to promote passwordless cybersecurity, and Hypr has joined up with Microsoft. - [Phone Week: Yubico YubiKey Review: Simple, Solid Protection for your Online Accounts](https://fidoalliance.org/phone-week-yubico-yubikey-review-simple-solid-protection-for-your-online-accounts/): Additionally, YubiKey — or the underlying FIDO2/WebAuthn & U2F standards — isn’t supported everywhere. Most of the important services that you probably use likely support it. As of writing, you can lock down your Gmail, Yahoo, Facebook, or Protonmail accounts, for example. You can also log into your Gmail account using a YubiKey as a second factor in the macOS or iOS Mail apps. - [Netzpalaver: FIDO2 Standard for Passwordless Authentication with New Features](https://fidoalliance.org/netzpalaver-fido2-standard-for-passwordless-authentication-with-new-features/): The new features of Client-To-Authenticator-Protocol (CTAP) v2.1 and WebAuthn-Level 2 simplify the implementation of passwordless procedures in enterprises and in complex applications, allow secure e-commerce transactions, and make login processes more convenient for users. - [Industry of Things: New FIDO Standard for Secure Onboarding of IoT Devices](https://fidoalliance.org/industry-of-things-new-fido-standard-for-secure-onboarding-of-iot-devices/): The new industry standard from the FIDO Alliance promises to make the onboarding of IoT devices in industry more effective. It aims to make the process faster, more secure and less expensive. - [Authenticate Financial Services Summit](https://fidoalliance.org/video-authenticate-financial-services-summit/): What’s the role of FIDO authentication in financial services and what can be done to help consumers and issuers be more secure? Those topics were at the foundation of the Authenticate Virtual Summit: Modern Authentication for Financial Services, hosted by the FIDO Alliance on March 25. - [Authenticate Virtual Summit: Focus on Europe](https://fidoalliance.org/video-authenticate-virtual-summit-focus-on-europe/): In Europe, financial services organizations, merchants, telecommunications companies, enterprises and the broader ecosystem are working to balance regulatory demands and rapidly evolving user expectations — all amidst a global pandemic. Implementing strong authentication has become a challenge for these organizations striving to protect valuable user and transaction data without introducing friction in the process. - [DocAuFutur: FIDO Alliance: major novelties to go even faster to a passwordless world](https://fidoalliance.org/docaufutur-fido-alliance-major-novelties-to-go-even-faster-to-a-passwordless-world/): The FIDO Alliance today unveiled its first User Experience (UX) guidelines and new enhancements to the FIDO2 standards to accelerate the move to a password-free world. - [Computerwoche: Finally password-free?](https://fidoalliance.org/computerwoche-finally-password-free/): With FIDO2, there is an industry standard that gets to the root of the problem with passwords. - [Back End News: FIDO releases UX guidelines to speed up adoption of password-less authentication](https://fidoalliance.org/back-end-news-fido-releases-ux-guidelines-to-speed-up-adoption-of-password-less-authentication/): The FIDO Alliance wants to accelerate the elimination of password use among consumers, with the introduction of its first user experience (UX) guidelines and new FIDO2 standards enhancements. - [MobileID World: FIDO Highlights PSD2, eIDAS, and Digital Wallets in Recap of Virtual Authenticate Event](https://fidoalliance.org/mobileid-world-fido-highlights-psd2-eidas-and-digital-wallets-in-recap-of-virtual-authenticate-event/): The FIDO Alliance has published a recap of its most recent Authenticate Virtual Summit. The event took place on June 17, with a Focus on Europe theme that explored some of the different use cases for passwordless technologies across the continent. - [MSN: Twitter Now Supports Security Keys as Sole Two-Factor Authentication Method](https://fidoalliance.org/msn-twitter-now-supports-security-keys-as-sole-two-factor-authentication-method/): The keys use the FIDO and WebAuthn security standards to transfer the burden of protecting against phishing attempts from a human to a hardware device. - [HelpNetSecurity: LoginID SDK empowers developers to integrate FIDO strong authentication into their websites or apps](https://fidoalliance.org/helpnetsecurity-loginid-sdk-empowers-developers-to-integrate-fido-strong-authentication-into-their-websites-or-apps/): LoginID announced additional SDK options for developers. These SDKs empower developers to integrate FIDO strong authentication into their websites or apps. - [FIDO Alliance’s Authenticate Conference Announces 2021 Keynote Speakers and Open Registration](https://fidoalliance.org/fido-alliances-authenticate-conference-announces-2021-keynote-speakers-and-open-registration/): Keynote speakers to include executives from Google, Microsoft, Visa and Yubico - [Authenticate Virtual Summit: Focus on Europe Recap](https://fidoalliance.org/authenticate-virtual-summit-focus-on-europe-recap/): By: FIDO Alliance Staff - [Global Security Mag: FIDO Alliance: Major Novelties to Move Faster Towards a Passwordless World](https://fidoalliance.org/global-security-mag-fido-alliance-major-novelties-to-move-faster-towards-a-passwordless-world/): The FIDO Alliance unveils its first user experience (UX) guidelines and new enhancements to the FIDO2 standards to accelerate the transition to a password-free world. With more than 4 billion devices, all major browsers and operating systems now supporting FIDO authentication, today's announcements make it even easier for service providers and businesses to deliver simple, phishing-resistant and privacy-enhancing login experiences. - [Major FIDO Updates Launched to Accelerate Global Charge Past Passwords](https://fidoalliance.org/new-fido-ux-guidelines-and-specification-enhancements/): New FIDO UX Guidelines and Specification Enhancements Enable Consumers and Enterprises to Meet Growing Demand for Simpler, Stronger Authentication - [FIDO2 Enhancements for Enterprise & Complex Security Applications](https://fidoalliance.org/fido2-enhancements/): By David Turner, Director of Standards Development, FIDO Alliance - [FindBiometrics: With Biometric Tech in Development, Panini Joins FIDO Alliance](https://fidoalliance.org/findbiometrics-with-biometric-tech-in-development-panini-joins-fido-alliance/): Italy-based payments technology provider Panini has joined the FIDO Alliance, and is working on adding biometric technology to its product portfolio, the company has revealed. - [MobileID World: FIDO Alliance Builds On Korea Hackathon With Global Developer Challenge](https://fidoalliance.org/mobileid-world-fido-alliance-builds-on-korea-hackathon-with-global-developer-challenge/): The FIDO Alliance is launching a new Developer Challenge that asks teams to come up with new and innovative ways to use the FIDO2 WebAuthn API. Teams can submit solutions for virtually any field, but they should all try to use FIDO authentication technologies to address some kind of social or technical concern. - [01Net: Apple’s new solution to finally get rid of passwords](https://fidoalliance.org/01net-apples-new-solution-to-finally-get-rid-of-passwords/): Apple emphasises the many advantages of its technology, which resists phishing attempts, syncs with all Apple devices in your account and has a recovery function thanks to iCloud Keychain. In addition, it works with apps, but also with websites. The only problem with this technology is that it is currently only available on Apple devices. This is why the manufacturer is currently in discussion with the FIDO alliance and the W3C consortium to make it a standard. - [IT Social: Auth0 proposes WebAuthn Passwordless, a biometric authentication tool](https://fidoalliance.org/it-social-auth0-proposes-webauthn-passwordless-a-biometric-authentication-tool/): Auth0 WebAuthnPasswordless thus allows users to authenticate using biometrics based on WebAuthn authentication, the official web standard for passwordless authentication published by the W3C and used by the FIDO Alliance, for one-factor authentication. This form of authentication eliminates the security weaknesses associated with password reuse, as passwords are not required. - [PhonAndroid: iOS 15: Face ID and Touch ID can now completely replace passwords](https://fidoalliance.org/phonandroid-ios-15-face-id-and-touch-id-can-now-completely-replace-passwords/): With iOS 15, iPhone users will be able to create accounts on compatible sites without ever choosing passwords. Instead, the Passkey feature will use biometrics (Face ID or Touch ID) to continuously generate the most secure keys possible, without you having to worry about anything. The technology is recognised by the FIDO Alliance. - [Global Security Mag: $10M+ stolen every day: lessons learned on cryptocurrency account security](https://fidoalliance.org/global-security-mag-10m-stolen-every-day-lessons-learned-on-cryptocurrency-account-security/): The risks of loose security for your digital assets and how to protect your digital currency efficiently. - [Computerwoche: How MFA is hacked](https://fidoalliance.org/computerwoche-how-mfa-is-hacked/): In June 2020, Apple announced that Safari 14 would support FIDO2 protocols, joining Android and most other major browsers. Background: FIDO is getting better and https://getzonedup.com/ better, even if the implementations require brainpower in order to be able to use them across browsers, different operating system versions and smartphone apps. - [Digitalisation World: Two-factor authentication yet to deliver?](https://fidoalliance.org/digitalisation-world-two-factor-authentication-yet-to-deliver/): Even among organisations who have implemented 2FA, only just above a quarter (27%) are rolling out FIDO-compliant hardware security keys, which offer the most advanced form of phishing protection, while others rely on more vulnerable and outdated solutions, such as mobile authentication apps (54%) and SMS one-time passcodes (47%). - [C-Net: Apple Says its New Logon Tech is as easy as Passwords but far more Secure](https://fidoalliance.org/c-net-apple-says-its-new-logon-tech-is-as-easy-as-passwords-but-far-more-secure/): Apple has begun testing passkeys, a new authentication technology it says are as easy to use as passwords but vastly more secure. The tech behind Apple's passkeys is built on the WebAuthn https://armodexperiment.com/ technology that emerged from the FIDO (Fast Identity Online) Alliance, a consortium that's been overhauling authentication with hardware security keys. - [Webinar: Considerations for Deploying FIDO in the Enterprise](https://fidoalliance.org/webinar-considerations-for-deploying-fido-in-the-enterprise-2/): Passwords are archaic, and a danger to enterprise security. Now the accepted standard for multi-factor authentication (MFA), FIDO Authentication can be deployed in the enterprise for easier and secure access to corporate networks, applications, and workstations. Organizations that adopt FIDO will experience profound improvements in security, helpdesk costs, user experience, and productivity. But where to start? Attend this webinar to learn about considerations for deploying FIDO in the enterprise, including how to gradually rollout FIDO authentication and select the right authenticators and the right server policies for the right user cases. This webinar will provide essential education for any organization that wants to get started on eliminating passwords and securing the simple act of logging on within their company. View the video. - [Webinar: Considerations for Deploying FIDO in the Enterprise](https://fidoalliance.org/webinar-considerations-for-deploying-fido-in-the-enterprise/): Passwords are archaic, and a danger to enterprise security. Now the accepted standard for multi-factor authentication (MFA), FIDO Authentication can be deployed in the enterprise for easier and secure access to corporate networks, applications, and workstations. Organizations that adopt FIDO will experience profound improvements in security, helpdesk costs, user experience, and productivity. But where to start? Attend this webinar to learn about considerations for deploying FIDO in the enterprise, including how to gradually rollout FIDO authentication and select the right authenticators and the right server policies for the right user cases. This webinar will provide essential education for any organization that wants to get started on eliminating passwords and securing the simple act of logging on within their company. View the slides. - [Webinar: Catch Up with FIDO Plus Open AMA Session](https://fidoalliance.org/webinar-catch-up-with-fido-plus-open-ama-session/): The FIDO Alliance's goal is for the whole world to move away from usernames, passwords, and traditional MFA to a simpler and stronger way to log in with FIDO! Here's a look at the past year’s progress and what's happening next. - [Webinar: Ask FIDO Anything: All About Certification](https://fidoalliance.org/webinar-ask-fido-anything-all-about-certification-2/): The FIDO Certified program is  a core activity of the FIDO Alliance that underpins the B2B FIDO ecosystem of interoperable products and services. A growing majority of service providers are specifying FIDO Certified products in their RFPs as they are seeking the benefits of having a standards-based and future-proof foundation for user authentication.   - [Webinar: Ask FIDO Anything: All About Certification](https://fidoalliance.org/webinar-ask-fido-anything-all-about-certification/): The FIDO Certified program is  a core activity of the FIDO Alliance that underpins the B2B FIDO ecosystem of interoperable products and services. A growing majority of service providers are specifying FIDO Certified products in their RFPs as they are seeking the benefits of having a standards-based and future-proof foundation for user authentication.   - [Webinar: Introducing FIDO’s IoT Specification: FIDO Device Onboard](https://fidoalliance.org/webinar-introducing-fidos-iot-specification-fido-device-onboard-2/): The FIDO Alliance announced today the launch of the FIDO Device Onboard (FDO) protocol, a new, open IoT standard that enables devices to simply and securely onboard to cloud and on-premise management platforms. Through this standard, the FIDO Alliance addresses challenges of security, cost and complexity tied to IoT device deployment at scale. FIDO Device Onboard furthers the fundamental vision of the Alliance, which has brought together 250+ of the most influential and innovative companies and government agencies from around the world to address cyber security in order to eliminate data breaches, and enable secure online experiences. - [Webinar: Introducing FIDO’s IoT Specification: FIDO Device Onboard](https://fidoalliance.org/webinar-introducing-fidos-iot-specification-fido-device-onboard/): The FIDO Alliance announced today the launch of the FIDO Device Onboard (FDO) protocol, a new, open IoT standard that enables devices to simply and securely onboard to cloud and on-premise management platforms. Through this standard, the FIDO Alliance addresses challenges of security, cost and complexity tied to IoT device deployment at scale. FIDO Device Onboard furthers the fundamental vision of the Alliance, which has brought together 250+ of the most influential and innovative companies and government agencies from around the world to address cyber security in order to eliminate data breaches, and enable secure online experiences. - [FIDO Alliance Announces the FIDO Developer Challenge](https://fidoalliance.org/fido-alliance-announces-the-fido-developer-challenge/): First Global Program Invites Teams to Leverage Public FIDO2 WebAuthn API to Showcase Unique FIDO Authentication Ideas - Entry Deadline July 2, 2021 - [Announcing the FIDO Developer Challenge for Developers Across the Globe](https://fidoalliance.org/announcing-the-fido-developer-challenge-for-developers-across-the-globe/): By Joon Hyuk Lee, APAC Market Development Director, FIDO Alliance - [FIDO Alliance Announces Speakers for Second 2021 Authenticate Virtual Summit: “Focus on Europe”](https://fidoalliance.org/fido-alliance-announces-speakers-for-second-2021-authenticate-virtual-summit-focus-on-europe/): June 17 event features representatives from Amazon, Consult Hyperion, Mastercard, Nok Nok, WorldPay, Yubico, and more - [Finextra: Visa invests in LoginID to accelerate Fido-certified SCA](https://fidoalliance.org/finextra-visa-invests-in-loginid-to-accelerate-fido-certified-sca/): Visa has invested in LoginID, the startup behind a series of APIs and SDKs that make it easy for firms to integrate Fido-certified biometric authentication steps into their sites and apps. - [IBS Intelligence: FIDO2-certified LoginID secures new investment from Visa](https://fidoalliance.org/ibs-intelligence-fido2-certified-loginid-secures-new-investment-from-visa/): LoginID, a FIDO-certified authentication provider, has announced securing additional investment from Visa on the heels of its $6M seed round from veteran payment and fintech entrepreneurs. The investment amount from Visa is undisclosed. - [TechCrunch: What $10M in Daily Thefts Tells us About Crypto Security](https://fidoalliance.org/techcrunch-what-10m-in-daily-thefts-tells-us-about-crypto-security/): FIDO Executive Director and CMO, Andrew Shikiar, explains how the cryptocurrency market must enable secure access to assets in order to meet its full potential. The FIDO (Fast IDentity Online) authentication protocols were developed by a who’s who of IT, payments and consumer services and ensure that all cryptographic credentials are stored on a user’s device — thereby eliminating even the most advanced machine-in-the-middle attacks. ## Pages - [FIDO Alliance and Payments](https://fidoalliance.org/fido-alliance-payments/): Payment fraud and friction cost the industry and consumers billions annually. Passwords and one-time codes sent via SMS remain the dominant authentication methods in payment flows — yet they are among the easiest to phish and compromise.  - [MDS Portal User Guide for Vendor Users](https://fidoalliance.org/mds-portal-user-guide-for-vendor-users/): This guide is for Vendor Users who are using the MDS Portal. It provides instructions on account management as well as metadata statement management. - [MDS Portal User Guide for Vendor Admins](https://fidoalliance.org/mds-portal-user-guide-for-vendor-admins/): This guide is for Vendor Admins who are using the MDS Portal. It provides instructions on account creation and management as well as metadata statement management. - [Alliance Membership](https://fidoalliance.org/alliance-membership-2/): The FIDO Alliance is driven by the hundreds of global tech that have come together in support of the organization’s mission to enable identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. - [FIDO Resources](https://fidoalliance.org/fido-resources/): This section includes:FIDO Case Studies - Papers that discuss how organizations have leveraged FIDO standards to create passwordless authentication to provide secure logins for their employees and clients. - [MDS Changelog](https://fidoalliance.org/mds-changelog/): This entry covers the addition of a GlobalSign cross-certificate to the BLOB for the MDS Service.  - [Security Certification: Authenticator Security Levels](https://fidoalliance.org/security-certification-authenticator-security-levels/): As passkey adoption expands worldwide, it's important for service providers implementing passkeys and vendors building FIDO-compliant authenticators to understand the function of FIDO authenticators and the protection they offer for cryptographic credentials - [The Passkey Pledge](https://fidoalliance.org/passkeypledge/): On April 9, 2025, the FIDO Alliance introduced the Passkey Pledge, inviting organizations worldwide to make a voluntary commitment to increase awareness and adoption of passkey sign-ins to make the web safer and more accessible. - [FIDO Device Onboarding](https://fidoalliance.org/fido-device-onboarding/): The FIDO Device Onboard (FDO) specification offers an automatic onboarding protocol for edge nodes, datacenter servers, and IoT devices. This protocol facilitates secure installation of secrets and configuration data into devices to allow for seamless connection to cloud and edge management platforms. - [Passkeys](https://fidoalliance.org/passkeys-2/): Passkeypassˌkee noun - [FIDO Alliance and Agentic AI](https://fidoalliance.org/fido-alliance-agentic-ai/): The FIDO Alliance's work in agentic AI is being carried out in its Agentic Authentication Technical Working Group, and the Payments Technical Working Group: - [FIDO Accredited Laboratories](https://fidoalliance.org/accredited-lab-finder/): The FIDO Accredited Lab Finder can be used to search for the lab that best meets your needs. Use the search bar or dropdown menus to filter results. Then select a lab to view more information. - [Alliance Membership](https://fidoalliance.org/alliance-membership/): The FIDO Alliance is driven by hundreds of members that have united globally in support of the organization’s mission to enable identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. - [FIDO Certification](https://fidoalliance.org/fido-certification-2/) - [User Authentication Certification Programs](https://fidoalliance.org/fido-user-authentication-certification-programs/): The FIDO Alliance’s user authentication certification programs ensure that authentication products adhere to FIDO user authentication specifications for conformance, security, and interoperability - enabling trusted sign-ins with passkey at scale. - [FIDO Certification Fees](https://fidoalliance.org/fido-certification-fees/): This page outlines the fees for FIDO Certification programs. As part of the product certification process, these fees must be paid before FIDO Certification can be issued. - [FIDO News and Events](https://fidoalliance.org/fido-news-and-events/): Welcome to FIDO News and Events! Here you can find the latest information from the FIDO Alliance as well as press releases and articles from global news sources. - [FIDO Alliance Focus Areas](https://fidoalliance.org/fido-alliance-focus-areas/): The FIDO Alliance enables identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. The Alliance provides a member-driven forum that focuses on: - [FIDO Certification](https://fidoalliance.org/fido-certification/): FIDO certification measures the compliance of products against FIDO specifications and globally recognized security and performance standards. Certification helps ensure that standards are met and that security and interoperability requirements are upheld worldwide. This benefits vendors, deploying organizations, and end users.  - [FIDO Groups and Committees](https://fidoalliance.org/fido-groups-and-committees/): The FIDO Alliance has numerous working groups, committees, and special interest groups, including various FIDO groups. Each one serves a purpose to help ensure the FIDO Alliance goals continue to be advanced and policies continue to be upheld. - [Fees for FIDO Accredited Labs](https://fidoalliance.org/fees-for-fido-accredited-labs/): FIDO Laboratory accreditation has associated fees. The following fees apply to laboratory accreditation for all laboratory types: - [Download Credential Exchange Specifications](https://fidoalliance.org/download-credential-exchange-specifications/): The FIDO Alliances publishes the following technical specifications for any implementer to download. The FIDO Specification Status and Intellectual Property Rights (IPR) of the FIDO Alliance specifications can be found here. - [FIDO Alliance Credential Exchange Specifications Overview](https://fidoalliance.org/fido-alliance-credential-exchange-specifications-overview/): FIDO Alliance’s credential exchange specifications define a standard format for transferring all types of credentials in a credential manager including passwords, passkeys and more in a manner that is secure by default. - [FIDO Alliance and Digital Credentials](https://fidoalliance.org/fido-alliance-digital-credentials/): The FIDO Alliance is coordinating global efforts to align the digital credentials ecosystem through certification, specifications, and market adoption programs. - [Passkeys Week 2025 Report](https://fidoalliance.org/passkeys-week-2025-report/): Passkeys Week is an industry-wide campaign to accelerate adoption of passkey sign-ins and encourage developers to build passkey support into their apps, websites, or authentication products. Throughout last week, FIDO Alliance and other leading global organizations participated in Passkeys Week 2025 by sharing passkey implementation experiences, success stories, highlighting new advancements and more.  - [Certification Secretariat / Program Coordinator](https://fidoalliance.org/careers-certification-secretariat-program-coordinator/): Job Title: Certification Secretariat / Program CoordinatorOrganization: FIDO AllianceLocation: RemoteReports To: Certification DirectorEmployment Type: Full-Time - [Automotive Use Cases](https://fidoalliance.org/passkey-use-case-automotive/): The automotive industry is undergoing a major transformation. Modern vehicles are no longer simply machines to transport people or goods, but also platforms for a range of digital services. This brings an unprecedented opportunity to innovate and capitalize on new business models (such as in-vehicle commerce and subscription services) and passkeys can play a critical role. - [FIDO Alliance Member Application](https://fidoalliance.org/membership-application/): The FIDO Alliance welcomes all organizations interested in helping to create a more secure online ecosystem for users and businesses. Membership allows your organization to participate in the definition of a standard protocol for secure authentication. By participating in developing the technical standard, and in planning and executing the Alliance’s marketing, FIDO certification and deployment programs, your organization will gain a thorough understanding of how user authentication is evolving to ensure a secure internet for the future. - [Government Showcase](https://fidoalliance.org/fido-government-deployments-and-recognitions/): This page lists government organizations that have either deployed FIDO Certified solutions or that recognize and include references to FIDO standards in policy documents and regulations pertaining to online authentication. - [Passkey Use Cases](https://fidoalliance.org/passkey-use-cases/): Support for passkeys can be implemented by most organizations across multiple industries. There are four main passkey use cases related to passkey implementation. However, each use case has specific guidelines to consider when implementing support for passkeys. - [Passkeys](https://fidoalliance.org/passkeys/): Passkeys pave the path to passwordless authentication,  moving away from passwords responsible for 80% of breaches today. A passkey is an authentication credential based on FIDO standards, that can be stored on your phone or computer, or in a hardware security key allowing a user to sign in to apps and websites with the same process that they use to unlock their device (biometrics, PIN, or pattern). Passkeys are FIDO cryptographic credentials that are tied to a user’s account on a website or application. With passkeys, users no longer need to enter usernames and passwords or additional factors. Instead, a user approves a sign-in with the same process they use to unlock their device (for example, biometrics, PIN, or pattern). - [FIDO® Certified FDO Products](https://fidoalliance.org/certification/fido-device-onboard/fido-certified-products/): Discover FIDO Device Onboarding (FDO) Certified Products for secure and scalable IoT device integration. Gain significant time to value with automated onboarding, surpassing manual methods. - [FIDO Biometric Certification FAQ](https://fidoalliance.org/certification-biometric-component-fido-biometric-certification-faq/): FIDO biometric certification is based on ISO standards1, with requirements developed by the FIDO Alliance, an international authority of stakeholders from industry, government, and subject matter experts, and offered by a FIDO accredited network of laboratories worldwide. - [FIDO® Certified IDV Face Verification Products](https://fidoalliance.org/certification/identity-verification/face-verification/fido-certified-products/): DFAR: - [Homepage](https://fidoalliance.org/) - [Credential Exchange Specifications](https://fidoalliance.org/specifications-credential-exchange-specifications/): FIDO Alliance’s credential exchange specifications define a standard format for transferring all types of credentials in a credential manager including passwords, passkeys and more in a manner that is secure by default. - [Face Verification Resource Documentation](https://fidoalliance.org/certification/identity-verification/face-verification/resource-documentation/): This policy governs the biometric certification aspects of the FIDO Certification Program. It defines the overall process of the Face Verification Certification and also answers questions around recertification. - [Get Certified for Face Verification](https://fidoalliance.org/certification/identity-verification/face-verification/get-certified/): Review and complete the FIDO vendor non-disclosure agreement . - [Face Verification Accredited Labs](https://fidoalliance.org/certification/identity-verification/face-verification/accredited-labs/): Company Telephone: +49 201 8999 639Primary Program Contact: M. LeGuin Email: M.LeGuin@tuvit.de  - [Face Verification Certification Fees](https://fidoalliance.org/certification/identity-verification/face-verification/fees/): The fees to participate in the Face Verification Certification Program are assessed per certified implementation. - [Face Verification Certification Process Overview](https://fidoalliance.org/certification/identity-verification/face-verification/process-overview/): FIDO Alliance’s Face Verification Certification Program is independent of its other certification programs. There are no FIDO certification prerequisites to apply for Face Verification certification for a remote identity verification solution.  - [Face Verification](https://fidoalliance.org/certification/identity-verification/face-verification/): Biometric face verification is imperative for validating a user’s identity in the authentication process – especially in remote environments.  - [Identity Verification Certifications](https://fidoalliance.org/certification/identity-verification/): Identity verification is mission-critical to ensure a user’s identity is accurately and securely verified in the user authentication process. - [设计系统重构](https://fidoalliance.org/design-system-refactor/) - [Payments](https://fidoalliance.org/passkey-use-case/payments/): In payments, passkeys can supplement existing payment authentication methods and strengthen the security of e-commerce transactions. - [Consumer Password and Passkey Trends: World Password Day 2024](https://fidoalliance.org/content-ebook-consumer-password-and-passkey-trends-wpd-2024/): Consumers are adopting passkeys at a rapid pace in 2024. With large global consumer brands, such as Adobe, Amazon, Apple, Google, Hyatt, Nintendo, PayPal, Playstation, Shopify and TikTok enabling passkey technology for their users, more than 13 billion accounts can now leverage passkeys for sign-in.  - [Careers](https://fidoalliance.org/careers/): FIDO Alliance is dedicated to helping the Alliance reach its technical and market adoption objectives.   - [FIDO Logo Trademark Usage Agreement for Press and Educational Purposes](https://fidoalliance.org/fido-logo-trademark-usage-agreement-for-press-and-educational-purposes/): By completing the form below, you are agreeing to this Agreement and the following terms and conditions associated with your use of a FIDO trademark or service mark (collectively the “FIDO Trademarks”) in your written materials and publications. - [Passkey Implementation Guide](https://fidoalliance.org/implement-passkeys-overview/): Consumer service providers, enterprises and governments around the world are rapidly moving from phishable forms authentication such as passwords and SMS OTPs to FIDO authentication-based sign-ins with passkeys. FIDO authentication reduces the risk of phishing and eliminates credential reuse. It also helps to speed up sign-ins, improve service delivery and lower costs. Every organization has its own varying use cases and business requirements; read on to get started by understanding passkey implementation in consumer, enterprise and government environments, and then dive into our technical resources to get started. - [Get the FIDO Passkey Icon](https://fidoalliance.org/get-the-passkey-icon/): Service providers providing sign-ins with passkeys should use the passkey icon to indicate to their users that they can securely and easily sign in to their website or app without passwords. The FIDO Alliance provides the passkey icon to promote consistency in user experience when signing in with a passkey. - [Government & Public Policy](https://fidoalliance.org/fido-alliance-public-policy-submissions/): The global market is bursting with innovation around authentication technology – but some solutions are better equipped to meet the security and usability needs in government. - [FIDO Accredited Security Laboratories](https://fidoalliance.org/fdo-security-certification/fido-accredited-security-laboratories/) - [Biometric Certification Resource Documentation](https://fidoalliance.org/certification/resource-documentation-biometric/): Biometric Component Certification Policy - [FIDO Accredited Biometric Laboratories](https://fidoalliance.org/certification/biometric-component-introduction/accredited-labs/): FIDO accredits independent labs to perform biometric evaluations as part of FIDO Alliance’s Biometric Component Certification Program. This page contains a list of the accredited laboratories and further information about the accreditation process. - [Get Certified for Biometric Components](https://fidoalliance.org/certification/get-certified-biometric/): Step 1: - [Certification Fees](https://fidoalliance.org/certification/biometric-certification-fees/): Fees are assessed per certified implementation and must be paid before the issuance of FIDO® Certified Certificate documentation. - [Biometrics Certification Process Overview](https://fidoalliance.org/certification/biometric-certification-process-overview/): FIDO Alliance’s Biometric Component Certification Program is independent of its other certification programs. There are no FIDO certification prerequisites to apply for biometric component certification for a subsystem. Once a biometric subsystem has been certified, there are rules for how it can be integrated into an authenticator seeking FIDO Authenticator Certification. These rules are described in the Allowed Integration Document and are defined by the biometric vendor during the biometric component certification process. - [Biometric Certification](https://fidoalliance.org/certification/biometric-component-introduction/): Biometric user verification has become a popular way to replace passwords and PINs. Due to the need for industry-defined standards to validate performance claims and address variances in the accuracy and reliability of these solutions, The FIDO Alliance offers the Biometric Component Certification Program. The Biometric Certification Program is the first program that tests biometrics for identity verification and is renowned for certification credibility in the industry. - [Laboratory Accreditation Process – Biometrics](https://fidoalliance.org/accreditation-process-fees-biometrics/): The full accreditation process and requirements for laboratories is defined in the Biometric Laboratory Accreditation Policy. - [FIDO Security Laboratory Accreditation](https://fidoalliance.org/accreditation-process-fees-security/): The full Accreditation process and requirements for laboratories is defined in the Security Laboratory Accreditation Policy. - [FIDO Accredited Laboratories](https://fidoalliance.org/laboratory-overview/): FIDO Accredited Laboratories are utilized to test and perform evaluations as part of the FIDO Alliance programs. - [Resource Documentation FDO](https://fidoalliance.org/device-onboarding-overview/device-onboarding-certification/resource-documentation-fdo/): Begin building trust among device owners connecting to other services and start the steps for FDO Certification. The program is open to FIDO Alliance members and non-members alike, although FIDO Alliance members will receive discounts on certification fees and be exposed to added co-marketing opportunities. - [Get Certified for FDO](https://fidoalliance.org/get-certified-fdo/): Begin building trust among device owners connecting to other services and start the steps for FDO Certification. The program is open to FIDO Members and non-members alike, although FIDO Alliance Members will receive discounts on certification fees and be exposed to added co-marketing opportunities. - [FDO Certification Fees](https://fidoalliance.org/fdo-certification-fees/): Fees are assessed per certified implementation and must be paid before the issuance of FIDO® Certified Certificate documentation. - [FDO Certification Process](https://fidoalliance.org/fdo-certification-process-overview/): FDO Certification is independent of other FIDO Alliance certification programs.  - [FDO Security Certification](https://fidoalliance.org/fdo-security-certification/): Security Certification is comprised of one step, FDO Security Evaluation, and is required for certifying Device Onboarding Services and Devices. FDO Security Certification validates the security characteristics of an implementation, including adherence to all FDO Security Requirements. Successful completion and evaluation of a vendor questionnaire by the FIDO Security Secretariat is required for at least FDO Certification Level 1 (L1) *. - [FIDO Device Onboard Certification](https://fidoalliance.org/certification/fido-device-onboard/): The FIDO Device Onboard (FDO) Certification Program is a product certification program intended to certify edge and IoT device onboarding implementations of FDO. These connected devices are components defined in the FDO specification, certification requirements, and policy documentation. - [User Authentication Certification Fees](https://fidoalliance.org/certification/user-authentication-certification-registration-fees/): Fees are assessed per certified implementation and must be paid before the issuance of FIDO® Certified Certificate documentation.User Authentication Certification Fees for Authenticators are assessed per certified implementation. For an overview of the different security levels and requirements that can impact certification fees, please review the Authenticator Certification page. Additionally, for an overview of the different authenticator scenarios following the certification of a base Certified product, please review the Authenticator Certification page. - [Functional Certification Process: Servers](https://fidoalliance.org/certification/functional-certification/functional-certification-process-servers/): Conformance self‐validation testing is a required step of the certification process. Self‐validation results submitted through the corresponding test tools must be confirmed by FIDO’s Certification Secretariat  at least 14 days before attending an interoperability event to ensure that implementations are at least minimally compliant with the specifications. Conformance testing is available for all FIDO protocols. - [Functional Certification: Servers](https://fidoalliance.org/certification/functional-certification/functional-certification-servers/): The FIDO Functional Certification program allows members and non-members to measure compliance and ensure interoperability among products and services that support FIDO specifications. Companies completing certification may display the FIDO® Certified logo to demonstrate to consumers, customers and partners that they have created a high‐quality, interoperable FIDO implementation that is known to work with other FIDO implementations. - [Device Onboarding Certification](https://fidoalliance.org/device-onboarding-overview/device-onboarding-certification/): FIDO’s certification programs are a critical element in ensuring an interoperable ecosystem of products and services that organizations can leverage to deploy FIDO Authentication solutions worldwide. FIDO Alliance manages functional certification programs for its core specifications (UAF, U2F and FIDO2) to validate product conformance and interoperability, and in addition has introduced programs to delineate security capabilities of FIDO Certified Authenticators as well as to test and validate the efficacy of biometric components. - [FIDO Device Onboarding Resources](https://fidoalliance.org/device-onboarding-overview/device-onboarding-resources/): Learn about device onboarding and the benefits of FDO, including acceleration of Edge and IoT provisioning at scale using FDO specifications. Use the FIDO Device Onboard resources below to start your journey to deploying FDO solutions for next-generation device onboarding. - [Consumer Use Cases](https://fidoalliance.org/passkey-use-case/consumer/): Large global service providers like Amazon, CVS Health, Google, Nintendo, Intuit, Mercari and many more now offer FIDO-based sign-ins with passkeys. FIDO authentication reduces the risk of phishing and eliminates credential reuse, and results in sign-ins that are up to 75% faster, and 20% more successful than passwords or passwords plus a second factor like SMS OTP. Faster, more secure and more successful sign-ins means less breach risk, more transactions, better service delivery and less resets or account recovery. - [Specifications](https://fidoalliance.org/specifications-overview/): Specification development is a core element of FIDO Alliance’s mission to reduce the world’s reliance on passwords.  Through its technical working groups, the FIDO Alliance publishes specifications in two areas: user authentication and secure device onboarding.  FIDO Alliance also submits mature technical specification(s) to recognized standards development organization(s) for formal standardization. - [Membership Benefits](https://fidoalliance.org/members/become-a-member/): There are significant benefits to taking part in the FIDO Alliance as a member, whether your company is a vendor looking to bring FIDO-based solutions to market or a service provider seeking to understand the most effective ways to deploy FIDO authentication to your customers and/or employees. - [FDO Functional Certification](https://fidoalliance.org/fdo-functional-certification/): Functional Certification is comprised of two steps, Conformance Testing and Interoperability Testing, and is required for all certifying implementations of FDO. Functional Certification validates the functional characteristics of an implementation, including conformity to the specification and requirements. Interoperability Testing validates that implementations are compatible with each other. - [Search](https://fidoalliance.org/search/) - [Blocks Sandbox](https://fidoalliance.org/blocks-sandbox/): Irure deserunt laborum irure anim laboris eu anim excepteur velit dolore ipsum aute Lorem ipsum ullamco. Reprehenderit tempor dolore aliqua mollit reprehenderit consectetur officia officia Lorem dolore deserunt excepteur commodo sit dolore. Labore Lorem ad sint esse quis ad consequat aute ut id esse sunt labore dolore. Cupidatat aute eiusmod aliqua mollit cillum deserunt aliqua. - [Enterprise Use Cases](https://fidoalliance.org/passkey-use-case/enterprise/): Enterprises still leveraging phishable authentication such as passwords and SMS one-time passwords are rapidly moving to phishing-resistant authentication with FIDO-based passkeys. FIDO authentication reduces the risk of phishing and eliminates credential reuse. It also helps increase productivity and lower costs – it has been proven to improve the speed and ease of authenticating employees, contractors, suppliers or other professionals during digital transactions and when accessing services. Enterprises evaluating FIDO and considering implementing sign-ins with passkeys should read on for information and guidance on how to advance their FIDO deployments while meeting their varying use cases and requirements. - [DocAuth Certification Fees](https://fidoalliance.org/certification/identity-verification/document-authenticity/fees/): The fees to participate in the Document Authenticity Certification Program are assessed per certified implementation. - [Accredited Labs](https://fidoalliance.org/certification/identity-verification/document-authenticity/accredited-labs/): Email: info@bixelab.com    - [FIDO Device Onboard](https://fidoalliance.org/device-onboarding-overview/): The FIDO Device Onboard (FDO) specification offers an automatic onboarding protocol for edge nodes, datacenter servers, and IoT devices. This protocol facilitates secure installation of secrets and configuration data into devices to allow for seamless connection to cloud and edge management platforms. - [Get Certified for DocAuth](https://fidoalliance.org/certification/identity-verification/document-authenticity/get-certified/): Step 1: - [DocAuth Resource Documentation](https://fidoalliance.org/certification/identity-verification/document-authenticity/resource-documentation/): This policy governs the document testing certification aspects of the FIDO Certification Program. It defines the overall process of the DocAuth certification and also answers questions around recertification. - [DocAuth Certification Process Overview](https://fidoalliance.org/certification/identity-verification/document-authenticity/process-overview/): FIDO Alliance’s Doc Auth Certification Program is independent of its other certification programs. There are no FIDO certification prerequisites to apply for DocAuth certification for a mobile document verification solution.   - [Document Authenticity (DocAuth) Certification Program](https://fidoalliance.org/certification/identity-verification/document-authenticity/): Identity verification of government-issued identity documents is mission-critical to ensure a user’s identity is accurately and securely verified in the authentication process. This is especially important in remote environments and mobile device applications. - [Metadata Submission Terms (for Authenticator Vendors)](https://fidoalliance.org/metadata-submission-terms-for-authenticator-vendors-2/): THESE METADATA SUBMISSION TERMS (“Terms”) govern the submission of Metadata Statements made available by you (“You”) by the Metadata Service (“MDS”), operated by FIDO Alliance, Inc. (“FIDO”). The specification of Version 3.0 of the Metadata Statements is defined by FIDO in the FIDO Metadata Statements Specification available at https://fidoalliance.org/specs/mds/fido-metadata-statement-v3.0-ps-20210518.html . By clicking on the “Accepted and Agreed” button at the bottom of this page, You agree to accept and be bound by these Terms. If You do not agree to be bound by these Terms (or any part thereof), click on “Do Not Accept” or simply leave this website. You are not granted permission to use the MDS or provide Metadata Statements and must exit this website immediately. - [Metadata Usage Terms (for Relying Parties or Service Providers)](https://fidoalliance.org/metadata-usage-terms-for-relying-parties-or-service-providers-2/): THIS METADATA USAGE TERMS (“Terms”) governs your use of Metadata Statements and BLOB files, including Metadata Statements in the BLOB files (collectively “METADATA”) accessed, viewed, downloaded or otherwise received by you (“You”) directly from the Metadata Service (“MDS”), operated by FIDO Alliance, Inc. (“FIDO”). The specification of Version 3.0 of the Metadata Statements is defined by FIDO in the FIDO Metadata Statements Specification available at https://fidoalliance.org/specs/mds/fido-metadata-statement-v3.0-ps-20210518.html . Each Metadata Statement is owned and contributed by its respective vendor (“Contributing Vendor”) through the MDS for use by You in accordance with the provisions of these Terms. The BLOB file is owned and made available by FIDO for use by You in accordance with the provisions of these Terms. The specification of the BLOB file is defined by FIDO in Version 3.0 of the FIDO Metadata Service Specification available at https://fidoalliance.org/specs/mds/fido-metadata-service-v3.0-ps-20210518.html. By continuing to access the MDS and use METADATA, You agree to accept and be bound by the terms of these Terms. If You do not agree to be bound by these Terms (or any part thereof), You are not granted permission to use the MDS or METADATA. - [Metadata Usage Terms (for Developers)](https://fidoalliance.org/metadata-usage-terms-for-developers/): THIS METADATA USAGE TERMS (“Terms”) governs the use of BLOB files, including Metadata Statements in the BLOB files (collectively “METADATA”) accessed, viewed, downloaded or otherwise received by you (“You”) or any software developed by You directly from the Metadata Service (“MDS”), operated by FIDO Alliance, Inc. (“FIDO”). The specification of Version 3.0 of the Metadata Statements is defined by FIDO in the FIDO Metadata Statements Specification available at https://fidoalliance.org/specs/mds/fido-metadata-statement-v3.0-ps-20210518.html. Each Metadata Statement is owned and contributed by its respective vendor (“Contributing Vendor”) through the MDS for use by You or any software developed by You in accordance with the provisions of these Terms. The BLOB file is owned and made available by FIDO for use by You or any software developed by You in accordance with the provisions of these Terms. The specification of the BLOB file is defined by FIDO in Version 3.0 of the FIDO Metadata Service Specification available at https://fidoalliance.org/specs/mds/fido-metadata-service-v3.0-ps-20210518.html. By developing software for use with the MDS and METADATA and by continuing to access the MDS and use METADATA, You agree to accept and be bound by the terms of these Terms. If You do not agree to be bound by these Terms (or any part thereof), You are not granted permission to use the MDS or METADATA. - [MDS Legal Terms](https://fidoalliance.org/metadata-legal-terms/): To preserve the rights and limit the liabilities of all parties using the MDS, especially FIDO as the MDSprovider, various legal agreements apply to the parties and legal headers must be placed in the BLOBand each Metadata Statement. The three legal agreements are: - [FIDO2](https://fidoalliance.org/fido2/): The FIDO Alliance developed FIDO Authentication standards based on public key cryptography for authentication that is more secure than passwords and SMS OTPs, simpler for consumers to use, and easier for service providers to deploy and manage. FIDO Authentication enables password-only logins to be replaced with secure and fast login experiences across websites and apps. - [Authenticator Level 1+](https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-1-2/): Level 1+ tests the authenticator’s (SW implemented) defense against large scale software attacks and provides greater assurance of defense compared to Level 1.  - [Research Findings: Online Authentication Barometer](https://fidoalliance.org/online-authentication-barometer/): To find out, the FIDO Alliance conducted a survey of 10,000 consumers in the U.S., U.K., France, Germany, Australia, Singapore, Japan, South Korea, India and China. - [Passkey Directory](https://fidoalliance.org/passkeys-directory/): Want to know where you can use passkeys today? The Passkeys Directory is an interactive resource that lists active FIDO passkey implementation examples, both for consumers and in the workforce. It also indicates what the user experience is — whether the passkey is synced and available across devices, or the passkey is bound and available on a single device such as a FIDO security key or within a mobile app. This is not an exhaustive list of deployments and will be updated regularly. If you have questions or would like to contribute an entry to the directory, contact us at marketing@fidoalliance.org. - [Code of Conduct](https://fidoalliance.org/code-of-conduct/): The FIDO Alliance is a non-profit industry organization that works to replace passwords with simpler, secure methods of authentication. It consists of hundreds of members varying in size and geographical diversity, and collaborates with industry partners and regulators around the world.   - [FIDO Alliance Privacy Principles](https://fidoalliance.org/fido-authentication-2/privacy-principles/): This page covers  the FIDO Alliance’s commitment to protecting user privacy, which has been a fundamental tenet of FIDO Authentication since its inception. The work of the FIDO Alliance and it's members is based on these principles. - [Download FDO Specifications](https://fidoalliance.org/specifications/download-iot-specifications/): The latest versions of the FIDO Alliance FDO specifications are available below. - [FIDO Alliance Public Policy Program and Submissions](https://fidoalliance.org/fido-alliance-policy-documents/): The FIDO Alliance has an active public policy program that enables working groups and member public policy leads to engage in meaningful discussion with policymakers around the world on how FIDO specifications offer newer, better options for strong authentication, and recommends associated policy updates. - [FIDO® Trademark and Service Mark Usage Agreement for Websites: EXHIBIT A](https://fidoalliance.org/fido-trademark-and-service-mark-usage-agreement-for-websites-exhibit-a/): Do not reproduce these examples. Upon execution of the FIDO Alliance Trademark and Service Mark Usage Agreement for Websites and qualifying to use the appropriate Marks, COMPANY will receive access to the following electronic logo art files. - [FIDO Leadership](https://fidoalliance.org/overview/leadership/): Executive Council Board Member Representatives Staff Members - [Derivative Certification](https://fidoalliance.org/certification/certification-maintenance-and-updates/derivative-certification/): For Consumer Electronics OEMs or other implementers that will be certifying a large number of implementations that are all based on the same FIDO® Certified implementation, FIDO offers derivative certification. The benefit of derivative certification is that the implementations are not required to go through interoperability testing and each derivative certification is subject to a lower fee than base certifications. - [Certification Maintenance and Updates](https://fidoalliance.org/certification/certification-maintenance-and-updates/): From time to time there are changes to the Certified Authenticator that can affect the FIDO Authenticator Security Requirements. These changes are classified as non-interfering, minor, or major, and relate directly to Derivative, Delta and Recertification. - [FIDO® Trademark and Service Mark Usage Agreement for Manufacturers Implementing FIDO Certified Level 1 Authenticators](https://fidoalliance.org/fido-trademark-and-service-mark-usage-agreement-for-manufacturers-implementing-fido-certified-level-1-authenticators/): Purpose: This Trademark Usage Agreement allows the licensee to display the FIDO Certified logo on products that bundle one or more FIDO Level 1 Certified Authenticators. The product itself does not have to go through certification, it just has to bundle a Level 1 Certified Authenticator. To display a certification logo for levels other than 1, the end product must go through certification. Bundling is not sufficient. - [Logo Usage and Legal](https://fidoalliance.org/overview/legal/): Visit the Membership Application page to view the Membership Agreement and other information on how to join the FIDO Alliance. - [FIDO Certification Request](https://fidoalliance.org/certification/secretariat/certification-request-agreement/certification-request/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df30004ffc39b0357d42658ce1", false);}catch(v_e){;} - [Certification Program Secretariat](https://fidoalliance.org/certification/secretariat/): FIDO Alliance Certification Program Secretariats play an important role in the certification process. The Program Secretariats are responsible for the implementation, operation, and management of the certification programs of FIDO Alliance. - [FIDO Certification](https://fidoalliance.org/certification/): Certify for UAF, U2F, FIDO2, and Identity Verification with Certification Programs from The FIDO Alliance. Validate requirements, improve deployments, and ensure interoperability. - [FIDO Press Center](https://fidoalliance.org/press-center/): All FIDO NEWS CENTER - [Newsletter Sign-Up](https://fidoalliance.org/newsletter-sign-up/) - [Metadata Service Overview](https://fidoalliance.org/metadata/metadata-service-overview/): The FIDO Alliance Metadata Service (MDS) is a web-based tool where FIDO authenticator vendors can publish metadata statements for FIDO servers to download. This provides organizations deploying FIDO servers with a centralized and trusted source of information about FIDO authenticators. - [User Authentication Specifications Overview](https://fidoalliance.org/specifications/): The FIDO Alliance has published three sets of specifications for simpler, stronger user authentication: FIDO Universal Second Factor (FIDO U2F), FIDO Universal Authentication Framework (FIDO UAF) and the Client to Authenticator Protocols (CTAP). CTAP is complementary to the W3C’s Web Authentication (WebAuthn) specification; together, they are known as FIDO2. - [FIDO Resource Library](https://fidoalliance.org/resource-library/): Use the search bar to find FIDO resources related to specific topics. To search by resource type, use the left-hand navigation bar. - [FIDO-Dev Forum](https://fidoalliance.org/developers/resources/fido-dev-forum/): We encourage developers to leverage this independent industry resource: fido-dev community - [Biometric Dashboard](https://fidoalliance.org/certification/functional-certification/biometric-dashboard/) - [Authenticator Level 3+](https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-3-plus/): Authenticator Certification Level 3+ (L3+) evaluates FIDO Authenticator protection against moderate or high effort software and hardware attacks. The confidence in the Authenticator’s security properties is high and the risk for having a successful attack is mitigated. - [Authenticator Level 3](https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-3/): Authenticator Certification Level 3 (L3) evaluates FIDO Authenticator protection against enhanced-basic effort software and hardware attacks. - [Companion Programs](https://fidoalliance.org/certification/authenticator-certification-levels/fido-authenticator-certification-companion-program/): Companion Programs are independent testing programs that FIDO partners use to lessen the certification burden on vendors. Companion Programs can be found within Security Level 3 and Level 3+. - [FIDO Accredited Biometric Laboratories](https://fidoalliance.org/certification/biometric-component-certification/fido-accredited-biometric-laboratories/): The full accreditation process and requirements for laboratories is defined in the Biometric Laboratory Accreditation Policy. - [Metadata Submission Terms (for Authenticator Vendors)](https://fidoalliance.org/metadata-submission-terms-for-authenticator-vendors/): THESE METADATA SUBMISSION TERMS (“Terms”) govern the submission of Metadata Statements made available by you (“You”) by the Metadata Service (“MDS”), operated by FIDO Alliance, Inc. (“FIDO”).  The specification of the Metadata Statements is defined by FIDO in the FIDO Metadata Statements Specification.  By clicking on the “Accepted and Agreed” button at the bottom of this page, You agree to accept and be bound by these Terms.  If You do not agree to be bound by these Terms (or any part thereof), click on “Do Not Accept” or simply leave this website.  You are not granted permission to use the MDS or provide Metadata Statements and must exit this website immediately. - [Metadata Usage Terms (for Relying Parties or Service Providers)](https://fidoalliance.org/metadata-usage-terms-for-relying-parties-or-service-providers/): THIS METADATA USAGE TERMS (“Terms”) governs your use of Metadata Statements and Table Of Contents (“TOC”) files (collectively “METADATA”) accessed, viewed, downloaded or otherwise received by you (“You”) directly from the Metadata Service (“MDS”), operated by FIDO Alliance, Inc. (“FIDO”).  The specification of the Metadata Statements is defined by FIDO in the FIDO Metadata Statements Specification. Each Metadata Statement is owned and contributed by its respective vendor (“Contributing Vendor”) through the MDS for use by You in accordance with the provisions of these Terms.  The TOC file is owned and made available by FIDO for use by You in accordance with the provisions of these Terms.  The specification of the TOC file is defined by FIDO in the FIDO Metadata Service Specification. By clicking on the “Accepted and Agreed” button at the bottom of this page, You agree to accept and be bound by the terms of these Terms.  If You do not agree to be bound by these Terms (or any part thereof), click on “Do Not Accept” or please leave this website. If You do not agree to be bound by these Terms (or any part thereof), You are not granted permission to use the MDS or METADATA and must exit this website immediately. - [Member Sponsorship and Co-Marketing Opportunities](https://fidoalliance.org/comarketing/): The FIDO Alliance enables identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. Its members are building, deploying, and advancing these technologies to shape the future of identity and authentication.  - [Tool Request Agreement](https://fidoalliance.org/tool-request-agreement/): The FIDO Alliance collects and processes personal data as described in the FIDO Alliance Privacy Policy available here. Tool Requestor shall inform all Tool Requestor personnel interacting with the FIDO Alliance on behalf of Tool Requestor that their business contact information and certain other personal data about such individuals may be collected and processed by the FIDO Alliance in accordance with the Privacy Policy, and that such personal data will be transmitted to the FIDO Alliance in the United States, where the laws may not be as protective of such data as the laws in the country where the data subject resides.  Tool Requestor shall obtain any consent from such individuals to the extent required by law to allow for such processing.  As described in the Privacy Policy, a party located in the European Union or the European Economic Area wishing to exercise rights under the General Data Protection Regulation (“GDPR”) with respect to such Personal Data may contact the Data Protection Officer at help@fidoalliance.org. - [FIDO Certification Request Agreement](https://fidoalliance.org/certification/secretariat/certification-request-agreement/): The FIDO Alliance collects and processes personal data as described in the FIDO Alliance Privacy Policy available here.  Certification Requestor shall inform all Certification Requestor personnel interacting with the FIDO Alliance on behalf of Certification Requestor that their business contact information and certain other personal data about such individuals may be collected and processed by the FIDO Alliance in accordance with the Privacy Policy, and that such personal data will be transmitted to the FIDO Alliance in the United States, where the laws may not be as protective of such data as the laws in the country where the data subject resides.  Certification Requestor shall obtain any consent from such individuals to the extent required by law to allow for such processing.  As described in the Privacy Policy, a party located in the European Union or the European Economic Area wishing to exercise rights under the General Data Protection Regulation (“GDPR”) with respect to such Personal Data may contact the Data Protection Officer at help@fidoalliance.org. - [Member Committees and Special Interest Groups](https://fidoalliance.org/members/committees-and-special-interest-groups/): Committees perform an oversight function, often with delegated authority from the board as defined in their charter. Participation of individuals in committees requires approval from the president and/or board.  - [FIDO Alliance Members](https://fidoalliance.org/members/): Board Level FIDO Members Sponsor Level FIDO Alliance Members Government Level FIDO Members Associate Level FIDO Alliance Members - [Implementer Dashboard](https://fidoalliance.org/certification/functional-certification/implementer-dashboard/) - [Lab Accreditation Request](https://fidoalliance.org/certification/functional-certification/lab-accreditation-request/) - [Password Recovery](https://fidoalliance.org/certification/functional-certification/password-recovery/) - [Certification Account Request](https://fidoalliance.org/certification/functional-certification/certification-account-request/) - [Lab Dashboard](https://fidoalliance.org/certification/functional-certification/lab-dashboard/):   - [Getting Started](https://fidoalliance.org/certification/getting-started/): FIDO Certification is currently available for UAF v1.1, U2F v1.2, and FIDO2 1.0 Specifications for Server, Client, and Authenticator implementations. For FIDO2 and U2F, the transport may be Bluetooth Low Energy, NFC, or USB. - [Authenticator Level 2](https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-2/): Authenticator Certification Level 2 (L2) evaluates FIDO Authenticator protection against basic, scalable attacks. - [Authenticator Level 1](https://fidoalliance.org/certification/authenticator-certification-levels/authenticator-level-1/): Authenticator Certification Level 1 (L1) evaluates FIDO Authenticator protection against basic, at-scale attacks. Being certified to at least Authenticator Certification Level 1 (L1) is required for UAF, U2F, and FIDO2 certification. - [Laboratory Accreditation Process – Security](https://fidoalliance.org/certification/authenticator-certification-levels/accredited-security-laboratories/): FIDO currently accredits Security Labs to perform FIDO Security Evaluations as part of Authenticator Level 1+ and higher Certification. Visit FIDO Accredited Laboratories to view FIDO Accredited labs. - [Authenticator Security Levels](https://fidoalliance.org/certification/authenticator-certification-levels/): The Authenticator Certification Levels introduce Authenticator Security Requirements to the FIDO Certification Program. Authenticators must be certified to at least Authenticator Certification Level 1 (L1) forUAF,U2F, and FIDO2 certification. - [FIDO Certified Showcase](https://fidoalliance.org/fido-certified-showcase/): The FIDO Certified Showcase features FIDO Alliance members and their FIDO Certified products and services. If you're looking to deploy FIDO, visit each company's showcase page to learn about their FIDO Certified products and solutions and how they can help get you on the path to simpler and stronger FIDO authentication. - [Government Use Cases](https://fidoalliance.org/passkey-use-case/government/): Enterprises and governments around the globe are turning to modern online authentication solutions featuring FIDO specifications based on public key cryptography for easier and phishing-resistant authentication. Notably, the Cybersecurity & Infrastructure Security Agency (CISA), a component of the U.S. Department of Homeland Security (DHS), refers to FIDO security keys as the gold standard of MFA1.  - [FIDO 如何工作](https://fidoalliance.org/fido-%e5%a6%82%e4%bd%95%e5%b7%a5%e4%bd%9c/) - [How Passkeys Work](https://fidoalliance.org/how-fido-works/): FIDO authentication uses standard public key cryptography techniques to provide phishing-resistant authentication. During registration with an online service, the user’s client device creates a new cryptographic key pair that is bound to the web service domain. The device retains the private key and registers the public key with the online service. These cryptographic key pairs, called passkeys, are unique to every online service. Unlike passwords, passkeys are resistant to phishing, are always strong, and are designed so that there are no shared secrets. - [Logo Usage & Style Guide](https://fidoalliance.org/overview/legal/logo-usage/): You can download FIDO Alliance logo files for general use here and our style guide here. - [Vendor IDs](https://fidoalliance.org/certification/functional-certification/vendor-ids/): A Vendor ID is a unique identifier assigned by FIDO to each company implementing a UAF Authenticator. It may also be referred to within the FIDO specifications as the AAID, or Authenticator Attestation ID. - [Metadata Service Terms](https://fidoalliance.org/metadata/metadata-service-terms/): THIS METADATA SERVICE TERMS (“Terms”) governs your submission or use of any content, material, data and information made available by, accessed, downloaded or otherwise received by or provided by you directly or indirectly from the Meta Data Service (“MDS”), operated by the FIDO Alliance, Inc. (“FIDO”). BY ACCESSING, VIEWING, DOWNLOADING OR OTHERWISE USING THE MDS, INCLUDING ANY CONTENT, MATERIAL, DATA AND INFORMATION, YOU, FOR YOURSELF AND ON BEHALF OF ANY PERSON, ORGANIZATION, ENTITY, OR EMPLOYER FOR WHICH YOU ARE ACTING, ACKNOWLEDGE THAT ACCESSING, VIEWING, DOWNLOADING OR OTHERWISE USING THE MDS IS SUBJECT TO THE FIDO TERMS OF USE (https://fidoalliance.org/terms-of-use/) AND PRIVACY POLICY (https://fidoalliance.org/privacy-policy/), INCLUDING THESE TERMS.  AND THAT YOU HAVE READ AND UNDERSTAND THESE TERMS, THAT YOU AGREE TO THEM AND THAT YOU INTEND TO BE LEGALLY BOUND BY THEM. IF YOU DO NOT AGREE TO THESE TERMS, YOU ARE NOT GRANTED PERMISSION TO USE THE MDS AND MUST EXIT IMMEDIATELY. - [FIDO Alliance Metadata Service](https://fidoalliance.org/metadata/): The FIDO Metadata Service (MDS) helps ensure you have the information necessary to successfully validate authenticators. As your organization deploys passkeys and FIDO authentication, it is critical to distinguish between trusted, certified authenticators and unverified implementations. - [Certification Request](https://fidoalliance.org/certification-request/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df30004ffc39b0357d42658ce1", false);}catch(v_e){;} - [Certified Logo Violation](https://fidoalliance.org/certified-logo-violation/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df3000852526f30553416ea395", false);}catch(v_e){;} - [Dispute Report](https://fidoalliance.org/dispute-report/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df30000eb44c0833274e58a693", false);}catch(v_e){;} - [Test Tool Access Request](https://fidoalliance.org/test-tool-access-request/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df3000e226da84543b4392959d", false);}catch(v_e){;} - [Vendor ID Request](https://fidoalliance.org/certification/functional-certification/vendor-ids/vendor-id-request/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df3000986e0bfc042742818ac7", false);}catch(v_e){;} - [Submit Interop Registration](https://fidoalliance.org/submit-interop-registration/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df3000a8524f86799e42509fef", false);}catch(v_e){;} - [Interop Registration](https://fidoalliance.org/certification/interoperability-testing/interop-registration/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df300012459d35776a491c97f1", false);}catch(v_e){;} - [Interop Add Implementation](https://fidoalliance.org/interop-add-implementation/): try{f_cbload(true, "c0ezh785.caspio.com", "f8df30008ed4c15219974e5aa406", false);}catch(v_e){;} - [Interop Add Participant](https://fidoalliance.org/interop-add-participant/): Click here to load this Caspio Online Database. - [Vendor ID](https://fidoalliance.org/vendor-id/): Sorry, but your browser does not support frames. - [FIDO Trademark License Agreement: Exhibit B](https://fidoalliance.org/overview/legal/fido-trademark-license-agreement-exhibit-b/): FIDO ALLIANCE (FIDO) Usage Guidelines - [FIDO<sup>®</sup> Certified Products Directory](https://fidoalliance.org/certification/fido-certified-products/): Click here to load this Caspio Cloud Database - [Liaison Partners](https://fidoalliance.org/members/liaison/): The FIDO Alliance is an open industry standards-setting association whose mission aligns closely with organizations around the world. - [FIDO Trademark License Agreement: Exhibit A](https://fidoalliance.org/fido-trademark-license-agreement-exhibit-a/): Do not reproduce these examples. Upon execution of the FIDO Alliance Specification Trademark License Agreement and qualifying to use the appropriate Marks, COMPANY will receive access to all of the electronic logo art files. - [FIDO Certification Mark Usage](https://fidoalliance.org/certification/mark-usage/): Owners of certified implementations are invited and encouraged to use the FIDO® Certified mark and logo to indicate their implementation’s conformance with the FIDO specifications. - [User Authentication Certification Registration](https://fidoalliance.org/certification/functional-certification/certification-submission/): After passing both conformance and interoperability testing, the implementation may be submitted for certification. This requires that the following be submitted: - [Interoperability Testing](https://fidoalliance.org/certification/interoperability-testing/): Interoperability Testing is a required step in the certification process. - [Conformance Self‐Validation Testing](https://fidoalliance.org/certification/functional-certification/conformance/): Conformance self‐validation testing is a required step of the certification process. Self‐validation results are submitted through the corresponding test tools must be confirmed by FIDO’s Certification Secretariat  at least 14 days before attending an interoperability event to ensure that implementations are at least minimally compliant with the specifications. Conformance testing is available for all FIDO protocols. - [Thank You](https://fidoalliance.org/thanks/): Thank you for signing up for the FIDO Alliance newsletter. You will receive an email shortly confirming your submission. - [Privacy Policy](https://fidoalliance.org/privacy-policy/): FIDO ALLIANCE INC (“FIDO ALLIANCE,” “us,” or “we”) is committed to protecting your privacy. This Privacy Policy explains our data practices regarding Personal Data (as defined below) and other information that we collect in connection with: - [Website Terms of Use](https://fidoalliance.org/terms-of-use/): Please carefully read these terms of use and legal restrictions ('Terms') before using this Website. By using this Website, you indicate your agreement to these Terms. If you do not accept these terms and conditions, please do not use this Website. - [Functional Certification: Authenticators/Clients](https://fidoalliance.org/certification/functional-certification/): The FIDO Functional Certification program allows FIDO members and non-members to measure compliance and ensure interoperability among products and services that support FIDO specifications. Companies completing certification may display the FIDO® Certified logo to demonstrate to consumers, customers and partners that they have created a high‐quality, interoperable FIDO implementation that is known to work with other FIDO implementations. - [Contact Us](https://fidoalliance.org/contact/): FIDO Alliance, Inc.3855 SW 153rd DriveBeaverton, OR 97003Phone: +1-503-619-2683 - [Membership Application](https://fidoalliance.org/members/membership-application/): The FIDO Alliance welcomes all organizations interested in helping to create a more secure online ecosystem for users and businesses. Membership allows your organization to participate in the definition of a standard protocol for secure authentication. By participating in developing the technical standard, and in planning and executing the Alliance’s marketing, certification and deployment programs, your organization will gain a thorough understanding of how authentication is evolving to ensure a secure internet for the future. - [Download Authentication Specifications](https://fidoalliance.org/specifications/download/): The latest versions of the FIDO Alliance user authentication specifications are available below. If you are new to FIDO, we recommend you first review the Authentication Specifications overview before proceeding further. - [Working Groups](https://fidoalliance.org/members/working-groups/): The FIDO Alliance has multiple active Working Groups, chartered to facilitate the Alliance’s technical and market adoption objectives. Participation in the working groups is open to all board, sponsor, and government members. - [FIDO Alliance Overview](https://fidoalliance.org/overview/): The FIDO Alliance enables identity technologies that put trust and simplicity at the center of interactions among people, services, and devices. ## Certified - [LoginID iOS SDK](https://fidoalliance.org/showcase/loginid-ios-sdk/): Use LoginID iOS SDK to eliminate traditional passwords for your users while employing strong security using LoginID native capabilities without compromising on the user experience. Once you import and configure our SDK, you will be able to perform high value functions including but not limited to: user registration, authentication, transaction confirmation, and management of your integrations through LoginID dashboard. - [LoginID FIDO Server](https://fidoalliance.org/showcase/loginid-fido-server/): Support FIDO-based passwordless authentication in your website or application by using LoginID headless solution that will handle cryptographic keys, signatures, attestation and more. You will be able to focus your efforts on your front end experience by using LoginID's DirectWeb SDK, or customized backend to backend integrations. LoginID supports multiple methods, and all the latest platform authenticators. - [LoginID Android SDK](https://fidoalliance.org/showcase/loginid-android-sdk/): Use LoginID Android SDK to eliminate traditional passwords for your users while employing strong security using LoginID native capabilities without compromising on the user experience. Once you import and configure our SDK, you will be able to perform high value functions including but not limited to: user registration, authentication, transaction confirmation, and management of your integrations through LoginID dashboard. - [Transmit Security WorkID](https://fidoalliance.org/showcase/transmit-security-workid/): WorkID™ is Transmit Security’s risk-based, passwordless workforce identity and access management solution. Whether logging into a workstation, a company-managed website, or a SaaS application using single sign-on, WorkID provides a consistent, hassle-free process that eliminates passwords for convenient, fast and secure access. Any combination of third-party or included authenticators including OTPs, soft tokens, and FIDO-certified biometrics are combined with real-time threat detection to quickly identify threats then automatically deploy security measures to stop them in their tracks. Administrators get precision control of business policies and risk management tools using a streamlined centralized management console with drag and drop simplicity. - [Transmit Security BindID](https://fidoalliance.org/showcase/transmit-security-bindid/): BindID™ is the industry’s first app-less, strong portable authenticator that uses device-based biometrics for secure, convenient and consistent customer authentication. With one-click to create new or sign into existing accounts, BindID eliminates passwords and the inconveniences of traditional credential-based logins. Shared trust at the user, device, and network levels, allows other biometric-enabled devices such as laptops and tablets to be associated with accounts, provides secure device re-enrollment, and delivers up-to-date profile information across the entire BindID member network. Organizations get an accurate and frictionless customer authenticator that is easy to deploy into any channel and doesn’t require specialized applications. - [Transmit Security FlexID](https://fidoalliance.org/showcase/transmit-security-flexid/): FlexID™ is a cross-channel identity orchestration platform that integrates and manages authentication, fraud detection, and access controls. Business policies, authenticators, fraud systems, and authorization tools can be updated and deployed without changing application code using low code journey editing tools. Centralized policy management and third-party integration consolidates existing identity point solutions into a single pane of glass that simplifies programming, reduces management costs, and provides agility to keep pace with the latest technologies. Comprehensive user and device behavioral analytics is combined with available risk information to detect and mitigate suspicious activity at every step, in every system, and throughout every channel. - [Crayonic](https://fidoalliance.org/showcase/crayonic/): A multifunctional external authenticator usable with any device via USB, Bluetooth, or NFC. Utilizing decentralized step-up biometrics – fingerprint, voice, handwriting – to enable passwordless login and digital signing of documents (QES). All via FIDO without the need to install any additional client app.  - [1Kosmos Inc. BlockID](https://fidoalliance.org/showcase/1kosmos-inc-blockid/): BlockID ensures the identity of an employee requesting access to your systems with their fido2 keys. - [Thales SafeNet eToken FIDO](https://fidoalliance.org/showcase/thales-safenet-etoken-fido/): Thales’s SafeNet eToken FIDO USB device enables organizations to secure cloud adoption and bridge secure access by relying on passwordless FIDO-based authentication. - [Thales SafeNet IDPrime 3940 FIDO smart card](https://fidoalliance.org/showcase/thales/): The SafeNet IDPrime FIDO Smart Card is a dual FIDO-PKI device designed for combined FIDO-PKI-based use cases. Organizations that rely on PKI authentication can use the IDPrime FIDO smart card to facilitate their cloud and digital transformation initiatives by providing their users with a single authentication device for securing access to legacy apps, network domains and cloud services. - [Identiv uTrust FIDO2 Security Keys](https://fidoalliance.org/showcase/identiv/): We’ve launched our new industrial-strength, government-grade uTrust FIDO2 NFC Security Keys, providing simple, strong authentication that eliminates the need for passwords, resists phishing attacks, and protects user credentials. uTrust FIDO2 supports the remote pandemic-era workforce, ensuring the critical data that resides on home-based systems and mobile devices remains highly secure and uncompromised. - [ATKey.Pro](https://fidoalliance.org/showcase/atkey-pro/): ATKey.Pro is built upon the FIPS 140-2 Level 3 Certified Broadcom® BCM5810X microcontroller suited for high security applications, fido2 certified, member of MISA for Azure Active Directory identity and authentication by fingerprint matching. - [LINE Pay](https://fidoalliance.org/showcase/line-pay/): Learn more about the FIDO deployment here: https://fidoalliance.org/a-first-step-to-a-world-without-passwords/ - [Target](https://fidoalliance.org/showcase/target/): Target team members have the option to use FIDO for step-up authentication when accessing external applications. - [StrongKey Tellaro](https://fidoalliance.org/showcase/strongkey-tellaro/): The StrongKey Tellaro is a “crypto swiss-army knife” server to perform cryptographic functions through webservices, while freeing up application developers to focus on business functionality. The Tellaro bundles encryption, tokenization, key management, and strong authentication in an affordable, easy to deploy, easy to use, and easy to manage appliance. Capable of scaling to meet your security needs, the E-series comes standard with a 140-2 Level 2 Trusted Platform Module (TPM) and has a Level 3 Hardware Security Module (HSM) as an available option, while the T-series is equipped with a 140-2 Level 2 TPM and is easily configurable to deploy in tandem with the E-series for greater deployment flexibility. - [Industrial and Commercial Bank of China](https://fidoalliance.org/showcase/industrial-commercial-bank-china/): ICBC's mobile app has officially launched FIDO, which allow Android users to log in and make payment via FIDO-based solution. - [SoftBank Corp.](https://fidoalliance.org/showcase/softbank-corp/): SoftBank Corp., a mobile network operator in Japan, has deployed a new login feature using FIDO Authentication on "My SoftBank PLUS" application where customers can check their monthly fees and subscribe additional data plans. With this new feature, smartphone customers no longer need to enter passwords and can easily login with fingerprints. - [HYPR True Passwordless MFA](https://fidoalliance.org/showcase/hypr-decentralized-authentication/): HYPR True Passwordless MFA - [NC7000-3A-FS](https://fidoalliance.org/showcase/nc7000-3a-fs/): NC7000-3A-FS is compliant with FIDO UAF 1.0. It provides a full lineup of authentication functions using a variety of biometric authentication such as face authentication for clients and servers to realize user-friendliness and safety.Our product offers National Institute of Standards and Technology (NIST), USA, proven accuracy. In 2017, NEC face recognition technology received 1st place for the 4th consecutive time by NIST. - [Crosscert FIDO](https://fidoalliance.org/showcase/crosscert-fido/): Crosscert offers a powerful and convenient alternative authentication solution developed in accordance with FIDO SPECIFICATIONS v1.0, the standard technical specification of FIDO Alliance. Providing a number of authentication token sync features including fingerprints, PIN, voice and face recognition, etc. – Crosscert FIDO is already serviced by a bank, online cyber university, and companies in Korea. And they use more than 10 million per month. - [ThumbSignin Passwordless Authentication Service](https://fidoalliance.org/showcase/thumbsignin-passwordless-authentication-service/): Our vision is to make biometric authentication ubiquitous and accessible to all developers. Hence we have created a SaaS offering that is completely FREE. - [NTT DOCOMO](https://fidoalliance.org/showcase/ntt-docomo/): Japan’s largest mobile network operator NTT DOCOMO, INC. has deployed FIDO Authentication to its millions of customers with Touch ID-equipped iOS devices and FIDO Certified Android devices from Samsung, Fujitsu, Sharp, and Sony Mobile, ensuring that their customers enjoy unprecedented choice between platforms, devices and biometric authentication modalities including fingerprint touch, fingerprint swipe, and iris recognition. - [PayPal](https://fidoalliance.org/showcase/paypal/): Founding FIDO Alliance board member PayPal had the first commercial deployment of FIDO Authentication on mobile devices, and has since announced a partnership with Intel and Lenovo to bring FIDO Authentication to laptops. - [Aetna](https://fidoalliance.org/showcase/aetna/): Aetna is now in a multi-year process of rolling out its next-generation authentication (NGA) platform across mobile and web applications. They have adopted passwordless FIDO Authentication with biometrics for their customers’ online account credentials, reducing their reliance on highly vulnerable “shared secrets,” like passwords and one-time-passcodes with strong, unphishable, public key cryptography. - [NELDTV TV Remote](https://fidoalliance.org/showcase/neldtv-tv-remote/): NELDTV TV Remote is a FIDO UAF certified TV Remote control for Bluetooth Low Energy connections. It enables TV users – with the single push of a button – to securely log and transact to their online TV applications without mobile phone. - [Uni-ID App SDK for Android](https://fidoalliance.org/showcase/uni-id-app-sdk-android/): The Uni-ID App SDK for Android enables Android-based mobile applications to leverage FIDO-certified authentication capabilities in an end-to-end framework capable of supporting organizations with internet-scale mobile and web applications. The Uni-ID App SDK for Android allows enterprises to rapidly improve the user-experience across heterogenous device populations and ensures secure implementation of strong authentication by taking advantage of complete scope of FIDO-certified authenticators. TheUni-ID App SDK can secure user information by leveraging Trusted Execution Environments and Secure Elements. - [Uni-ID Authenticator SDK for Android (Overseas)](https://fidoalliance.org/showcase/uni-id-authenticator-sdk-android-overseas/): The Uni-ID Authenticator SDK for Android(Overseas) enables developers to create Authenticator and Authenticator Specific Module(ASM) that can be used by a standalone FIDO Client or embedded into a mobile application in conjunction with the Uni-ID App SDK for Android. Especially The Uni-ID Authenticator SDK for Android(Overseas) is developed for overseas market. - [Uni-ID Authenticator SDK for Android](https://fidoalliance.org/showcase/uni-id-authenticator-sdk-android/): The Uni-ID Authenticator SDK for Android enables developers to create Authenticator and  Authenticator Specific Module(ASM) that can be used by a standalone FIDO Client or embedded into a mobile application in conjunction with the Uni-ID App SDK for Android. - [11st](https://fidoalliance.org/showcase/11st/): 11st is an online marketplace where not only individuals and small merchants but big brand names, department stores, and even supermarket chains also freely interact and engage in commercial transactions. 11st provides customers online and mobile access to quality products at affordable prices, with assurance that all transactions will be carried out in a secure manner. - [ING Bank](https://fidoalliance.org/showcase/ing-bank/): ING Bank’s Xtrong Authentication Suite can be integrated into mobile apps on iOS and Android platforms to allow customers secure, convenient and manageable authentication experience. - [China Minsheng Bank](https://fidoalliance.org/showcase/china-minsheng-bank/): China Minsheng Bank’s app has deployed FIDO authentication solution in both Android and iOS devices. Users could both login and make transactions with both fingerprint and iris. It is also the first bank in the world to make payment with iris via iris-enabled device, e.g. Samsung S8. - [Aware FIDO® Server](https://fidoalliance.org/showcase/aware-fido-server/): Aware FIDO® Server enables a relying party server to offer FIDO-based login from their mobile applications. FIDO® Server encapsulates the FIDO features required at the server, such as maintenance of the FIDO login policies, management of the public keys, and verification of the signatures created on the mobile device. It exposes REST-style web services that can be consumed by a relying party server to enable FIDO functionality.The messages consumed or generated by the FIDO Server are also governed by the FIDO UAF Protocol Specification. A relying party server and mobile applications act as carriers of the UAF protocol messages. - [Aware FIDO® Client](https://fidoalliance.org/showcase/aware-fido-client/): FIDO® Client is the intermediary application that helps to bind FIDO authenticators with the relying party mobile application. A FIDO client can look up all FIDO authenticators on the device, and communicate via JSON messages standardized by the FIDO ASM API. - [Aware FIDO® Face Authenticator](https://fidoalliance.org/showcase/aware-fido-face-authenticator/): FIDO Face Authenticator allows a user to login to a mobile application of a relying party (such as a banking app) using their face for authentication. It provides liveness detection via passive mechanisms and also active interaction with the user, including eye blinking. The captured face never leaves the security boundaries of the authenticator application.Each time the user logs in to the mobile application using FIDO, their face is biometrically verified against the template stored on the device. Once verified, the private key is unlocked from the device and a signature is created on a challenge, which is send to the server. The server verifies the challenge using the stored public key, thus enabling the login process to complete. - [Samsung SDS Nexsign™](https://fidoalliance.org/showcase/samsung-sds-fido/): Samsung SDS's FIDO Certified biometric authentication solutions allow end users to access applications using unique, non-duplicative information such as fingerprint, voice, eye print or facial scan. - [AccessMatrix UAS](https://fidoalliance.org/showcase/accessmatrix-uas/): AccessMatrix™ Universal Authentication Server (UAS) enables organizations to deploy a wide variety of authentication methods to address the business requirements for strong authentication and evolving authentication mechanisms, through a single, unified framework. AccessMatrix™ UAS, FIDO UAF Certified, is a future-proof authentication infrastructure. It supports multiple authentication mechanisms for strong authentication and authorization requirements. - [DIGIPASS SecureClick](https://fidoalliance.org/showcase/digipass-secureclick/): DIGIPASS SecureClick is a FIDO U2F certified device for both USB and Bluetooth Low Energy connections. DIGIPASS SecureClick enables users – with the single push of a button – to securely complete access to their online applications on PCs. One simple solution means users can connect anywhere to everywhere easily, quickly and securely without the burden of having to remember multiple passwords. - [Bluink Key](https://fidoalliance.org/showcase/bluink-key/): Bluink Key is a FIDO U2F authenticator and password manager that lets you securely log in to anything using your smartphone. - [SYNOCHIP SecureFP FIDO® Authenticator](https://fidoalliance.org/showcase/synochip-securefp-fido-authenticator/): SYNOCHIP SecureFP FIDO® Authenticator has the following core benefits and capabilities: - [mFIDO](https://fidoalliance.org/showcase/mfido/): The mFIDO U2 token by Century Longmai is a specially designed FIDO U2F authenticator relying on high-security, public-key cryptography to any website that supports the FIDO U2F protocol, such as Gmail, Google Apps, GitHub, Dropbox, and Salesforce. Meanwhile, mFIDO doesn’t require any client software, middleware or traditional CA (certificate authority) mechanism. One mFIDO U2 token could be applied in multiple online working environment and it is high security level and easy-to-manage identity authentication product. - [IdentityX](https://fidoalliance.org/showcase/identityx/): IdentityX® is a universal mobile biometric authentication platform that verifies a person is who they claim to be using biometrics such as their face, voice, and fingerprint. IdentityX deploys biometrics with a combination of device binding, geolocation, liveness detection, and more to facilitate a seamless authentication experience that is inherently multi-factor. With an eye toward the future, IdentityX allows for easy integration of new technology and biometric modalities as they become available. Integrate IdentityX once and it becomes your shopping cart for innovation, allowing our customers to innovate while they authenticate. - [TouchEn OnePass](https://fidoalliance.org/showcase/touchen-onepass/): TouchEn OnePass FIDO-based biometric authentication system provides an end-to-end, secure integrated authentication system which does not rely on user IDs and passwords. Providing a secure and convenient user authentication experience – TouchEn OnePass is already deployed by numerous banks, financial institutions, and companies, as well as with all three mobile telecom providers in Korea. - [nebulaACCESS](https://fidoalliance.org/showcase/nebulaaccess/): ADAPTATIVE MULTIFACTOR DYNAMIC AUTHENTICATION (ADAPTATIVE MFA) Protect your operations without hindering access for authorised users. nebulaACCESS presents multiple easy-to-use robust authentication options for users, from both workstations and when on the move. - [CloudGateUNO](https://fidoalliance.org/showcase/cloudgateuno/): CloudGate UNO is Single Sign On Service for public cloud service such as G Suite, Office 365 and more.  CloudGate UNO protects customer's information asset by access restriction rules on CloudGate UNO. CloudGate UNO provides a practical and affordable solution to these challenges with strong multi-factor authentication options. These include support for FIDO U2F protocols for physical hardware tokens like the Yubico Yubikey. - [BC Card](https://fidoalliance.org/showcase/bc-card/): BC Card provides FIDO Authentication services to the financial industry in Korea.  Its offerings leverage FIDO authentication to strengthen the security and safety of Samsung Pay in Korea and also the BC Pay offline mobile payment service. - [eBay](https://fidoalliance.org/showcase/ebay/): eBay has built FIDO Authentication into their mobile apps on iOS and Android in order to provide their customers with stronger, simpler authentication. - [GitHub](https://fidoalliance.org/showcase/github/): GitHub, the leading software developers community with 11 million global users and 27 million projects, has built FIDO Authentication into their authentication system in order to protect GitHub’s millions of users and their volumes of sensitive data. - [FastMail](https://fidoalliance.org/showcase/fastmail/): FastMail supports FIDO Authentication via FIDO U2F to provide their users with simpler, stronger, second-factor authentication. - [HyperFIDO Mini](https://fidoalliance.org/showcase/hyperfido-mini/): HyperFIDO Mini is one of the most popular FIDO certified security key in the market, provided by Hypersecu Information Systems Inc. The mini design makes it fit any computer or laptop easily, and the LED built-in button provides a solid and confident feeling every time user presses it. - [TrulySecure](https://fidoalliance.org/showcase/trulysecure/): TrulySecure represents the culmination of over 20 years of Sensory’s industry leading experience in the biometric space. Consistent with FIDO standards, TrulySecure is an on-device biometric authenticator that does not require a cloud connection. TrulySecure allows application developers concerned about both security and convenience to quickly and easily deploy a FIDO compliant multimodal voice and vision authentication solution for mobile phones, tablets, and PC applications. TrulySecure is secure and user friendly – offering greater convenience and security over pins and passwords. Ideal for online banking, mobile transactions and mobile wallets, TrulySecure combines face and voice biometrics for user authentication and offers more than twice the security of single mode biometric systems, without requiring any costly biometric scanners. - [Bank of America](https://fidoalliance.org/showcase/bank-of-america/): Bank of America's iOS and Android apps support FIDO Authentication, which enables users to log into their accounts with their fingerprint. - [Facebook](https://fidoalliance.org/showcase/facebook/): Facebook users can now leverage FIDO Authentication via Facebook's support of Security Keys to enable simpler, stronger, second-factor authentication. - [StonePASS](https://fidoalliance.org/showcase/stonepass/): Under the premise that any system can be susceptible to information leakage, the company has developed a 2-way dynamic key-matching algorithm to guarantee smooth user authentication even in case of user information leakage. This patent-protected technology is the first to integrate all existing security technologies—including password-authentication, online payment, OTP, SMS replacement, bio-authentication, SSO—and to be native to blockchain, cloud computing, mobile, and IoT environments. With SSenStone’s solution, developers no longer need to sweat over adopting multiple authentication technologies for different platforms. - [Wega 3DSA 2.0 Acoustic Card](https://fidoalliance.org/showcase/wega-3dsa-acoustic-card/): With Wega® AuDioCard, validated by MasterCard, and 3DSA 2.0® Strong Authentication Solutions, TRUXTUN Capital provides a universal payments system and smart, trusted and secure solution across all channels, in-store, online and mobile commerce. TRUXTUN Capital is the only company in the market that has developed the familiar and convenient credit card size form factor into a self-powered, multi-purpose electronic transaction and identity authentication device which offers the highest level of security available today. - [Google](https://fidoalliance.org/showcase/google/): Google for Work and Google Gmail users can protect their accounts with FIDO Authentication using a Security Key for strong, simple two-factor access. - [Salesforce](https://fidoalliance.org/showcase/6134/): Salesforce integrated FIDO Authentication using a second-factor to create a more secure, more convenient alternative to using Salesforce Authenticator or One-Time Passwords (OTP) sent by email or SMS. - [Dropbox](https://fidoalliance.org/showcase/6132/): Dropbox users can protect their files, photos and other stored online content using a Security Key for FIDO Authentication. Dropbox's two-step verification works with both its enterprise and consumer products. - [TapID(tm) Mobile Account FIDO U2F NFC Security Card](https://fidoalliance.org/showcase/tapid-mobile-account-fido-u2f-nfc-security-card/): TapID Mobile Account Security Card is FIDO U2F Certified for NFC Contactless Authentication.TapID NFC Card offers strong authentication via FIDO Universal 2nd Factor (U2F) with a simple tap to your NFC-enabled mobile phones. - [SurePassID Auth Server](https://fidoalliance.org/showcase/surepassid-auth-server/): SurePassID’s next-generation identity, cloud and mobile security solutions are built around our enterprise-class multi-factor authentication server. We support the widest range of authentication methods and devices, including passwordless and transparent FIDO UAF and U2F methods. Whether you require secure access to enterprise, web or mobile applications or connected IoT devices; or need to address regulatory compliance with PCI DSS, HIPAA/HITECH, Sarbanes-Oxley, NIST 800-53 and PIPEDA, we accomplish it all with simple, scalable and seamless multi-factor authentication. Take a test drive with our free sandbox account and pilot the most advanced authentication server today! - [ePass FIDO®-NFC Security Key](https://fidoalliance.org/showcase/epass-fido-nfc-security-key/): Feitian ePass FIDO® -NFC is a FIDO® alliance certified U2F authentication key. Unlike the traditional second factor authentication devices, FIDO® U2F provides a much more convenient solution to replace or be a plus of traditional password. A single Feitian ePass FIDO® -NFC is able to protect unlimited applications with both USB and NFC communications to meet users’ requirements. Each application will be assigned an individual key pair.Feitian ePass FIDO® -NFC employs high-performance NXP secure elements. Besides generating strong keys pairs for FIDO® U2F application, the JAVA smart card platform in the secure element also provides room for other applications. - [Nok Nok Authentication Server v. 5.1](https://fidoalliance.org/showcase/nok-nok-authentication-server-v-5-1/): The Nok Nok Authentication Server enables an organization to support both UAF and U2F FIDO-certified authentication scenarios from a single, unified solution. Leveraging a REST interface, the Nok Nok Authentication Server can process additional session, risk and transaction signals for enhanced security. The Nok Nok Authentication Server can also support multi-tenancy scenarios to allow an organization to maintain logically different and separate users to co-exist on the same server. - [Nok Nok App SDK for iOS v. 5.0](https://fidoalliance.org/showcase/nok-nok-app-sdk-for-ios-v-5-0/): The Nok Nok App SDK for iOS enables iOS-based mobile applications to leverage FIDO-certified authentication capabilities in an end-to-end framework capable of supporting organizations with internet-scale mobile and web applications. The Nok Nok App SDK for iOS allows enterprises to support a diverse set of authenticators including PINs, Apple Touch ID, and other emerging modalities including the full scope of FIDO-certified, iOS capable authenticators. The Nok Nok App SDK can secure user information by leveraging secure hardware, such as Trusted Execution Environments and Secure Elements, where available. It can be embedded in mobile applications and supports enhanced capabilities such as Out-of-Band Authentication, Risk-Signal Integration and Policy Based Authentication. - [Nok Nok App SDK for Android v. 5.0](https://fidoalliance.org/showcase/nok-nok-app-sdk-for-android-v-5-0/): The Nok Nok App SDK for Android enables Android-based mobile applications to leverage FIDO-certified authentication capabilities in an end-to-end framework capable of supporting organizations with internet-scale mobile and web applications. The Nok Nok App SDK for Android allows enterprises to rapidly improve the user-experience across heterogenous device populations and ensures secure implementation of strong authentication by taking advantage of complete scope of FIDO-certified authenticators. The Nok Nok App SDK can secure user information by leveraging Trusted Execution Environments and Secure Elements. It can be embedded in applications and supports enhanced capabilities such as Out-of-Band Authentication, Risk-Signal Integration and Policy Based Authentication. - [Nok Nok Authenticator SDK for Android](https://fidoalliance.org/showcase/nok-nok-authenticator-sdk-for-android/): The Authenticator SDK for Android enables developers to create an Authenticator Specific Module(ASM) that can be used by a standalone FIDO Client or embedded into a mobile application in conjunction with the Nok Nok App SDK for Android. - [Natural ID™ FS4300 Family of Fingerprint Sensors](https://fidoalliance.org/showcase/natural-id-fs4300-family-of-fingerprint-sensors/): Synaptics Natural ID™ fingerprint sensors provide biometric authentication for smartphones, notebooks, PC peripherals, automotive applicaions, and more. Solutions include Synaptics SentryPoint™ features for industry leading security, advanced matching algorithms and anti-spoofing technology. - [Natural ID™ FS4200 Family of Fingerprint Sensors](https://fidoalliance.org/showcase/natural-id-fs4200-family-of-fingerprint-sensors/): Synaptics Natural ID™ fingerprint sensors provide biometric authentication for smartphones, notebooks, PC peripherals, automotive applications, and more. Solutions include Synaptics SentryPoint™ features for industry leading security, advanced matching algorithms and anti-spoofing technology. - [Natural ID™ VFS6100 Family of Fingerprint Sensors](https://fidoalliance.org/showcase/natural-id-vfs6100-family-of-fingerprint-sensors/): Synaptics Natural ID™ fingerprint sensors provide biometric authentication for smartphones, notebooks, PC peripherals, automotive applications, and more. Solutions include Synaptics SentryPoint™ features for industry leading security, advanced matching algorithms and anti-spoofing technology. - [Natural ID™ VF7500S Family of Fingerprint Sensors](https://fidoalliance.org/showcase/natural-id-vf7500s-family-of-fingerprint-sensors/): Synaptics Natural ID™ fingerprint sensors provide biometric authentication for smartphones, notebooks, PC peripherals, automotive applications, and more. Solutions include Synaptics SentryPoint™ features for industry leading security, advanced matching algorithms and anti-spoofing technology. - [Natural ID VF7500 Family of Fingerprint Sensors](https://fidoalliance.org/showcase/natural-id-vf7500-family-of-fingerprint-sensors/): Synaptics Natural ID fingerprint sensors provide biometric authentication for smartphones, notebooks, PC peripherals, automotive applications, and more. Solutions include Synaptics SentryPoint features for industry leading security, advanced matching algorithms and anti-spoofing technology. - [YubiKey 4 Nano](https://fidoalliance.org/showcase/yubikey-4-nano/): The YubiKey is the original and leading FIDO U2F authenticator, proven at scale by global enterprises and consumers. - [YubiKey 4](https://fidoalliance.org/showcase/yubikey-4/): The YubiKey is the original and leading FIDO U2F authenticator, proven at scale by global enterprises and consumers. - [FIDO U2F Security Key](https://fidoalliance.org/showcase/fido-u2f-security-key/): The YubiKey is the original and leading FIDO U2F authenticator, proven at scale by global enterprises and consumers. - [YubiKey NEO](https://fidoalliance.org/showcase/yubikey-neo/): The YubiKey is the original and leading FIDO U2F authenticator, proven at scale by global enterprises and consumers. - [YubiKey 4C](https://fidoalliance.org/showcase/yubikey-4c/): The YubiKey is the original and leading FIDO U2F authenticator, proven at scale by global enterprises and consumers. - [Feitian MultiPass FIDO® Security Key](https://fidoalliance.org/showcase/feitian-multipass-fido-security-key/): Feitian MultiPass FIDO® Security Key is a device to go beyond the traditional two-factor authentication systems, the built-in three communication interfaces (BLE, NFC, and USB) empower user to select the desired channel and complete a secure FIDO® U2F authentication across any of your client devices in contact or wirelessly, including desktop, notebook, tablet, and smartphone. ## Govt. Deployments - [The State of Michigan’s Department of Technology, Management & Budget (DTMB)](https://fidoalliance.org/government_deployment/the-state-of-michigans-department-of-technology-management-budget-dtmb/) - [France](https://fidoalliance.org/government_deployment/france/) - [United States](https://fidoalliance.org/government_deployment/united-states/) - [Czech Republic](https://fidoalliance.org/government_deployment/czech-republic/) - [Australia](https://fidoalliance.org/government_deployment/australia/) - [United Kingdom](https://fidoalliance.org/government_deployment/united-kingdom/) - [Thailand](https://fidoalliance.org/government_deployment/thailand/) - [Taiwan](https://fidoalliance.org/government_deployment/taiwan/) - [Sweden](https://fidoalliance.org/government_deployment/sweden/) - [South Korea](https://fidoalliance.org/government_deployment/south-korea/) - [Norway](https://fidoalliance.org/government_deployment/norway/) - [Malaysia](https://fidoalliance.org/government_deployment/malaysia/) - [Hong Kong](https://fidoalliance.org/government_deployment/hong-kong/) - [Canada](https://fidoalliance.org/government_deployment/canada/) ## Members ## Companies - [RSA](https://fidoalliance.org/company/rsa/) - [Token2](https://fidoalliance.org/company/token2/) - [LastPass](https://fidoalliance.org/company/lastpass/) - [Authsignal](https://fidoalliance.org/company/authsignal/) - [PONE Biometrics](https://fidoalliance.org/company/pone-biometrics/) - [Kelvin Zero](https://fidoalliance.org/company/kelvin-zero/) - [SmartDisplayer](https://fidoalliance.org/company/smartdisplayer/) - [IDEMIA](https://fidoalliance.org/company/idemia/) - [Swissbit](https://fidoalliance.org/company/swissbit/) - [Hirsch](https://fidoalliance.org/company/hirsch/) - [Hideez Group Inc.](https://fidoalliance.org/company/hideez-group-inc/) - [Ping Identity](https://fidoalliance.org/company/ping-identity/) - [NEOWAVE](https://fidoalliance.org/company/neowave/) - [OCTATCO](https://fidoalliance.org/company/octatco/) - [Ensurity](https://fidoalliance.org/company/ensurity/) - [HID](https://fidoalliance.org/company/hid/) - [Thales](https://fidoalliance.org/company/thales/) - [IntercedeMyID](https://fidoalliance.org/company/intercedemyid/) - [WiSECURE Technologies](https://fidoalliance.org/company/wisecuretech/) - [FEITIAN Technologies](https://fidoalliance.org/company/feitian/) - [Secret Double Octopus](https://fidoalliance.org/company/secret-double-octopus/) - [Authentrend](https://fidoalliance.org/company/authentrend/) - [1Kosmos](https://fidoalliance.org/company/1kosmos/) - [Hanko](https://fidoalliance.org/company/hanko/) - [ISR](https://fidoalliance.org/company/isr/) - [NokNok](https://fidoalliance.org/company/noknok/) - [Vincss.Official](https://fidoalliance.org/company/vincss-official/) - [SOFTGIKEN](https://fidoalliance.org/company/softgiken/) - [Yubico](https://fidoalliance.org/company/yubico/) - [Entersekt](https://fidoalliance.org/company/entersekt/) - [Hypersecu](https://fidoalliance.org/company/hypersecu/) - [Identy](https://fidoalliance.org/company/identy/) - [KeyxenticFido](https://fidoalliance.org/company/keyxenticfido/) - [MKGroup](https://fidoalliance.org/company/mkgroup/) - [Google](https://fidoalliance.org/company/google/) - [HYPR](https://fidoalliance.org/company/hypr/) - [StrongKey](https://fidoalliance.org/company/strongkey/) - [Transmit Security](https://fidoalliance.org/company/transmit-security/) - [LoginID](https://fidoalliance.org/company/loginid/) ## Events - [FIT 2026 (Financial Information Technology)](https://fidoalliance.org/event/fit-2026-financial-information-technology/): The FIDO Alliance will be exhibiting at FIT 2026 – Booth #EA07 The FIDO theme this year is "Trust in the Age of AI Begins with Passkeys" - [Authenticate U.S. 2026](https://fidoalliance.org/event/authenticate-2026/): FIDO Alliance's Authenticate U.S. Conference will take place October 19-21, 2026 at the Omni La Costa Resort & Spa in Carlsbad, California. - [FIDO Sponsored Webinar Series | The Frontline Authentication Gap: What It Means for Mission-Critical Organizations](https://fidoalliance.org/event/fido-sponsored-webinar-the-frontline-authentication-gap-what-it-means-for-mission-critical-organizations/): First Webinar in the Series: The Frontline Authentication Gap: What It Means for Mission-Critical OrganizationsDate: November 3, 2026Time: 10am ET / 4pm CET - [FIDO Sponsored Webinar Series | Closing the Frontline Authentication Gap: From Friction to Secure Access](https://fidoalliance.org/event/fido-sponsored-webinar-closing-the-frontline-authentication-gap-from-friction-to-secure-access/): Second Webinar in the Series:Closing the Frontline Authentication Gap: From Friction to Secure AccessDate: November 10, 2026Time: 10am ET / 4pm CET - [FIDO Seoul Seminar](https://fidoalliance.org/event/2026-fido-alliance-seoul-seminar/): Event Overview - [FIDO Tokyo Seminar](https://fidoalliance.org/event/fido-tokyo-seminar-passkeys-today-and-beyond/): FIDO Alliance, which drives the standardization of technical specifications and certification programs for online authentication that replaces passwords, has decided to hold its 13th seminar since 2014. - [FIDO Hong Kong Seminar](https://fidoalliance.org/event/fido-hong-kong-seminar/): The FIDO Hong Kong Seminar has been scheduled for December 7. The venue location will be announced soon. The seminar is co-hosted by FIDO Alliance & Tradelink, and supported by HK SFC.