Recent academic research has revealed new insights into the security considerations surrounding FIDO2 authentication and synced passkeys, highlighting both the strengths and potential vulnerabilities of current authentication systems. The analysis comes at a time when major technology companies are increasingly adopting passkey technology, with Microsoft reporting login times three times faster than traditional passwords.

Formal methods analysis of the FIDO2 standard has revealed potential weaknesses in the underlying protocols that warrant attention from security professionals. The research particularly focuses on the implementation of synced passkeys, which enable cross-device access through passkey providers. These findings support recent expert warnings about interoperability concerns in FIDO2 implementations.


More

ComputerWeekly: Time to deploy strong authentication, says FIDO

In this ComputerWeekly story, FIDO Alliance CMO Andrew Shikiar explains that with the tools required…

Read More →

Threatpost: Threatpost Survey Says: 2FA is Just Fine, But Go Ahead and Kill SMS

In a Threatpost survey on two-factor authentication, 57% of respondents said hardware tokens like FIDO…

Read More →

The Parallax: Primer: How to lock your online accounts with a security key

This article in The Parallax reports that FIDO Security Keys, FIDO2 and WebAuthn are gaining…

Read More →