VIA POLITICO Morning Cybersecurity Report 10/6/17

NOW THAT’S WHAT I’M TOKEN ABOUT — The Social Security Administration should let Americans add an extra layer of hack-proof protection to the information they provide the agency, according to a leading cyber-focused lawmaker. In a letter to acting SSA Commissioner Nancy Berryhill, Oregon Sen. Ron Wyden said the agency should let people use physical tokens for two-factor authentication on their accounts. Unlike the most common two-factor approaches — text messages and authenticator apps — these tokens are “resistant to all phishing,” Wyden wrote. He pointed out that the agency had already started moving in this direction by making two-factor authentication mandatory for all accounts in June, and he commended the agency for adding a security feature to its website that would make it harder for cyber criminals to impersonate the government in phishing emails. The logical next step, he wrote, is the token-based Universal 2nd Factor, or U2F, standard. “Given the low cost of implementation and strong additional protection that U2F provides, I urge SSA to consider supporting U2F on an opt-in basis for workers and beneficiaries,” Wyden told Berryhill.

Read the story: https://www.politico.com/tipsheets/morning-cybersecurity/2017/10/06/latest-reported-nsa-cyber-tool-theft-raises-contractor-kaspersky-concerns-222693

Read the letter: https://www.finance.senate.gov/imo/media/doc/100517%20RW%20to%20SSA%20U2F.pdf


More

HYPR: The State of Passwordless Identity Assurance 2026

Crucial Insights Into Identity Threats, Technologies and Trends The sixth annual 2026 State of Passwordless…

Read More →

Computing: Passwordless authentication gaining popularity, Computing research finds

Half of UK IT leaders polled say their organisation is now using passkeys. Passkeys are…

Read More →

Finextra: Deep Dive: Mastercard Verifiable Intent vs Visa Trusted Agent Protocol

Agentic commerce breaks a core assumption of online payments, that a human is directly clicking…

Read More →


123317 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.