The problem today is that no agreed set of standards exists. We have widely disparate views of what these should be. Everybody has their own favourites. In one camp, we have people who believe the future is a completely new set of digital identity technologies: blockchains, DIDs, new cryptographic algorithms, and the DIDComm protocol stack (which is really little more than S/MIME with onion routing), and those like myself who believe we should build the verifiable credential digital identity eco-system on today’s existing ubiquitous standardised protocols and cryptography, such as X.509, OpenID Connect, W3C Web Authentication (FIDO2) and JWTs.


More

SC Media: OneSpan’s Ashish Jain on why passkeys are ready for prime time in modern banking

Authentication has long required an uneasy tradeoff between strong security and smooth user experience. Banks…

Read More →

Tech Radar: Why strong authentication beyond the browser will define the future of connected devices

The way we interact with technology is no longer confined to the browser. Cars, smart…

Read More →

Security Brief US: RSA expands Microsoft tie-up with passwordless access

RSA has expanded support between RSA ID Plus and Microsoft 365 E7, extending the companies’…

Read More →


123319 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.