Passwords are a form of knowledge-based authentication. For a user to prove they are who they claim to be, they need a secret — the password — that has been previously stored by the service. Multifactor authentication (MFA) is a technique designed to strengthen the authentication process by adding possession-based authentication to knowledge-based authentication. A service can only authenticate a user when they prove they have knowledge of the shared secret in addition to something they have or are. Eliminating shared secrets removes the intrinsic weakness of password-based authentication and MFA. A secure form of possession-based authentication is the best alternative. Passwordless authentication based on FIDO standards is considered the archetype. FIDO passwordless authentication is based on public-key cryptography.


More

Security Insider: The future of user authentication: password methods on the brink of extinction?

For some time now, the ‘big three’ – Google, Apple and Microsoft – have been…

Read More →

IBS Intelligence: Financial services still use passwords – and it’s costing them 

The FIDO Alliance published its second annual Online Authentication Barometer, which gathers insights into the…

Read More →

Business Leader: Post-pandemic security: 79% IT decision-makers want company password manager implemented

According to the Bitwarden survey, roughly half of respondents deploy or have plans to deploy…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.