FIDO in the News – FIDO Alliance https://fidoalliance.org Open Authentication Standards More Secure than Passwords Thu, 05 Feb 2026 16:01:06 +0000 en-US hourly 1 https://wordpress.org/?v=6.9.1 https://fidoalliance.org/wp-content/uploads/2023/12/cropped-FIDO_Passkey_mark_B-1-32x32.png FIDO in the News – FIDO Alliance https://fidoalliance.org 32 32 Biometric Update: FIDO’s Andrew Shikiar predicts the triumph of wallets in 2026 https://fidoalliance.org/biometric-update-fidos-andrew-shikiar-predicts-the-triumph-of-wallets-in-2026/ Thu, 05 Feb 2026 16:00:59 +0000 https://fidoalliance.org/?p=88421 Passkey champions to develop certification profile as focus turns to digital credentials

At the annual Identity Identity & Policy Forum, it’s a tradition for Andrew Shikiar, CEO of the FIDO Alliance, to reflect on his predictions from the previous year and offer predictions for the coming one. 2025 was a pivotal year for FIDO: passkeys – FIDO’s raison d’etre in recent years – finally became a mainstream authentication method, marking a long-term win for the Alliance.

In his keynote, FIDO Alliance CEO Andrew Shikiar estimates over 4 billion passkeys are now being used to secure sign-ins around the world. “That’s a massive number considering we introduced passkeys in 2022.”

Shikiar’s speech runs through his record on predictions he made at the beginning of 2025, and comes out looking pretty clairvoyant. Major banks have deployed passkeys. “I stood here last year and said 2025 will be the year of passkeys and banking,” Shikiar says. “I was kind of eating my socks on that until around Q4, when all of a sudden basically every major bank in the U.S. passkeys for sign-up.”

]]>
Meta Engineering: No Display? No Problem: Cross-Device Passkey Authentication for XR Devices https://fidoalliance.org/meta-engineering-no-display-no-problem-cross-device-passkey-authentication-for-xr-devices/ Thu, 05 Feb 2026 12:40:00 +0000 https://fidoalliance.org/?p=88419 Meta shares a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices).

  • We’re sharing a novel approach to enabling cross-device passkey authentication for devices with inaccessible displays (like XR devices).
  • Our approach bypasses the use of QR codes and enables cross-device authentication without the need for an on-device display, while still complying with all trust and proximity requirements.
  • This approach builds on work done by the FIDO Alliance and we hope it will open the door to bring secure, passwordless authentication to a whole new ecosystem of devices and platforms.
]]>
The Indian Express: ‘Password resets cost businesses more than they realise’: Zoho exec on ROI of going passwordless https://fidoalliance.org/the-indian-express-password-resets-cost-businesses-more-than-they-realise-zoho-exec-on-roi-of-going-passwordless/ Mon, 22 Sep 2025 19:31:16 +0000 https://fidoalliance.org/?p=86621 The world is rapidly moving away from traditional security methods. With FIDO standards in place, more companies are shifting toward passwordless authentication. Many industry players are already phasing out passwords from their authenticator apps.

In India, the passwordless market is estimated at $411 million in 2024 and projected to reach more than $1.5 billion by 2030. This reflects how businesses are opting for faster, smarter, and safer login experiences. To understand what’s driving this trend and how companies are adapting, indianexpress.com spoke with Chandramouli Dorai, chief evangelist, cyber solutions and digital signatures at Zoho Corp.

]]>
Biometric Update: To build trust in biometrics, Vietnam banks should adopt FIDO passkeys: report https://fidoalliance.org/biometric-update-to-build-trust-in-biometrics-vietnam-banks-should-adopt-fido-passkeys-report/ Mon, 22 Sep 2025 19:30:50 +0000 https://fidoalliance.org/?p=86620 VinCSS has released an industry first report on the authentication experience in apps for Vietnamese banks, and it shows a “strong shift from traditional to modern authentication methods” in the country’s banking ecosystem.

Biometrics rank as the most commonly used authentication methods for high risk transactions. It’s also rated as the most convenient, with 58.3 respondents listing it as such.

As usual, there are corresponding concerns about data privacy. One in three people worry their biometric data or digital credentials could be stolen or faked, leading to identity fraud. One in Authentication data theft is a top fear. “Many users feel that biometric authentication, though widely implemented, still is not secure enough for them or their digital assets.”

]]>
Back End News: HID offers passwordless authentication to support BSP compliance https://fidoalliance.org/back-end-news-hid-offers-passwordless-authentication-to-support-bsp-compliance/ Mon, 22 Sep 2025 19:30:31 +0000 https://fidoalliance.org/?p=86619 HID, a company that provides secure identity solutions, announced the availability of its updated FIDO-certified authentication solutions in the Philippines, to help financial institutions and enterprises comply with the Bangko Sentral ng Pilipinas’ (BSP) new rules on IT risk management under the Anti-Financial Account Scamming Act (AFASA).

BSP requires organizations under its supervision to strengthen fraud management and identity verification by June 25, 2026. The directive calls for the adoption of secure, phishing-resistant methods, such as passwordless authentication through FIDO standards.

The measure comes amid rising online scams and fraud cases in the country. 

]]>
Security Boulevard: Beyond Passwords: A Guide to Choosing the Right Passkey https://fidoalliance.org/security-boulevard-beyond-passwords-a-guide-to-choosing-the-right-passkey/ Mon, 22 Sep 2025 19:25:48 +0000 https://fidoalliance.org/?p=86617 For many market analysts, cybersecurity agencies and authentication experts, passkeys, based on FIDO2 standard protocol, appear as the future proof authentication technology that will become mainstream within the next years.

“By 2027, more than 90% of MFA transactions using a token will be based on FIDO protocols natively supported in IAM tools.”

]]>
Techradar Pro: Millions of Brits to be impacted by UK Gov decision to move away from passwords, 2FA and the replacement is far from perfect https://fidoalliance.org/techradar-pro-millions-of-brits-to-be-impacted-by-uk-gov-decision-to-move-away-from-passwords-2fa-and-the-replacement-is-far-from-perfecttechradar-pro/ Fri, 16 May 2025 16:10:48 +0000 https://fidoalliance.org/?p=85399 The UK government has said it will roll out passkey technology across its digital services later in 2025, aiming to phase out SMS-based verification in favour of a more secure, user-friendly alternative.

Passkeys are unique digital credentials tied to a user’s personal device and offer a way to authenticate identity without the need for traditional passwords or one-time text codes.

Passkeys never leave the device and so cannot be reused across websites, which makes them resistant to phishing and other common attacks.

]]>
Independent: Government to roll out passwords replacement on Gov.UK to boost cyber security https://fidoalliance.org/independent-government-to-roll-out-passwords-replacement-on-gov-uk-to-boost-cyber-security/ Fri, 09 May 2025 15:09:59 +0000 https://fidoalliance.org/?p=85361 The National Cyber Security Centre said moving to digital passkeys to log on to Gov.UK was a vital step in making the tech more ubiquitous.

The Government has announced plans to replace passwords as the way to access Gov.UK, its digital services platform for the public.

In contrast to using a password and then an additional text message or code sent to a user’s trusted device – known as two-factor authentication – passkeys are unique digital keys tied to a specific device that proves the user’s identity when they log in without requiring them to input any further codes.

]]>
Expert Insights: What’s Next For Cybersecurity? 19+ Key Predictions From Security Experts https://fidoalliance.org/expert-insights-whats-next-for-cybersecurity-19-key-predictions-from-security-experts/ Fri, 09 May 2025 15:07:51 +0000 https://fidoalliance.org/?p=85359 At the 2025 RSAC Conference in San Francisco, our team met with dozens of industry experts, cybersecurity professionals, and investors to find out more about the biggest security technologies and trends that are impacting your business. 

Tech-Specific Innovation

While AI was one of the hottest topics at the show, it wasn’t the only topic of discussion; we also heard a lot about the evolving ransomware ecosystem and what organizations need to be doing today to prepare for the arrival of “Q-Day”. 

But perhaps the second-biggest discussion piece was around identity and access security. 

With the rise of AI-powered deepfakes and fraud attempts, we’re seeing more need than ever before for organizations to make the switch from passwords to more secure methods of authentication, such as Passkeys—and many experts were optimistic that this space will see a lot of adoption over the next year. 

Key Insights:

  • Andrew Shikiar, Executive Director and CEO of the FIDO Alliance: “We’re going to see Passkey deployment continue to grow in regulated industries. That’s really important, because addressing the higher assurance use cases and taking passwords out of play there will give greater confidence for more and more companies to deploy Passkeys at scale, which will further accelerate our journey towards putting passwords fully in the rear-view mirror.”

]]>
SC Media: Microsoft moves to default passkey sign-ins https://fidoalliance.org/sc-media-microsoft-moves-to-default-passkey-sign-ins/ Fri, 09 May 2025 15:03:45 +0000 https://fidoalliance.org/?p=85357 Microsoft has officially shifted to passkeys, such as facial recognition, fingerprint scans, and PINs, as the default sign-in method for all new accounts beginning this month, marking its most significant step yet toward a password-free future, according to TechRepublic.

The move coincides with World Password Day and aligns with the tech giant’s broader commitment to the Passkey Pledge, an industry initiative to eliminate passwords in favor of more secure, phishing-resistant login methods. In a blog post, Microsoft executives Joy Chik and Vasu Jakkal emphasized that passkey users are three times more likely to log in successfully than those using passwords. Although existing account holders can still use passwords, Microsoft is nudging them toward using biometrics or PINs by default. Nearly all Windows users already rely on Windows Hello, and the shift is backed by support from industry partners, including Apple and Google, who are also rolling out FIDO-compliant passkey systems across their platforms. The change promises to streamline security and user experience across the board.

]]>
Gov Info Security: UK Government to Roll Out Passkeys Late This Year https://fidoalliance.org/gov-info-security-uk-government-to-roll-out-passkeys-late-this-year/ Thu, 08 May 2025 17:18:09 +0000 https://fidoalliance.org/?p=85308 FIDO-Based Authentication to Replace SMS-Based Verification, Says UK NCSC

The U.K. government is set to replace SMS-based verification systems for digital services with passkeys this year in a bid to shore up cyber defenses.

The initiative will be rolled out by the U.K. National Cybersecurity Center using the open authentication standard Fast IDentity Online, or FIDO, as a more “secure and cost-effective solution.”

“The NCSC considers passkey adoption as vital for transforming cyber resilience at a national scale,” the NCSC said. “In addition to enhanced security and cost savings, passkeys offer users a faster login experience, saving approximately one minute per login when compared to entering a username, password and SMS code,” the agency said.

]]>
NCSC: UK pioneering global move away from passwords https://fidoalliance.org/ncsc-uk-pioneering-global-move-away-from-passwords/ Wed, 07 May 2025 16:49:54 +0000 https://fidoalliance.org/?p=85293 The UK government is set to roll out passkey technology for its digital services later this year as an alternative to the current SMS-based verification system, offering a more secure and cost-effective solution that could save several million pounds annually.

]]>
ID Tech Wire: FIDO Alliance Launches Payment Authentication Working Group https://fidoalliance.org/id-tech-wire-fido-alliance-launches-payment-authentication-working-group/ Tue, 06 May 2025 15:28:15 +0000 https://fidoalliance.org/?p=85266 The FIDO Alliance announced today the launch of a new Payments Working Group (PWG) focused on developing and implementing FIDO authentication solutions specifically for payment use cases. This initiative marks a significant expansion of the organization’s efforts to eliminate password dependencies in critical digital transactions.

The new working group emerges at a time of growing momentum for passwordless authentication in the payments sector. Last year, Visa implemented passkeys for online payments, allowing customers to authorize transactions using biometric authentication rather than traditional passwords.

The Alliance, which now comprises over 250 members, has been steadily expanding its influence across various sectors of digital authentication.

]]>
Biometric Update: It’s World Passkey Day, actually: trust, adoption grows for FIDO credential https://fidoalliance.org/biometric-update-its-world-passkey-day-actually-trust-adoption-grows-for-fido-credential/ Tue, 06 May 2025 15:27:03 +0000 https://fidoalliance.org/?p=85264 World Password Day is no longer. The annual day to promote secure password practices has run its course, and the FIDO Alliance (whose stated mission, to be fair, is to bring the world beyond passwords) has rebranded World Password Day as World Passkey Day – an occasion to celebrate the encrypted FIDO credentials that combine data you possess (a digital key or credential) with a biometric trait (something you are, usually a face or fingerprint).

]]>
PC Mag: RIP Passwords: Microsoft Moves to Passkeys as the Default on New Accounts https://fidoalliance.org/pc-mag-rip-passwords-microsoft-moves-to-passkeys-as-the-default-on-new-accounts/ Tue, 06 May 2025 15:21:48 +0000 https://fidoalliance.org/?p=85262 Anyone setting up a new Microsoft account will soon find they’re encouraged to use a passkey during the sign-up process.

Microsoft introduced passkey support across most of its consumer apps last year, allowing users to sign into their accounts without the need for 2FA methods or remembering long passwords. A year later, it’s removing passwords as the default and encouraging all new signups to use passkeys.

PCMag attempted to sign up for a new Microsoft account on May 2, but it still asked for a password at the time of publication. Microsoft hasn’t shared an exact timeframe for when the change will take place, but you should expect it to happen in the coming days.

This is the first time a new account can be entirely passwordless. Previously, it had to have one alongside your passkey.

In a blog post, Microsoft says 98% of passkey attempts to log in are successful, while passwords are only at 32%. Microsoft is also introducing what it calls a “streamlined” sign-in experience for all accounts that “prioritizes passwordless methods for sign-in and sign-up.” It means some UX design changes to highlight passkey functionality.

]]>
The Verge: Microsoft goes passwordless by default on new accounts https://fidoalliance.org/the-verge-microsoft-goes-passwordless-by-default-on-new-accounts/ Mon, 05 May 2025 13:29:51 +0000 https://fidoalliance.org/?p=85244 After supporting passwordless Windows logins for years and even allowing users to delete passwords from their accounts, Microsoft is making its biggest move yet toward a future with no passwords. Now it will ask people signing up for new accounts to only use more secure methods like passkeys, push notifications, and security keys instead, by default.

The new no-password initiative by Microsoft is accompanied by its recently launched, optimized sign-in window design with reordered steps that flow better for a passwordless and passkey-first experience.

Although current accounts won’t have to shed their passwords, new ones will try and leave them behind by not prompting you to create a password at all:

As part of this simplified UX, we’re changing the default behavior for new accounts. Brand new Microsoft accounts will now be “passwordless by default.” New users will have several passwordless options for signing into their account and they’ll never need to enroll a password. Existing users can visit their account settings to delete their password.

With today’s changes, Microsoft is renaming “World Password Day” to “World Passkey Day” instead and pledges to continue its work implementing passkeys over the coming year. This time last year, the company implemented passkeys into consumer accounts. Microsoft says it’s seeing “nearly a million passkeys registered every day,” and that passkey users have a 98 percent success rate of signing in versus 32 percent for password-based accounts.

]]>
BetaNews: Research confirms consumers are turning to passkeys to protect their accounts https://fidoalliance.org/betanews-research-confirms-consumers-are-turning-to-passkeys-to-protect-their-accounts/ Mon, 05 May 2025 13:28:09 +0000 https://fidoalliance.org/?p=85242 As you’ll already know, today is World Passkey Day and the FIDO Alliance has released an independent study of over 1,300 consumers across the US, UK, China, South Korea, and Japan to understand how passkey usage and consumer attitudes towards authentication have evolved.

The results are encouraging, they find 74 percent of consumers are aware of passkeys and 69 percent have enabled passkeys on at least one of their accounts.

Among those who have used passkeys, 38 percent report enabling them whenever possible. More than half of consumers now believe passkeys are both more secure (53 percent) and more convenient (54 percent) than passwords.

This increase in passkey adoption is likely driven by the shortcomings of passwords. Last year, over 35 percent of people had at least one of their accounts compromised due to password vulnerabilities. In addition, 47 percent of consumers will abandon purchases if they have forgotten their password for that particular account.

To further encourage organizations to embrace the shift to passkeys, the FIDO Alliance has also launched the Passkey Pledge, a voluntary pledge for online service providers and authentication product and service vendors committed to embracing passkeys.

“The establishment and growth of World Passkey Day reflects the fact that organizations of all shapes and sizes are taking action upon the imperative to move away from relying on passwords and other legacy authentication methods that have led to decades of data breaches, account takeovers and user frustration, which imperil the very foundations of our connected society,” says Andrew Shikiar, executive director and CEO of the FIDO Alliance. “We’re thrilled by the fact that over 100 organizations around the world signed our Passkey Pledge, and we are pleased to support the market in their march towards passkeys through a variety of freely available assets, including our market-leading Passkey Central resource center.”

The full report is available from the FIDO Alliance site.

]]>
Cyber Security News: 15 Billion User Gain Passwordless Access to Microsoft Account Using Passkeys https://fidoalliance.org/cyber-security-news-15-billion-user-gain-passwordless-access-to-microsoft-account-using-passkeys/ Mon, 05 May 2025 13:26:49 +0000 https://fidoalliance.org/?p=85240 As the first-ever World Passkey Day replaces the traditional World Password Day, Microsoft joins the FIDO Alliance in celebrating a milestone achievement: over 15 billion online accounts now have access to passwordless authentication through passkeys.

This significant shift marks a turning point in digital security as the tech industry moves decisively away from vulnerable password-based systems.

“The establishment and growth of World Passkey Day reflects the fact that organizations of all shapes and sizes are taking action upon the imperative to move away from relying on passwords and other legacy authentication methods,” said Andrew Shikiar, Executive Director and CEO of the FIDO Alliance. 

]]>
Forbes: Microsoft Warns All Windows Users—Delete Your Password https://fidoalliance.org/forbes-microsoft-warns-all-windows-users-delete-your-password/ Mon, 05 May 2025 13:25:48 +0000 https://fidoalliance.org/?p=85237 Microsoft is on a mission to delete passwords for a billion users, given that “the password era is ending.” The Windows-maker warns users that “bad actors know it, which is why they’re desperately accelerating password-related attacks while they still can.” And those attacks are now making headlines weekly.

The answer is passkeys, which link your account security to your physical device security, which means unless an attacker has access to your hardware and unlock method — biometric or PIN, they can’t bypass a password to login.

More than others, Microsoft is not just promoting passkeys but also password deletion: “If a user has both a passkey and a password, and both grant access to an account, the account is still at risk for phishing. Our ultimate goal is to remove passwords completely and have accounts that only support phishing-resistant credentials.”

The FIDO Alliance, the organization charged with promoting passkeys has taken to the internet airwaves this time around to “launch a Passkey Pledge to further accelerate [the] global movement away from passwords.”

Its latest research found that “over 35% of people had at least one of their accounts compromised due to password vulnerabilities, [and] 47% of consumers will abandon purchases if they have forgotten their password for that particular account. This is significant for passkey adoption, as 54% of people familiar with passkeys consider them to be more convenient than passwords, and 53% believe they offer greater security.”

FIDO has welcomed Microsoft’s password deletion as industry leading. “This is an exciting and seminal milestone as Microsoft is taking passwords out of play for over a billion user accounts,” its CEO Andrew Shikiar told me, “who can now instead leverage user-friendly, phishing-resistant passkeys. Microsoft’s leadership in doing so today will help encourage more service providers to do the same, which moves us collectively closer to the day when passwords are fully in our rear-view mirror.”

]]>
TechRadar: World Password Day 2025: All the news, updates and advice from our experts as it happened https://fidoalliance.org/world-password-day-2025-all-the-news-updates-and-advice-from-our-experts-as-it-happened/ Mon, 05 May 2025 13:22:40 +0000 https://fidoalliance.org/?p=85234 Moving past passwords is improving brand trust

The FIDO Alliance has also recently invited companies to participate in the World Passkey Pledge to create a more secure future, and move past the vulnerability and hassle of passwords.

Simon McNally, Cybersecurity Expert at Thales said, “Passwords have long been a weak link in digital security, forcing consumers and businesses into a frustrating cycle of password resets and potential breaches. We welcome the FIDO Alliance’s commitment to World Passkey Day and its push for a passwordless future. Passkeys provide a seamless and secure authentication experience, eliminating the risks and frustrations associated with traditional passwords.

Passkeys are automatically generated and securely stored, removing the burden of creating and managing complex passwords. They also enhance privacy by allowing authentication without sharing sensitive data, reducing the risk of breaches. As trust in digital security becomes more critical, businesses must prioritise passwordless solutions to protect users and build brand confidence.”

The Passkey Pledge for a Passwordless Future

To commemorate World Password Day (or at it will henceforth be known, World Passkey Day), the FIDO Alliance has released a survey on the usage of passkeys which found that 74% of consumers are aware of passkeys, meaning that consumers are aware of the potential value a passkey login experience can bring. To support this, the survey also found that 69% of consumers have enabled passkeys on at least one of their accounts.

Furthermore, for those who have used passkeys, 38% report enabling them whenever possible suggesting that some consumers already see the added user experience and security benefits passkeys bring. In fact, more than half of consumers believe passkeys are both more secure (53%) and more convenient (54%) than passwords. Many businesses and organizations have already signed the Passkey Pledge, including Amazon, Apple, Google, Microsoft, Samsung, and many more!

A pivotal moment

Andrew Shikiar, executive director and CEO of the FIDO Alliance, commented on both the recent survey, and the Passkey Pledge:

“This year’s World Passkey Day comes at a pivotal moment for user authentication around the world – with a rapidly growing number of service providers (including nearly half of the world’s top 100 websites) offering billions of user accounts the option to sign in with passkeys instead of passwords. Well over 100 organizations have taken the Passkey Pledge, indicating their commitment towards a future free from the risk and burdens of passwords.

Consumers are not only increasingly aware of passkeys, they’re using them more frequently: 69% of respondents to our recent survey are enabling them on at least one account, and 38% are now enabling them whenever possible.

Passkeys are so intuitive to use that once users integrate passkeys, they rarely go back. This is good for consumers who are frustrated by password reliant sign-in processes — 35% of whom said they experienced account compromises as a result of password vulnerabilities last year — and e-commerce retailers alike.

This shift isn’t just about innovation or bottom lines; it’s about rebuilding digital trust and creating a safer, more efficient internet for everyone.”

]]>
MobileIDWorld: Google Developing Passkey Transfer Feature for Android Password Manager https://fidoalliance.org/mobileidworld-google-developing-passkey-transfer-feature-for-android-password-manager/ Fri, 04 Apr 2025 15:21:55 +0000 https://fidoalliance.org/?p=84435 Google is developing a new feature that will allow secure passkey transfers between Android devices through its Google Password Manager service. The functionality, which is currently under development, aims to simplify the process of moving authentication credentials across devices while maintaining security standards. The development follows Google’s recent enhancements to its Password Manager, including improved security features and user interface updates.

The passkey transfer capability is being integrated into Google Password Manager, with recent releases of Google Play Services containing direct references to passkey export and import tools. These developments are part of Google’s broader effort to enhance authentication security and usability on Android platforms. The initiative comes as enterprise adoption of passkeys continues to grow, according to recent FIDO Alliance research.

]]>
Forbes: Google’s Gmail Upgrade—Good And Bad News For 3 Billion Users https://fidoalliance.org/forbes-googles-gmail-upgrade-good-and-bad-news-for-3-billion-users/ Fri, 04 Apr 2025 15:16:47 +0000 https://fidoalliance.org/?p=84433 Just days after Google confirmed it is bringing its next AI upgrade to Gmail, with major privacy implications, there’s more good and bad news for the 3 billion users relying on Google to deliver secure, spam-free email to their phones and computers. It turns out that a dangerous email attack has operated under the radar for years — until now.

First to the good news. Google’s tightening restrictions on the mass delivery of spam emails to your inbox is working and it’s having a devastating impact on the industry spawned to plague you with marketing messages. “Over the last year,” website MarTech says the industry has seen “engagement rates (open and click rates, especially) drop considerably. Their emails only show up in the inboxes of people already engaging with the brand. For most subscribers, the emails are getting flagged as spam.”

]]>
TechRadar: Great news everyone! Google is going to let you transfer your passkeys to a new phone https://fidoalliance.org/techradar-great-news-everyone-google-is-going-to-let-you-transfer-your-passkeys-to-a-new-phone/ Fri, 04 Apr 2025 15:15:34 +0000 https://fidoalliance.org/?p=84431 Google’s password manager may soon allow you to transfer your passkeys to a new phone, making their use as a login tool even easier.

An APK teardown by AndroidAuthority has found that Google might be working on a potential update that would allow you to export passkeys from one device to another.

Password export and import is already a key feature of many of the best password managers, but the same functionality for passkeys would be a huge step forward.

]]>
International Security Journal: Passkeys set to become leading authentication method by 2027, HYPR reports https://fidoalliance.org/international-security-journal-passkeys-set-to-become-leading-authentication-method-by-2027-hypr-reports/ Mon, 31 Mar 2025 14:08:47 +0000 https://fidoalliance.org/?p=84331 HYPR, an Identity Assurance Company, has released the fifth edition of its ‘State of Passwordless Identity Assurance Report.’

The report reveals an increasing misalignment between real-world security risks and outdated authentication methods.

It also highlights the growing risks associated with outdated authentication methods and the rise of new generative AI-related attacks.

However, the report signals a potential turning point in the fight against identity-based attacks, with phishing-resistant authentication methods like FIDO passkeys poised to become the dominant solution within the next two years.

The company states that this is a first in the report’s five-year history.

]]>
Security Info Watch: iProov launches facial biometric MFA support targeting workforce identity theft https://fidoalliance.org/security-info-watch-iproov-launches-facial-biometric-mfa-support-targeting-workforce-identity-theft/ Mon, 31 Mar 2025 14:06:49 +0000 https://fidoalliance.org/?p=84329 This device-independent, FIDO Alliance-certified biometric authentication solution helps organizations mitigate the risk of one of workforce security’s most crucial concerns: account takeover.

iProov today launched iProov Workforce MFA. 

This device-independent, FIDO Alliance-certified biometric authentication solution helps organizations mitigate the risk of one of workforce security’s most crucial concerns: account takeover.

]]>
Forbes: Microsoft Warns 1 Billion Windows Users—Do Not Use Password https://fidoalliance.org/forbes-microsoft-warns-1-billion-windows-users-do-not-use-password/ Mon, 31 Mar 2025 14:03:08 +0000 https://fidoalliance.org/?p=84327 All change for Microsoft. The company has suddenly confirmed a major update “for over 1 billion end users,” as the deletion of passwords for all users becomes real. Your Microsoft password, it warns, “could be easily forgotten or guessed by an attacker,” and it’s now time “to completely remove the password from your account.”

“The password era is ending,” Microsoft warned in December. “Bad actors know it, which is why they’re desperately accelerating password-related attacks while they still can.” With “7,000 attacks on passwords [blocked] per second… almost double from a year ago,” the company is on a mission to “convince a billion users to love passkeys.”

A passkey replaces password and two-factor authentication (2FA) codes with account authentication linked to your hardware devices or devices and secured by the same security that unlocks that device, most likely your fingerprint or your face. Unlike passwords, this means a passkey cannot leak or be stolen as it requires that physical hardware device. And unlike 2FA, it cannot be intercepted or bypassed.

]]>
IT News: Over 200,000 myGov users disable passwords in passkey shift https://fidoalliance.org/it-news-over-200000-mygov-users-disable-passwords-in-passkey-shift/ Mon, 17 Mar 2025 23:52:22 +0000 https://fidoalliance.org/?p=84209 New figures reveal that over 200,000 users of myGov password stopped using passwords in favour of exclusively using passkeys as their login method by the end of last year.

]]>
Mobile ID World: VicRoads Implements Passkeys Authentication System for Enhanced Digital Security https://fidoalliance.org/mobile-id-world-vicroads-implements-passkeys-authentication-system-for-enhanced-digital-security/ Mon, 17 Mar 2025 13:06:32 +0000 https://fidoalliance.org/?p=84203 VicRoads, Victoria’s road transport authority, has implemented a passkeys authentication system as part of its digital security enhancement initiative, marking a significant step in Australia’s broader transition toward advanced digital identity solutions. The new system moves away from traditional password-based authentication methods toward a more secure passwordless approach, following similar changes by major technology providers like Microsoft in recent months.

]]>
The Payers: Fime secures FIDO IDV certification for identity verification https://fidoalliance.org/the-payers-fime-secures-fido-idv-certification-for-identity-verification/ Mon, 17 Mar 2025 13:05:34 +0000 https://fidoalliance.org/?p=84201 Fime’s testing laboratories in both EMEA and Taiwan have obtained full accreditation under the FIDO Alliance Identity Verification (IDV) Certification Programme.

This certification allows the company to assess and validate identity verification vendors’ Document Authenticity and Face Verification solutions, contributing to fraud prevention efforts while ensuring compliance with industry standards.

Growing concerns over deepfakes drive standardisation 

The introduction of FIDO’s IDV Programme comes in the context of increasing concerns about AI-driven fraud. According to the official press release, despite over 70 billion digital identity verification checks conducted in 2024, more than half of users remain worried about the risks posed by deepfakes and other fraudulent activities. The programme establishes a unified accreditation process to ensure remote identity verification solutions are secure and resistant to manipulation. 

A representative from Fime stated that remote identity verification is essential for sectors such as banking and digital ID enrolment, given the rapid advancements in deepfake technology. The official highlighted the importance of FIDO IDV Certification in helping service providers ensure that their vendors deliver reliable, validated solutions capable of protecting users and mitigating risk. 

Officials from the FIDO Alliance emphasised that the certification programme is designed to strengthen security during onboarding and enrolment processes. They noted that, alongside biometric component certification, this initiative aims to reduce reliance on traditional passwords while enhancing security and user experience.

]]>
Help Net Security: Goodbye passwords? Enterprises ramping up passkey adoption https://fidoalliance.org/help-net-security-goodbye-passwords-enterprises-ramping-up-passkey-adoption/ Mon, 17 Mar 2025 13:04:21 +0000 https://fidoalliance.org/?p=84199 87% of companies have, or are in the midst of, rolling out passkeys with goals tied to improved user experience, enhanced security, and compliance, according to the FIDO Alliance.

Key findings

Enterprises understand the value of passkeys for workforce sign-ins. Most decision makers (87%) report deploying passkeys at their companies. Of these, 47% report rolling out a mix of device-bound passkeys (on physical security keys and/or cards) and synced passkeys (synced securely across the user’s devices).

Organizations are prioritizing passkey rollouts to users with access to sensitive data and applications, including the three most commonly cited priority groups: Those requiring access to IP (39%), users with admin accounts (39%), and users at the executive level (34%). Organizations leverage communication, training, and documentation within these deployments to increase adoption.

Passkey deployments are linked to significant security and business benefits. Respondents report moderate to strong positive impacts on user experience (82%), security (90%), help center call reduction (77%), productivity (73%), and digital transformation goals (83%).

Groups that do not have active passkey projects cite complexity (43%), costs (33%), and lack of clarity (29%) about implementation as reasons. This signals a need for increased education for enterprises on rollout strategies to reduce concerns, as there is a correlation between these perceived challenges and the proven benefits of passkeys.

]]>
Get With IT Podcast: The State of Passkey Adoption https://fidoalliance.org/get-with-it-podcast-the-state-of-passkey-adoption/ Thu, 13 Mar 2025 17:55:40 +0000 https://fidoalliance.org/?p=84197 In this episode, Jenna Barron interviews Andrew Shikiar, CEO and executive director of FIDO Alliance. They discuss the state of passkey adoption in the industry today and how organizations can prepare for adopting them.

Key talking points include:

  • Why passkeys are more secure than passwords
  • How widespread their adoption is 
  • Ways organizations can prepare for broader passkey adoption

Visit Passkey Central for more resources on passkeys: https://www.passkeycentral.org/home 

]]>
Fime supports fight against identity fraud with FIDO ID verification accreditations https://fidoalliance.org/fime-supports-fight-against-identity-fraud-with-fido-id-verification-accreditations/ Wed, 12 Mar 2025 18:16:25 +0000 https://fidoalliance.org/?p=84195 Fime has achieved full  FIDO Alliance Identity Verification (IDV) Certification Program accreditation across multiple regions. Both the Fime EMEA and Fime Taiwan testing laboratories can now support identity verification vendors in certifying their Document Authenticity and Face Verification solutions, helping combat fraud while enhancing the user experience.

With over 70 billion digital identity verification checks conducted in 2024, a reported 52% of people are still concerned about deepfakes and AI-driven fraud. To address this, FIDO introduced the IDV Program, providing a standardized accreditation that ensures remote digital identity verification solutions are secure, reliable, and fraud resistant. 

]]>
MobileIDWorld: Tech Giants Microsoft, Google, and Apple Drive Global Passkey Adoption with Visa Support https://fidoalliance.org/mobileidworld-tech-giants-microsoft-google-and-apple-drive-global-passkey-adoption-with-visa-support/ Tue, 11 Mar 2025 13:27:22 +0000 https://fidoalliance.org/?p=84142 Major technology companies Microsoft, Google, and Apple are driving widespread adoption of passkeys as an alternative to traditional passwords, leveraging biometric authentication methods like facial recognition and fingerprint scanning for enhanced security and user convenience. The initiative builds on the FIDO Alliance standards that these companies have been developing since 2019.

The initiative, which began with a joint announcement by the three tech giants in 2022, has now reached full implementation across all major platforms. Users can access passkey functionality through their devices’ built-in biometric systems, enabling seamless authentication across various services and applications. Microsoft has recently announced plans to implement passkeys for over one billion users in response to a 200 percent increase in cyberattacks.

]]>
Security Infowatch: How FIDO Can Safeguard Against Advanced Cyber Threats https://fidoalliance.org/security-infowatch-how-fido-can-safeguard-against-advanced-cyber-threats/ Tue, 11 Mar 2025 13:26:35 +0000 https://fidoalliance.org/?p=84140
  •  FIDO as the Future of Authentication: Traditional password-based systems are vulnerable to phishing, credential stuffing, and other cyberattacks. FIDO (Fast Identity Online) uses public key cryptography to deliver phishing-resistant, passwordless authentication.
  • Implementation Roadmap: Organizations should assess current authentication methods, educate stakeholders, select FIDO-compatible solutions, and roll out the technology gradually to maximize security and user adoption.
  • Security Meets Usability: FIDO enhances security and simplifies the user experience with biometrics, hardware tokens, and multi-device passkeys, offering both protection and convenience.
  • ]]>
    Forbes: AI Can Crack Your Passwords Fast—6 Tips To Stay Secure https://fidoalliance.org/forbes-ai-can-crack-your-passwords-fast-6-tips-to-stay-secure/ Tue, 11 Mar 2025 13:25:24 +0000 https://fidoalliance.org/?p=84138 Do you think your trusty 8-character password is safe? In the age of AI, that might be wishful thinking. Recent advances in artificial intelligence are giving hackers superpowers to crack and steal account credentials. Researchers have demonstrated that AI can accurately guess passwords just by listening to your keystrokes. By analyzing the sound of typing over Zoom, the system achieved over 90% accuracy in some cases.

    And AI-driven password cracking tools can run millions of guess attempts lightning-fast, often defeating weak passwords in minutes. It is no surprise, then, that stolen or weak passwords contribute to about 80% of breaches​.

    The old password model has outlived its usefulness. As cyber threats get smarter, it is time for consumers to do the same.

    ]]>
    MobileIDWorld: Google Replacing Gmail SMS Authentication with QR Code Verification System https://fidoalliance.org/mobileidworld-google-replacing-gmail-sms-authentication-with-qr-code-verification-system/ Tue, 11 Mar 2025 13:24:14 +0000 https://fidoalliance.org/?p=84136 Google has announced plans to phase out SMS-based authentication for Gmail accounts in favor of more secure methods like QR code verification and passkeys. The change follows similar moves by other tech giants like Microsoft and Apple to strengthen authentication methods as part of the company’s broader security enhancement initiatives.

    ]]>
    Biometric Update: Passkeys for enterprise report from FIDO says adoption is growing https://fidoalliance.org/biometric-update-passkeys-for-enterprise-report-from-fido-says-adoption-is-growing/ Tue, 11 Mar 2025 13:22:10 +0000 https://fidoalliance.org/?p=84134 A new report from the FIDO Alliance aims to understand the state of passkey deployments by enterprises in the U.S. and UK, including methods for deploying FIDO passkeys, total employees enrolled and perceived barriers to deployment.

    Based on a survey of 400 IT professionals (200 from each country), the report says passkey adoption for employee sign-ins is a high or critical priority for two thirds of respondents, and that the majority of enterprises have “either deployed or are in the midst of deploying passkeys with goals tied to improved user experience, enhanced security and standards/regulatory compliance.”

    ]]>
    Identity Week: New FIDO Alliance report: 87% of enterprises in the U.S. and UK are deploying passkeys https://fidoalliance.org/new-fido-alliance-report-87-of-enterprises-in-the-u-s-and-uk-are-deploying-passkeys/ Tue, 11 Mar 2025 13:18:58 +0000 https://fidoalliance.org/?p=84131 The FIDO Alliance along with underwriters AxiadHID, and Thales today released its State of Passkey Deployment in the Enterprise report, finding that 87% of surveyed companies have, or are in the midst of, rolling out passkeys with goals tied to improved user experience, enhanced security, and compliance.

    ]]>
    Biometric Update: Biometrics connecting ID and payments through digital wallets, apps and passkeys https://fidoalliance.org/biometric-update-biometrics-connecting-id-and-payments-through-digital-wallets-apps-and-passkeys/ Mon, 24 Feb 2025 22:19:08 +0000 https://fidoalliance.org/?p=83982 Biometrics are connecting with payment credentials, whether through numberless credit cards and banking apps or passkeys, as the concrete steps towards linking digital identity and payment systems shows up as a major theme in the week’s most-read stories on Biometric Update. Mastercard announced it will ditch the familiar credit card number in favor of on-device biometrics and tokenization, while everyone in digital wallets, from the EUDI Wallet Consortium to Fime and Mattr to Apple is looking at how to bring together identity and payments, and Visa arguing for the role of passkeys in a converged digital ID and payments ecosystem.

    ]]>
    CPO Magazine: Passkey Authentication and Its Relevant Authentication Standards https://fidoalliance.org/cpo-magazine-passkey-authentication-and-its-relevant-authentication-standards/ Mon, 24 Feb 2025 22:18:30 +0000 https://fidoalliance.org/?p=83980 Passkey authentication replaces traditional passwords with a pair of cryptographic keys—public and private. The private key stays on the user’s device, while the public key sits on the server. During login, the server issues a challenge that only the private key can solve, and the response gets verified using the public key. No passwords are transmitted or stored, which reduces the attack surface significantly. Password leaks and brute-force attempts become non-issues because there is no static secret to steal or guess.

    FIDO2 is a joint initiative by the FIDO Alliance and the World Wide Web Consortium (W3C) aimed at delivering streamlined, strong authentication without relying on passwords. It defines a set of technical components: WebAuthn and CTAP2 (Client to Authenticator Protocol). WebAuthn standardizes how a web application interacts with an authenticator—often a platform feature like a secure enclave on a phone or a hardware security key. CTAP2 governs how that authenticator communicates with the client device, such as a laptop or smartphone.

    ]]>
    HealthcareIT: Passwords Are the Problem: How More Secure Authentication Methods Can Transform Healthcare Workflows https://fidoalliance.org/healthcareit-passwords-are-the-problem-how-more-secure-authentication-methods-can-transform-healthcare-workflows/ Mon, 24 Feb 2025 22:17:24 +0000 https://fidoalliance.org/?p=83978 Username and password authentication is a fixture in healthcare but one that continues to hinder operations and put patient privacy – and care – at risk. In just the first three months of 2024, there were over 116 data breaches in the healthcare industry, allowing cybercriminals to access private patient data, medications, clinical records, Social Security numbers, and more by employing tactics like phishing emails and malware.

    As a result, passwordless authentication is steadily gaining traction, enabling healthcare facilities to implement more secure user verification and streamline access management.

    The transition to passwordless won’t happen overnight. However, we can expect continued adoption of passwordless methods over the next decade, as the challenges of traditional passwords become too glaring to ignore in this mission-critical industry.

    ]]>
    Health Management: The Future of Healthcare Security: Embracing Passwordless Authentication https://fidoalliance.org/health-management-the-future-of-healthcare-security-embracing-passwordless-authentication/ Mon, 24 Feb 2025 22:13:02 +0000 https://fidoalliance.org/?p=83976 Traditional username and password authentication remains a standard practice in healthcare, but it increasingly compromises operational efficiency, patient privacy and care quality. In the first quarter of 2024 alone, over 116 data breaches exposed sensitive patient data, including medications, clinical records and Social Security numbers. Cybercriminals use tactics like phishing and malware to exploit these vulnerabilities, underscoring the need for stronger authentication measures. As a response, passwordless authentication is gaining traction, offering a more secure and streamlined approach to access management. Although the transition will take time, the next decade will likely see widespread adoption of passwordless solutions as the limitations of passwords become too costly to ignore.

    ]]>
    Thales Launches FIDO Key Management Solution for Enterprise Passwordless Authentication https://fidoalliance.org/thales-launches-fido-key-management-solution-for-enterprise-passwordless-authentication/ Wed, 12 Feb 2025 23:39:48 +0000 https://fidoalliance.org/?p=83884 Thales has unveiled a new solution designed to streamline the deployment and management of FIDO security passkeys for large-scale implementations. The OneWelcome FIDO Key Lifecycle Management solution enables organizations to efficiently manage the complete lifecycle of FIDO keys while transitioning to passwordless authentication systems. The launch follows Thales’ previous efforts in passwordless authentication, expanding their enterprise security portfolio.

    The solution provides IT teams with comprehensive control over FIDO key management, from initial enrollment through to eventual revocation. By allowing IT departments to pre-register keys and handle lifecycle management tasks, the platform helps reduce the burden on end users while maintaining security standards. The approach supports recent FIDO Alliance guidelines for enterprise passkey implementation, which emphasize the importance of streamlined deployment processes.

    A key feature of the solution is its integration with Microsoft Entra ID through FIDO2 provisioning APIs, enabling organizations to pre-register Thales FIDO keys for their users. The integration is particularly relevant for enterprises using Microsoft 365, providing secure authentication capabilities from initial deployment. The feature arrives as Microsoft implements mandatory multi-factor authentication across its enterprise platforms.

    ]]>
    Yuno Rolls Out Mastercard Payment Passkey in Latin America to Combat Fraud and Streamline Checkouts https://fidoalliance.org/yuno-rolls-out-mastercard-payment-passkey-in-latin-america-to-combat-fraud-and-streamline-checkouts/ Wed, 12 Feb 2025 13:49:56 +0000 https://fidoalliance.org/?p=83877 Global payments orchestrator Yuno is launching the Mastercard Payment Passkey Service across Latin America, enabling merchants in the region to streamline online checkout processes and enhance fraud protection.

    Following the launch by Yuno, merchants in Brazil, Argentina, and Chile can replace increasingly vulnerable traditional authentication methods, such as one-time passwords, with Mastercard Payment Passkey Service, which uses device-based biometrics, such as fingerprints and facial recognition already available on smartphones, to authenticate purchases.

    Mastercard Payment Passkey Service also leverages tokenisation technology to ensure that sensitive data is never shared with third parties and remains useless to fraudsters in the event of a data breach, making transactions even more secure.

    This technology promises to not only boost the security of online transactions, but also to significantly reduce cart abandonment rates by increasing convenience for merchants’ customers.

    ]]>
    Goodbye to manual card entry: Mastercard reveals when the new era of one-click online payments begins https://fidoalliance.org/goodbye-to-manual-card-entry-mastercard-reveals-when-the-new-era-of-one-click-online-payments-begins/ Wed, 12 Feb 2025 13:49:00 +0000 https://fidoalliance.org/?p=83875 Changes are on the way for online shopping and e-commerce. The traditional way of paying for items online by typing in your credit card details (card number and CVV security code) will soon be a thing of the past.

    Mastercard and other card payment companies will be introducing a one-click button that will work on any online platform.

    One of the reasons why services will be moving to a one-click system is to deter hackers who target merchant sites to steal consumer card information. According to a 2023 study by Juniper Research, merchant losses from online payment fraud will exceed $362 billion globally between 2023 to 2028, with losses of $91 billion alone in 2028.

    The one-click system will protect consumers and their online data.

    ]]>
    PayPal Newsroom: Solving the Convenience and Security Equation https://fidoalliance.org/paypal-newsroom-solving-the-convenience-and-security-equation/ Fri, 24 Jan 2025 15:43:45 +0000 https://fidoalliance.org/?p=83763 PayPal has remained at the forefront of the digital payment revolution for more than 25 years by creating innovative experiences that empower over 400 million consumers and merchants to move money easily and securely.

    Safety is a cornerstone of our global operations, and we are committed to protecting our users across the approximately 200 markets that we serve. In this piece, we detail the latest developments in authentication security and share recommendations for policymakers to enable increased safety in the digital economy.

    ]]>
    Analytics Insight: Revolutionizing Digital Security: The Rise of Passkeys https://fidoalliance.org/analytics-insight-revolutionizing-digital-security-the-rise-of-passkeys/ Tue, 21 Jan 2025 17:43:11 +0000 https://fidoalliance.org/?p=83715 The Core of Passkey Technology

    Passkeys, a breakthrough in the realm of digital security, eliminate the vulnerabilities of password-based systems. Utilizing cryptographic key pairs, passkeys are designed to safeguard user identities without relying on shared secrets. The system operates on a challenge-response mechanism: a private key stored securely on the user’s device interacts with a public key on the service provider’s server. This interaction ensures that sensitive credentials are never exposed, making passkeys inherently resistant to phishing attempts and credential theft.

    This technology is underpinned by the FIDO2 standard, which comprises WebAuthn and the Client-to-Authenticator Protocol (CTAP). WebAuthn facilitates seamless integration of passkeys into web applications, while CTAP supports communication between devices and authenticators, ensuring flexibility and security. Together, these components offer a standardized and robust framework for passwordless authentication across various platforms.

    ]]>
    TechRadar: Passwords out, passkeys in: The future of secure authentication https://fidoalliance.org/techradar-passwords-out-passkeys-in-the-future-of-secure-authentication/ Tue, 21 Jan 2025 17:41:38 +0000 https://fidoalliance.org/?p=83714 Since the inception of the internet, passwords have been the primary authentication factor to gain access to online accounts. Yubico’s recent Global State of Authentication survey of 20,000 employees found that 58 percent still use a username and password to login to personal accounts, with 54 percent using this login method to access work accounts.

    This is despite the fact that 80 percent of breaches today are a result of stolen login credentials from attacks like phishing. Because of this, passwords are widely understood by security experts as the most insecure authentication method that leaves individuals, organizations and their employees around the world vulnerable to increasingly sophisticated modern cyber attacks like phishing.

    ]]>
    MobileIDWorld: Research Reveals Security Implications of FIDO2 and Synced Passkeys https://fidoalliance.org/mobileidworld-research-reveals-security-implications-of-fido2-and-synced-passkeys/ Tue, 21 Jan 2025 17:39:30 +0000 https://fidoalliance.org/?p=83713 Recent academic research has revealed new insights into the security considerations surrounding FIDO2 authentication and synced passkeys, highlighting both the strengths and potential vulnerabilities of current authentication systems. The analysis comes at a time when major technology companies are increasingly adopting passkey technology, with Microsoft reporting login times three times faster than traditional passwords.

    Formal methods analysis of the FIDO2 standard has revealed potential weaknesses in the underlying protocols that warrant attention from security professionals. The research particularly focuses on the implementation of synced passkeys, which enable cross-device access through passkey providers. These findings support recent expert warnings about interoperability concerns in FIDO2 implementations.

    ]]>
    ZDNet: What are passkeys? How going passwordless can simplify your life in 2025 https://fidoalliance.org/zdnet-what-are-passkeys-how-going-passwordless-can-simplify-your-life-in-2025/ Tue, 21 Jan 2025 17:36:35 +0000 https://fidoalliance.org/?p=83712 You probably have a lot of passwords in your life.

    Even with the help of password managers, passwords are becoming more and more of a burden for most people.

    Long gone are the days of being able to use and reuse rubbish passwords like p455w0rd123. Now, all of your online accounts need to be protected by passwords that are complex and unique.

    Also: Passkeys take yet another big step towards killing off passwords

    You also need to be ever vigilant in case one of your many passwords is compromised.

    There’s a better solution: Passkeys.

    ]]>
    Tech Target: Adopt passkeys over passwords to improve UX, drive revenue https://fidoalliance.org/tech-target-adopt-passkeys-over-passwords-to-improve-ux-drive-revenue/ Tue, 21 Jan 2025 17:34:33 +0000 https://fidoalliance.org/?p=83711 The digital economy continues to rely on password-based authentication, but password weaknesses — and human nature — make them horrible for security. Password use also impacts businesses’ bottom lines because every year, forgotten passwords and password resets result in millions of dollars of lost sales and wasted IT staff hours.

    It’s a “password tax” on businesses and consumers that no one can seem to get past.

    As the digital economy has grown, so has the value associated with passwords. As a result, phishing and credential theft continue to run rampant, with stolen credentials sold openly on the dark web.

    To protect people, organizations add more friction and worsen UX. They ask users to create long and complex passwords, change passwords every few months and use MFA. This results in lost sales, reduced company productivity and added costs.

    A secure alternative to the password has emerged: passkeys. This option can strengthen organizations’ security posture because passkeys have the potential to generate billions in revenue and cost savings for businesses.

    ]]>
    Federal Register: Strengthening and Promoting Innovation in the Nation’s Cybersecurity https://fidoalliance.org/federal-register-strengthening-and-promoting-innovation-in-the-nations-cybersecurity/ Tue, 21 Jan 2025 15:33:30 +0000 https://fidoalliance.org/?p=83709 A Presidential Document by the Executive Office of the President on 01/17/2025

    Executive Order on Strengthening and Promoting Innovation in the Nation’s Cybersecurity 

    The WebAuthn standard was called out by name in a new cybersecurity executive order (EO) that was released by the White House – in the final days of the Biden Administration. Among other things, the new EO effectively codifies a previous 2022 policy memo that called for the US government to use only phishing-resistant authentication. 

    ]]>
    Insurance Business: Experts warn NZ businesses to prepare for AI-driven cyber threats https://fidoalliance.org/insurance-business-experts-warn-nz-businesses-to-prepare-for-ai-driven-cyber-threats/ Tue, 21 Jan 2025 14:46:42 +0000 https://fidoalliance.org/?p=83708 Cybersecurity experts are calling on New Zealand businesses to strengthen their defences as cyber threats grow in sophistication.

    Key developments, such as AI-driven phishing, the adoption of digital identity wallets, and the shift to passkey authentication, are reshaping the cybersecurity landscape. These trends, combined with rising attack frequencies, require organisations to adopt proactive measures and align with evolving regulatory standards.

    Global leaders, including experts from Yubico, and local organisations like CERT NZ and the National Cyber Security Centre (NCSC), have identified critical areas of focus for 2025. These include:

    • combating increasingly sophisticated attacks
    • implementing modern authentication methods
    • prioritising board-level involvement in cybersecurity strategies

    ]]>
    Biometric Update: State of passkeys 2025: passkeys move to mainstream https://fidoalliance.org/biometric-update-state-of-passkeys-2025-passkeys-move-to-mainstream/ Tue, 21 Jan 2025 14:44:36 +0000 https://fidoalliance.org/?p=83707 More than 1 billion people have activated at least one passkey according to the FIDO Alliance – an astonishing number that highlights the quick evolution of passkeys from a buzzword to a trusted login method. In just two years, consumer awareness of the technology jumped from 39% to 57%. Let’s see how passkeys have moved to mainstream.

    ]]>
    National Cyber Security Centre: Passkeys: they’re not perfect but they’re getting better https://fidoalliance.org/national-cyber-security-centre-passkeys-theyre-not-perfect-but-theyre-getting-better/ Tue, 21 Jan 2025 14:43:23 +0000 https://fidoalliance.org/?p=83706 Passkeys are the future of authentication, offering enhanced security and convenience over passwords, but widespread adoption faces challenges that the NCSC is working to resolve.

    What’s wrong with passwords – why do we need passkeys?

    Most cyber harms that affect citizens occur through abuse of legitimate credentials. That is, attackers have obtained the victim’s password somehow – whether by phishing or exploiting the fact the passwords are weak or have been reused.

    Passwords are just not a good way to authenticate users on the modern internet (and arguably weren’t suitable back in the 1970s when the internet was used by just a few academics). Adding a strong – phishing-resistant – second factor to passwords definitely helps, but not everyone does this and not every type of Multi-Factor Authentication (MFA) is strong.

    ]]>
    GlobeNewswire: Passwordless Authentication Market to Surpass Valuation of US$ 8,944.3 Million By 2033 https://fidoalliance.org/globenewswire-passwordless-authentication-market-to-surpass-valuation-of-us-8944-3-million-by-2033/ Tue, 21 Jan 2025 14:41:16 +0000 https://fidoalliance.org/?p=83705 Growing enterprise reliance on biometric and token-based authentication propels the passwordless market forward. Providers innovate frictionless FIDO2/WebAuthn solutions, boosting collaboration between fintech, retail, and the public sector, while unresolved interoperability hinders the seamless global rollout of passkey technologies.

    ]]>
    GlobeNewswire: Expanding the API Economy and CIAM with Passkeys, Identity Verification, and Decentralized Identity https://fidoalliance.org/globenewswire-expanding-the-api-economy-and-ciam-with-passkeys-identity-verification-and-decentralized-identity/ Tue, 21 Jan 2025 14:37:56 +0000 https://fidoalliance.org/?p=83704 The study illustrates successful implementations of CIAM solutions across various verticals and use cases. This report’s geographic coverage is global. The study period is 2023-2029, with 2024 as the base year and 2025-2029 as the forecast period.

    The report defines consumer identity and access management (CIAM) as a framework that controls and manages consumer identities, access, and policies across IT infrastructures to protect enterprises from unauthorized and potentially harmful security breaches. CIAM solutions include single sign-on, multi-factor authentication, identity verification, lifecycle management (provisioning, deprovisioning), password management, and compliance management.

    ]]>
    HYPR Unmasks a Fake IT Worker: North Korea Isn’t the Only Threat https://fidoalliance.org/hypr-unmasks-a-fake-it-worker-north-korea-isnt-the-only-threat/ Tue, 21 Jan 2025 14:34:06 +0000 https://fidoalliance.org/?p=83703 Highlights:

    • Fraudulent job applicants posing as IT workers from countries like North Korea have infiltrated organizations, posing significant security risks.
    • HYPR encountered a potential fraud attempt during its onboarding process and successfully thwarted it using its Identity Assurance platform.
    • HYPR’s use of multi-layered identity verification, including biometrics and video verification, helped prevent the fraudulent hire from gaining access to their systems.
    • This issue is not limited to North Korea plots; fake workers and interview fraud are widespread and growing

    ]]>
    Biometric Update: Passkeys build momentum, enabling access to 15 billion online accounts https://fidoalliance.org/biometric-update-passkeys-build-momentum-enabling-access-to-15-billion-online-accounts/ Tue, 17 Dec 2024 00:21:40 +0000 https://fidoalliance.org/?p=83466 FIDO passkey adoption doubles in 2024 as major firms opt for passwordless log-in

    Passkeys are a biometric security trend to watch in 2025. The FIDO Alliance themed its 11th annual FIDO Tokyo Seminar on how passkey adoption is accelerating, with presentations from Google, Sony Interactive Entertainment, Mastercard, and other organizations joining the journey to password-free living. Microsoft has confirmed its advice on how to make people love passkeys – as it sweeps aside a major vulnerability that exposed 400 million Outlook 365 users.

    Major tech brands drive mainstreaming of passkey account log-ins

    In 2024, Amazon made passkeys available to 100 percent of its users and has seen 175 million passkeys created for sign-in to amazon.com globally. Google says 800 million Google accounts now use passkeys, with more than 2.5 billion passkey sign-ins over the past two years and sign-in success rates improving by 30 percent. Sony adopted passkeys for the global Playstation gaming community and saw a 24 percent reduction in sign-in time on its web applications.

    Hyatt, IBM, Target and TikTok are among firms that have added passkeys to their workforce authentication options. More credential management products offering passkey options means more flexibility for consumers.

    Japan joins passkey party in private sector, academia

    The Japanese market showed a notable turn toward passkeys, with Nikkei, Nulab and Tokyu Corporation among firms embracing passwordless authentication technology. Nikkei will deploy passkeys for Nikkei ID as early as February 2025. Tokyu Corporation says 45 percent of TOKYU ID users have passkeys. And Nulab announced a “dramatic improvement in passkey adoption.”

    Academia is helping drive innovation, with teams from Keio University and Waseda University winning acknowledgement for their research and prototypes at a slew of hackathons and workshops.

    And FIDO, of course, is there to offer support, now offering its Passkey Central website resource on passkey implementation in Japanese, so that Japanese companies can take better advantage of its introductory materials, implementation strategies, UX  and design guidelines and detailed roll-out guides.

    The FIDO Japan Working Group, which includes 66 of the FIDO Alliance’s member companies, is now in its 9th year of working to raise passkey awareness in the country.

    ]]>
    Podcast: The Password Problem https://fidoalliance.org/podcast-the-password-problem/ Mon, 16 Dec 2024 14:22:05 +0000 https://fidoalliance.org/?p=83444 In this episode of the Trust Issues podcast, host David Puner sits down with Andrew Shikiar, the Executive Director and CEO of the FIDO Alliance, to discuss the critical issues surrounding password security and the innovative solutions being developed to address them. Andrew highlights the vulnerabilities of traditional passwords, their susceptibility to phishing and brute force attacks, and the significant advancements in passwordless authentication methods, particularly passkeys. He explains how passkeys, based on FIDO standards, utilize asymmetric public key cryptography to enhance security and reduce the risk of data breaches. 

    The conversation also covers the broader implications of strong, user-friendly authentication methods for consumers and organizations, as well as the collaborative efforts of major industry players to make the internet a safer place. Additionally, Andrew highlights the importance of identity security in the context of these advancements, emphasizing how robust authentication methods can protect personal and organizational data. 

    Tune in to learn about the future of authentication and the steps being taken to eliminate the reliance on passwords.

    ]]>
    Finextra: Thought Leadership: The Future of Payment Authentication https://fidoalliance.org/finextra-thought-leadership-the-future-of-payment-authentication/ Thu, 21 Nov 2024 14:01:58 +0000 https://fidodev.wpengine.com/?p=83044 In this PREDICT 2025 USA interview, Andrew Shikiar, Executive Director and CEO, FIDO Alliance, discusses how the industry has been exploring the death of the password for decades, how this conversation has evolved and where we are with passkeys today – pinpointing why making progress with eliminating dependence on passwords is of paramount importance.

    Watch the interview with Andrew Shikiar on “The Future of Payment Authentication.”

    ]]>
    CISA: USDA Stops Credential Phishing with FIDO Authentication https://fidoalliance.org/cisa-usda-stops-credential-phishing-with-fido-authentication/ Wed, 20 Nov 2024 20:18:24 +0000 https://fidodev.wpengine.com/?p=83041 As the saying goes, malicious actors don’t break in—they log in. There’s a significant truth in that statement. Today, many organizations struggle to protect their staff from credential phishing, a challenge that’s only grown as attackers increasingly execute “MFA bypass” attacks. 

    In an MFA bypass attack, threat actors use social engineering techniques to trick victims into providing their username and password on a fake website. If victims are using “legacy MFA” (such as SMS, authenticator apps, or push notifications), the attackers simply request the MFA code or trigger the push notification. If they can convince someone to reveal two pieces of information (username and password), they can likely manipulate them into sharing three (username, password, and MFA code or action). 

    Make no mistake—any form of MFA is better than no MFA. But recent attacks make it clear: legacy MFA is no match for modern threats. So, what can organizations do? Sometimes a case study can answer that question.

    Today, CISA and the USDA are releasing a case study that details the USDA’s deployment of FIDO capabilities to approximately 40,000 staff. While most of their staff have been issued government-standard Personal Identity Verification (PIV) smartcards, this technology is not suitable for all employees, such as seasonal staff or those working in specialized lab environments where decontamination procedures could damage standard PIV cards. This case study outlines the challenges the USDA faced, how they built their identity system, and their recommendations to other enterprises. Our personal favorite recommendation: “Always be piloting”.

    FIDO authentication addresses MFA-bypass attacks by using modern cryptographic techniques built into the operating systems, phones, and browsers we already use. Single sign-on (SSO) providers and popular websites also support FIDO authentication. 

    ]]>
    Practical Ecommerce: Passkeys Gain Traction with Ecommerce Shoppers https://fidoalliance.org/practical-ecommerce-passkeys-gain-traction-with-ecommerce-shoppers/ Wed, 20 Nov 2024 19:15:52 +0000 https://fidodev.wpengine.com/?p=83036 Passkeys allow users to log in to their secure accounts without passwords. Ecommerce businesses were first in line when the FIDO Alliance introduced passkeys in 2022. The trade association, which stands for Fast ID Online, launched in 2012 with a mission to reduce the world’s password reliance.

    Andrew Shikiar, executive director of FIDO, said the past two years have been momentous for members and ecommerce businesses. “You want to attract customers to your site and protect them from account takeover, credential stuffing, and phishing attacks,” he said. “That’s why PayPal, eBay, Amazon, Walmart, Best Buy, and other ecommerce companies were the earliest adopters of passkey payments.”

    Shikiar noted that passkey awareness has risen from 39% in 2022 to 57% in 2024, according to a FIDO survey of 10,000 consumers in the U.S., U.K., France, Germany, Australia, Singapore, Japan, South Korea, India, and China.

    ]]>
    ARC Advisory Group: Wireless Broadband Alliance Integrates OpenRoaming with FIDO Device Onboard to Enable Zero-Touch Framework for IoT Device Onboarding https://fidoalliance.org/arc-advisory-group-wireless-broadband-alliance-integrates-openroaming-with-fido-device-onboard-to-enable-zero-touch-framework-for-iot-device-onboarding/ Mon, 18 Nov 2024 15:33:15 +0000 https://fidodev.wpengine.com/?p=82969 The Wireless Broadband Alliance (WBA), the global industry body dedicated to improving Wi-Fi standards and services, announced a new framework for WBA integrating OpenRoaming and FIDO Device Onboard (FDO). This initiative is intended to enable a seamless and secure zero-touch onboarding process for Internet of Things (IoT) Wi-Fi devices.

    ]]>
    Fast Company: Say Goodbye to Passwords https://fidoalliance.org/fast-company-say-goodbye-to-passwords/ Mon, 18 Nov 2024 15:30:49 +0000 https://fidodev.wpengine.com/?p=82968 It’s been a couple of years since Apple, Google, and Microsoft started trying to kill the password, and its demise seems more likely than ever.

    The FIDO Alliance, the industry group spearheading the passkey push, is putting out some much-needed guidelines to make passkeys usage feel more consistent from one site to the next, and the big tech platforms are getting better at letting you store passkeys in your preferred password manager. Work is also underway on a protocol to let people securely switch between password managers and take all their passkeys with them.

    All this is contributing to an air of inevitability for passkeys, especially as major e-commerce players such as Amazon and Shopify get on board. Even if you’re not fully attuned to the passkey movement, you’ll soon have to go out of your way to avoid it.

    “Within the next three to five years, virtually every major service will offer consumers a passwordless option,” says Andrew Shikiar, the FIDO Alliance’s CEO and executive director.

    ]]>
    Daily Mail: Top 10 passwords used in the United States revealed – stop using them immediately if they’re yours https://fidoalliance.org/daily-mail-top-10-passwords-used-in-the-united-states-revealed-stop-using-them-immediately-if-theyre-yours/ Fri, 15 Nov 2024 20:25:47 +0000 https://fidodev.wpengine.com/?p=82964 Experts discovered the top 10 overused passwords in the US that could put you at risk of being easily hacked.

    NordPass and NordSteller recently released its sixth annual analysis of personal password habits.

    Based on NordPass and NordStellar’s data they crunched, ‘secret’ was the most common password in the US.

    The management platforms found that the password was used 328,831 times, and it would take less than one second for someone to crack it.

    ‘Secret’ is also ranked in the top 10 most common passwords in the world.

    Andrew Shikiar, executive director of FIDO Alliance, mentioned hackers could guess the password if it’s even spelled using numbers or with other substitutions while speaking with CNBC.

    ‘For example, they might believe that “secret” is a weak password but “s3cr3t” will be hard to guess,’ Shikiar said in 2019. 

    ]]>
    The Associated Press: One Tech Tip: Replacing passwords with passkeys for an easier login experience https://fidoalliance.org/the-associated-press-one-tech-tip-replacing-passwords-with-passkeys-for-an-easier-login-experience/ Thu, 14 Nov 2024 14:18:40 +0000 https://fidodev.wpengine.com/?p=82928 You might have noticed that many online services are now offering the option of using passkeys, a digital authentication method touted as an easier and more secure way to log in. 

    Some 20% of the world’s top 100 websites now accept passkeys, said Andrew Shikiar, CEO of the FIDO Alliance, an industry group that developed the core authentication technology behind passkeys.

    Passkeys first came to the public’s attention when Apple added the technology to iOS in 2022. They got more traction after Google started using them in 2023. Now, many other companies including PayPal, Amazon, Microsoft and eBay work with passkeys. There’s a list on the FIDO Alliance website.

    Still, some popular sites like Facebook and Netflix haven’t started using them yet.

    Passkey technology is still in the “early adoption” phase but “it’s just a matter of time for more and more sites to start offering this,” Shikiar said.

    ]]>
    Biometric Update: Mastercard replacement of OTPs with passkeys and Click to Pay reaches APAC https://fidoalliance.org/biometric-update-mastercard-replacement-of-otps-with-passkeys-and-click-to-pay-reaches-apac/ Tue, 12 Nov 2024 20:28:17 +0000 https://fidodev.wpengine.com/?p=82910 Mastercard is enabling faster and more convenient online transactions with its newest feature, Mastercard Click to Pay, launching in the Asia-pacific region.

    The result is that consumers will be able to enjoy one-click checkout across devices, browsers and operating systems, without needing to input one-time passwords (OTPs).

    The feature is enabled by the Mastercard Payment Passkey Service, which allows on-device biometric authentication through facial scans or fingerprints, the same way phones are unlocked.

    ]]>
    The Record: These major software firms took CISA’s secure-by-design pledge. Here’s how they’re implementing it https://fidoalliance.org/the-record-these-major-software-firms-took-cisas-secure-by-design-pledge-heres-how-theyre-implementing-it/ Tue, 12 Nov 2024 20:23:12 +0000 https://fidodev.wpengine.com/?p=82909 The Cybersecurity and Infrastructure Security Agency’s (CISA) secure-by-design pledge has hit its six-month mark, and companies that took the pledge say they’ve made significant security improvements since they signed onto the initiative.

    ]]>
    Security Boulevard: FIDO: Consumers are Adopting Passkeys for Authentication https://fidoalliance.org/security-boulevard-fido-consumers-are-adopting-passkeys-for-authentication/ Tue, 12 Nov 2024 20:21:29 +0000 https://fidodev.wpengine.com/?p=82908 There appears to be growing momentum behind the use of passkeys as an alternative identity verification tool to passwords, with the familiarity with the technology growing over the past two years while the use of passwords as declined a bit, according to the Fast IDentity Online (FIDO) Alliance.

    In its latest Online Authentication Barometer, FIDO found that support for a number of authentication options – including not just passkeys but also biometrics – is growing.

    Public awareness of passkeys has jumped from 39% in 2022, when the technology was first introduced, to 57% this year. Meanwhile, the use of passwords in various services sectors is dropping. For example, the percentage of people who used a password over a two-month period for financial services dropped from 51% two years ago to 31% this year.

    ]]>
    Retail TouchPoints: The Login Effect: The Role of Customer Authentication Psychology in Retail Success https://fidoalliance.org/retail-touchpoints-the-login-effect-the-role-of-customer-authentication-psychology-in-retail-success/ Tue, 12 Nov 2024 20:19:13 +0000 https://fidodev.wpengine.com/?p=82907 Retail lags in authentication modernization, but not because providers aren’t interested in upgrading. It’s because customers actively reject change. Familiarity, ease of implementation and legacy system compatibility all mean that very few retailers offer anything beyond usernames and passwords, not even two-factor (2FA) and multi-factor authentication (MFA).

    Ecommerce sites have experimented with magic links, an authentication method that is a little higher friction but is still a viable passwordless alternative. Meanwhile, biometric authentication (think fingerprints and facial recognition) is gaining popularity among less technical users, even if it’s simply to unlock their smartphones. Passkeys, another passwordless authentication method, leverage biometrics or a PIN to let consumers confirm a purchase with just a tap or a quick selfie.

    ]]>
    TechRadar: Youth of today say passwords are old news; passkeys are the future https://fidoalliance.org/techradar-youth-of-today-say-passwords-are-old-news-passkeys-are-the-future/ Thu, 07 Nov 2024 13:45:29 +0000 https://fidodev.wpengine.com/?p=82788 Younger generations see passwords as outdated and are opting for passkeys, a FIDO-backed technology offering more secure, passwordless authentication. With increasing support from popular apps and services, young users are helping to drive this transition towards safer, FIDO-endorsed security solutions.

    “Consumer expectations are changing, and this data should serve as a clear call to action for brands and organizations still relying on outdated password systems,” noted Andrew Shikiar, CEO at FIDO Alliance.

    “Consumers are actively seeking out and prefer passwordless alternatives when available, and brands that fail to adapt are losing patience, money, and loyalty – especially among younger generations.”

    “When consumers know about passkeys, they use them. Excitingly, 20% of the world’s top 100 websites and services already support passkeys. As the industry accelerates its efforts toward education and making deployment as simple as possible, we urge more brands to work with us to make passkeys available for consumers. The pace of passkey deployment and usage is set to accelerate even more in the next twelve months, and we are eager to help brands and consumers alike make the shift,” Shikiar concluded.

    ]]>
    ZDNET: Passkeys are more popular than ever. This research explains why https://fidoalliance.org/zdnet-passkeys-are-more-popular-than-ever-this-research-explains-why/ Thu, 07 Nov 2024 13:42:05 +0000 https://fidodev.wpengine.com/?p=82787 The FIDO Alliance’s fourth annual Online Authentication Barometer reveals significant growth in awareness and adoption of passkeys, with 57% of surveyed consumers now familiar with the technology (up from 39% in 2022). As awareness increases, FIDO is urging more brands to adopt passkey support to help combat the rising sophistication of online threats and scams.

    ]]>
    Vox: A world without passwords is in sight https://fidoalliance.org/vox-a-world-without-passwords-is-in-sight/ Sat, 26 Oct 2024 13:31:50 +0000 https://fidodev.wpengine.com/?p=82494 Thanks to passkeys, you may not need to remember a password ever again.

    Apple thinks 249 of my passwords need attention. Some of them have been reused. Some of them have been caught up in data breaches. Some are just bad passwords.

    That’s why, for the past 11 years, a group called the FIDO Alliance has been working to kill passwords — or at least make us less reliant on them. FIDO, short for Fast IDentity Online, wants to make signing into your accounts not only more secure but also, as the name implies, faster and easier. Since its members include Amazon, Apple, Google, Meta, and other architects of our online experience, the FIDO Alliance is in a position to accomplish this, too.

    Whether you’ve realized it or not, FIDO’s efforts have already transformed the way you sign into everything online. You may have noticed a few years ago, for instance, that a lot more sites started requiring something called multifactor authentication, which adds an extra step to the login process, like texting a code to your phone so the site can verify you are you. That was FIDO’s doing.

    But after years of making logging in more difficult but more secure, the alliance recently began a major push to get platforms and people alike to adopt a technology that may just kill passwords altogether: passkeys.

    ]]>
    Android Authority: Passkeys make switching to Android more challenging, but not for long https://fidoalliance.org/android-authority-passkeys-make-switching-to-android-more-challenging-but-not-for-long/ Thu, 17 Oct 2024 13:39:17 +0000 https://fidodev.wpengine.com/?p=82497 The FIDO Alliance is aware of passkey lock-in, and it’s actively working to address that:

    With all relevant operating systems now natively supporting passkeys, companies have been increasingly adopting them as an alternative to passwords. Relying on passkeys minimizes the risk of getting hacked, as users don’t have access to their cryptographic keys, and intercepting them is significantly more challenging. However, those switching between different service providers may prefer traditional passwords, as there’s currently no easy way to import or export passkeys. To minimize the friction separating distinct platforms, the FIDO Alliance is working on a solution that makes moving passkeys between them a breeze.

    The FIDO Alliance has published (via Neowin) a working draft encompassing specifications that would make moving passkeys between providers possible. When implemented, users would be able to securely import and export their passkeys, making switching platforms less challenging. Read more of the article.

    ]]>
    ZDNet: Passkeys take yet another big step towards killing off passwords https://fidoalliance.org/zdnet-passkeys-take-yet-another-big-step-towards-killing-off-passwords/ Tue, 15 Oct 2024 13:43:14 +0000 https://fidodev.wpengine.com/?p=82499 One of the drawbacks to passkeys is that currently there’s no way to import or export them between devices. The FIDO Alliance wants to change that.

    It’s been around two years since passkeys came onto the scene, and the technology has come a long way in making the world a passwordless place. Yet, one feature that’s been absent is the ability to import or export passkeys between devices.

    That is set to change, as the FIDO Alliance — the working group behind the technology — has published a draft specification for Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF) formats that would not only work for the secure transferring of passkeys but also other forms of authentication.

    ]]>
    Bleeping Computer: Amazon says 175 million customers now use passkeys to log in https://fidoalliance.org/bleeping-computer-amazon-says-175-million-customers-now-use-passkeys-to-log-in/ Tue, 15 Oct 2024 13:41:52 +0000 https://fidodev.wpengine.com/?p=82498 Amazon says 175 million customers now use passkeys to log in:

    Amazon has seen massive adoption of passkeys since the company quietly rolled them out a year ago, announcing today that over 175 million customers use the security feature.

    “Today, we’re excited to share that more than 175 million customers have enabled passkeys on their Amazon accounts, allowing them to sign in six-times faster than they could otherwise,” says Amazon.

    ]]>
    MacRumors: https://fidoalliance.org/macrumors/ Tue, 15 Oct 2024 13:36:53 +0000 https://fidodev.wpengine.com/?p=82496 FIDO Alliance Working on Making Passkeys Portable Across Platforms:

    Passkeys are an industry standard developed by the FIDO Alliance and the World Wide Web Consortium, and were integrated into Apple’s ecosystem with iOS 16, iPadOS 16.1, and macOS Ventura. They offer a more secure and convenient alternative to traditional passwords, allowing users to sign in to apps and websites in the same way they unlock their devices: With a fingerprint, a face scan, or a passcode. Passkeys are also resistant to online attacks like phishing, making them more secure than things like SMS one-time codes.

    The draft specifications, called Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF), will standardize the secure transfer of credentials across different providers. This addresses a current limitation where passkeys are often tied to specific ecosystems or password managers.

    ]]>
    Wired: The War on Passwords Is One Step Closer to Being Over https://fidoalliance.org/wired-the-war-on-passwords-is-one-step-closer-to-being-over/ Mon, 14 Oct 2024 13:35:11 +0000 https://fidodev.wpengine.com/?p=82495 Passkeys,” the secure authentication mechanism built to replace passwords, are getting more portable and easier for organizations to implement thanks to new initiatives the FIDO Alliance announced this month.

    At the FIDO Alliance’s Authenticate Conference in Carlsbad, California, on Monday, October 14, researchers are announcing two projects that will make passkeys easier for organizations to offer—and easier for everyone to use. One is a new technical specification called Credential Exchange Protocol (CXP) that will make passkeys portable between digital ecosystems, a feature that users have increasingly demanded. The other is a website, called Passkey Central, where developers and system administrators can find resources like metrics and implementation guides that make it easier to add support for passkeys on existing digital platforms.

    “To me, both announcements are part of the broader story of the industry working together to stop our dependence on passwords,” Andrew Shikiar, CEO of the FIDO Alliance, told WIRED ahead of Monday’s announcements. “And when it comes to CXP, we have all these companies who are fierce competitors willing to collaborate on credential exchange.”

    ]]>
    What is a passkey? Why Apple is betting on password-free tech https://fidoalliance.org/what-is-a-passkey-password-apple-ios-18-google-microsoft-bank/ Tue, 02 Jul 2024 16:22:23 +0000 https://fidodev.wpengine.com/?p=81111 The digital realm has long struggled with the vulnerabilities inherent in password-based authentication systems. With iOS 18 launching in September, Apple introduces a groundbreaking API for developers to implement passkeys, transforming how users secure their online accounts. This innovation is set to create a password-less future, significantly enhancing user data protection.

    What Are Passkeys?

    Passkeys are a sophisticated, passwordless login option for apps and websites developed by the FIDO Alliance. They consist of a “private key” stored on the user’s device and a “public key” residing with the service. This dual-key system undergoes an encrypted verification process, ensuring that access is granted only when the user’s biometrics or device PIN confirm their identity. This system effectively eliminates the need for passwords and multi-factor authentication codes, creating a seamless and secure user experience.

    The Benefits of Passkeys

    Traditional logins rely on passwords, which users often reuse across multiple sites, posing substantial security risks. Passkeys, however, are tied to the user’s unique device and biometric data, rendering them immune to phishing and brute-force attacks. If a passkey is stolen, it becomes useless without the rightful owner’s biometric verification. This intrinsic link between the user and the device significantly mitigates the threat landscape.

    Banks and Passkey Adoption

    While the advantages of passkeys are clear, some industries have been slow to adopt, including banks. Andrew Shikiar, CEO and Executive Director of the FIDO Alliance, explains, “Banks and financial institutions operate in a highly regulated industry, so they are vigilant when it comes to ensuring that user authentication complies with relevant regulations. Synced passkeys introduce a new customer assurance model that compliance leads within banks are still adjusting to.”

    However, Shikiar noted that “we are now seeing regulatory and other government bodies begin to give formal guidance on how industry should contemplate passkeys,” including an April 2024 missive from the U.S. Department of Commerce’s National Institute of Standards and Technology (NIST) offering guidance about implementation.

    But Shikiar says that “banks are hypersensitive to customer experience,” too, and thus more cautious about changing how customers log in—even if passkeys are quicker and more secure. New login methods require educating customers—and that takes time.

    Despite these bottlenecks, Shikiar says that banks are slowly moving away from strictly password-based logins because they “inherently understand that using a passkey as a primary factor is far superior to a password.”

    The Collaborative Future of Passwordless Authentication

    Apple’s implementation of passkeys underlines a collective effort by tech giants within the FIDO Alliance, including Microsoft and Google, to enhance internet security. The Alliance has pioneered developments in authentication standards, striving to eliminate the vulnerabilities of password-based systems. Users can visit the FIDO Alliance to learn more about the ongoing efforts and advancements in passkey technology and the latest in passkey implementation.

    As passkeys gain traction, the internet moves closer to a future where security does not come at the expense of user convenience. The collaborative efforts of industry leaders within the FIDO Alliance signal a transformative shift towards more secure, passwordless authentication methods, promising a safer digital experience for all.

    ]]>
    The Register: AWS is pushing ahead with MFA for privileged accounts. What that means for you. https://fidoalliance.org/the-register-aws-is-pushing-ahead-with-mfa-for-privileged-accounts-what-that-means-for-you/ Mon, 24 Jun 2024 16:20:44 +0000 https://fidodev.wpengine.com/?p=80986 AWS is making multi-factor authentication (MFA) mandatory for privileged users, specifically management account root users and standalone account root users. Customers must enable MFA within a 30-day grace period to maintain account access.

    ]]>
    IT Brew: FIDO Alliance announces identity-proofing certification https://fidoalliance.org/it-brew-fido-alliance-announces-identity-proofing-certification/ Mon, 24 Jun 2024 16:19:12 +0000 https://fidodev.wpengine.com/?p=80985 FIDO’s Face Verification Certification tests for security, liveness, and bias in remote identity verification technology through FIDO-accredited laboratories, and ISO and industry standards. Andrew Shikiar, Executive Director and CEO of the FIDO Alliance, highlights that this certification technology “gives licensing companies added assurance that a vendor is performing well.”

    ]]>
    Find Biometrics: ID Talk: Passkeys, Standards, and Selfie Certification with FIDO’s Andrew Shikiar https://fidoalliance.org/find-biometrics-id-talk-passkeys-standards-and-selfie-certification-with-fidos-andrew-shikiar/ Mon, 24 Jun 2024 16:18:28 +0000 https://fidodev.wpengine.com/?p=80984 Andrew Shikiar, FIDO’s Executive Director and CEO, discusses key topics in authentication and identity security on the ID Talk podcast (produced by Find Biometrics), including passkeys, phishing threats, deepfakes, FIDO’s vendor accreditation, and the new Face Verification Certification program.

    ]]>
    AWS Expands MFA Requirements, Boosting Security and Usability with Passkeys https://fidoalliance.org/aws-expands-mfa-requirements-boosting-security-and-usability-with-passkeys/ Tue, 18 Jun 2024 12:13:59 +0000 https://fidodev.wpengine.com/?p=80963 AWS has announced the introduction of FIDO passkeys for multi-factor authentication (MFA) to further secure customer accounts. This move aligns with AWS’s objective to offer a secure cloud environment by incorporating secure-by-design and safe-by-default principles. FIDO passkeys offer a strong and easy MFA option, leveraging public key cryptography to resist phishing attempts and enhance overall account protection.

    ]]>
    ID Talk Podcast: Passkeys, Standards, and Selfie Certification with FIDO’s Andrew Shikiar https://fidoalliance.org/id-talk-passkeys-standards-and-selfie-certification-with-fidos-andrew-shikiar/ Mon, 17 Jun 2024 17:44:52 +0000 https://fidodev.wpengine.com/?p=80960 The FIDO Alliance, founded in 2012, stands as a pivotal organization in the identity technology sector, advocating for strong passwordless authentication mechanisms. The Alliance has been instrumental in establishing influential industry standards, promoting the adoption of biometrics, and enhancing digital security through two-factor and multi-factor authentication technologies.

    This week, Andrew Shikiar, FIDO’s Executive Director and CEO, joins the ID Talk podcast to discuss critical issues in authentication and identity security. The conversation covers topics such as the intricacies of passkeys, the dangers of phishing and deepfakes, and the comprehensive testing FIDO certified products undergo with independent, accredited labs to gain FIDO certification. Additionally, Shikiar introduces FIDO’s new Face Verification Certification program, aimed at standardizing selfie-based identity verification technologies across various sectors.Gain valuable insights from Andrew Shikiar by tuning into the podcast, available on Soundcloud, Spotify, Apple Podcasts, or using the link below.

    ]]>
    InfoSecurity Magazine: #Infosec2024: CISOs Need to Move Beyond Passwords to Keep Up With Security Threats https://fidoalliance.org/content-cisos-need-to-move-beyond-passwords-to-keep-up-with-security-threats/ Fri, 07 Jun 2024 18:12:09 +0000 https://fidodev.wpengine.com/?p=80848 Passwordless systems, even if they stop short of a full zero-trust environment, improve convenience as well as security. CISOs should look at approaches such as the FIDO model or web 3.0 technologies as a basis for future authentication systems.

    ]]>
    CXMToday: Visa Unveils Card Updates https://fidoalliance.org/cxmtoday-visa-unveils-card-updates/ Fri, 24 May 2024 17:01:36 +0000 https://fidodev.wpengine.com/?p=79823 Built on the latest Fast Identity Online (FIDO) standards, the Visa Payment Passkey Service confirms a consumer’s identity and authorises online payments with a quick scan of their biometrics like a face or fingerprint. When shopping online, Visa passkeys replace the need for passwords or one-time codes, enabling more streamlined, secure transactions.

    ]]>
    Identity Week: State of Michigan’s MiLogin supported by FIDO passkeys https://fidoalliance.org/identity-week-state-of-michigans-milogin-supported-by-fido-passkeys/ Fri, 24 May 2024 17:00:52 +0000 https://fidodev.wpengine.com/?p=79822 The system leverages passkeys based on FIDO authentication promoting strong authentication, unifying Michigan’s approach to cybersecurity and improving the user experience.

    The State of Michigan aimed to address several key objectives with the integration of passkeys, fortifying security and enhancing the digital user experience to access critical state government services.

    ]]>
    FindBiometrics: Visa Brings Passkeys to Online Payments in Major FIDO Victory https://fidoalliance.org/visa-brings-passkeys-to-online-payments-in-major-fido-victory/ Fri, 24 May 2024 16:59:54 +0000 https://fidodev.wpengine.com/?p=79821 Visa has introduced passkeys to the payment industry, enabling customers to authorize online purchases through a biometric scan on their smartphones or computers when making a purchase online.

    This capability is powered by the Visa Payment Passkey Service, which is built on Visa’s Fast Identity Online (FIDO) server. The service allows merchants to integrate the Visa Payment Passkey Service into their checkout systems without needing to establish their own servers, thereby simplifying the setup process.

    For users, this means they can use the same biometric authentication methods they use to unlock their devices to approve Visa payments online, with a one-time enrollment required during checkout. Visa also plans to extend enrollment options to banking apps in the future.

    The development of passkeys was a collaborative effort among major technology companies such as Apple, Google, and Microsoft, which joined forces around 2012 to form the FIDO Alliance. This group aimed to overcome the limitations of traditional passwords by creating open standards for more robust authentication, involving biometric experts like HYPR and Nok Nok Labs.

    FIDO released its first standards in 2014, setting the stage for authentication methods that do not depend on passwords. Subsequent advancements led to the establishment of the WebAuthn standard in 2019, which quickly gained acceptance among major web browsers. This progress facilitated the creation of passkeys, leveraging FIDO protocols to link authentication credentials to users’ mobile biometrics.

    Visa’s recent move has been welcomed by supporters of FIDO and passkeys. HYPR’s co-founder and CEO, Bojan Simic, commented on this development, stating that nearly every regulated business he has interacted with in the past year has included a passkey initiative in their plans in an online post. “I’m so proud of the work that we have all done at the FIDO Alliance to make this a reality. When we wrote the first FIDO implementation in 2014 here at HYPR, seeing the top brands adopt the standard in a major way seemed like fantasy.”

    In making this vision a reality, Visa joins several other prominent companies that have recently introduced support for passkeys, including PayPal, Samsung, and Amazon.

    ]]>
    Tech Radar: Navigating towards a passwordless future https://fidoalliance.org/navigating-towards-a-passwordless-future/ Mon, 20 May 2024 17:28:09 +0000 https://fidodev.wpengine.com/?p=79576 Traditionally, passwords have served as the primary means of securing digital identities, yet their limitations are becoming increasingly evident. To pave the way for a passwordless future, accessibility is paramount. Any alternative authentication method must be inclusive, catering to users across diverse technological environments. Whether it’s the latest smartphone or a dated desktop, the authentication process should seamlessly adapt. For example, solutions like the FIDO Alliance’s Web Authentication (WebAuthn) standard aim to bridge this accessibility gap, enabling passwordless logins across a spectrum of devices and platforms.

    ]]>
    Security Informed: trinamiX Unveils Secure Face Authentication In Foldable Phones https://fidoalliance.org/trinamix-unveils-secure-face-authentication-in-foldable-phones/ Mon, 20 May 2024 17:27:12 +0000 https://fidodev.wpengine.com/?p=79575 This touchless solution offers enhanced security and convenience, meeting the biometric security requirements set by organizations such as the International Internet Finance Authentication Alliance (IIFAA), the FIDO Alliance, and Android (Google).

    ]]>
    The Fintech Times: Visa Reveals Digital Products to be Launched Over the Year Catering to Evolving Consumer Demands https://fidoalliance.org/visa-reveals-digital-products-catering-to-evolving-consumer-demands/ Mon, 20 May 2024 17:26:26 +0000 https://fidodev.wpengine.com/?p=79574 Built on the latest Fast Identity Online (FIDO) standards, the Visa Payment Passkey Service confirms a consumer’s identity and authorises online payments with a quick scan of their biometrics like a face or fingerprint. When shopping online, Visa passkeys replace the need for passwords or one-time codes, enabling more streamlined, secure transactions.

    ]]>
    PYMNTS: Visa Recasts Digital Wallet Landscape at Intersection of Identity and Payments https://fidoalliance.org/pymnts-visa-recasts-digital-wallet-landscape-at-intersection-of-identity-and-payments/ Mon, 20 May 2024 17:25:36 +0000 https://fidodev.wpengine.com/?p=79573 Visa has enhanced their security and streamlined transactions by onboarding passkeys. Now consumers can confirm their identity and authorize online payments through facial or fingerprint scans, eliminating the need for passwords and one-time codes.

    ]]>
    Biometric Update: Authenticate 2024 https://fidoalliance.org/biometric-update-authenticate-2024/ Fri, 17 May 2024 16:35:06 +0000 https://fidodev.wpengine.com/?p=79176 Authenticate 2024
    Omni La Costa Resort & Spa, Carlsbad, CA
    October 14-16, 2024

    It’s time to modernize your authentication! Organizations around the globe are embracing a new way to authenticate with FIDO standards, moving past passwords and legacy forms of multi-factor authentication to provide users with passkeys for phishing-resistant sign-ins. Their results? Strong security, lessened data breach risk, improved user experiences, faster sign-in rates, and reduced costs.

    Join these industry leaders as they come together at Authenticate 2024, and get the latest tools and insights to get your organization on the path to strong, modern passwordless authentication.

    Hosted by the FIDO Alliance, Authenticate is the industry’s only conference dedicated to all aspects of user authentication – including a focus on FIDO-based sign-ins. It is the place for CISOs, business leaders, product managers, security strategists and identity architects to get all of the education, tools and best practices to roll out modern authentication across web, enterprise and government applications.

    Authenticate 2024 will be held at the Omni La Costa Resort & Spa in Carlsbad, California for the second year in a row. This venue includes ample space for our growing audience, more sessions and session types for all levels, and more opportunities for networking with peers. The 2024 event will include our most dynamic expo hall yet, where all exhibiting sponsors can showcase their solutions and meet companies looking for partners on their path to passwordless.

    Whether you are new to FIDO, in the midst of deployment or somewhere in between, Authenticate 2024 will have the right content – and community – for you.

    Register and learn more here.

    ]]>
    Biometric Update: Passkeys continue march to mainstream with Visa, WhatsApp updates https://fidoalliance.org/biometric-update-passkeys-continue-march-to-mainstream-with-visa-whatsapp-updates/ Fri, 17 May 2024 16:22:23 +0000 https://fidodev.wpengine.com/?p=79175 FIDO2 protocol finding wide adoption but analysts may have found MITM vulnerability.

    Visa has unveiled new digital products and services based on biometrics and passkeys, as it aims to address rapid changes in AI and digital identity technology. WhatsApp has expanded its passkey availability for all users. And the FIDO Alliance welcomes a new board member, while researchers question how airtight its security protocol really is.

    ]]>
    The Register: Microsoft, Google do a victory lap around passkeys https://fidoalliance.org/the-register-microsoft-google-do-a-victory-lap-around-passkeys/ Fri, 03 May 2024 16:05:21 +0000 https://fidodev.wpengine.com/?p=78018 Passkeys are based on a FIDO alliance standard that’s supported by Apple, Microsoft and Google. Think of them as password replacements. The tech, simply put, works like this: When you create an account for a website or app, your device generates a cryptographic public-private key pair.

    ]]>
    Silicon Republic: Microsoft and Google are pushing harder for passkeys https://fidoalliance.org/silicon-republic-microsoft-and-google-are-pushing-harder-for-passkeys/ Fri, 03 May 2024 16:04:35 +0000 https://fidodev.wpengine.com/?p=78017 Passkeys have been growing rapidly in popularity. In the UK, for instance, more than half the population has enabled passkeys on at least one of their accounts, according to a FIDO Alliance survey published this week. What’s more, around a fifth have passkeys activated on every account that allows them.

    ]]>
    TechCrunch: Google expands passkey support to its Advanced Protection Program ahead of the US presidential election https://fidoalliance.org/techcrunch-google-expands-passkey-support-to-its-advanced-protection-program-ahead-of-the-us-presidential-election/ Fri, 03 May 2024 16:03:43 +0000 https://fidodev.wpengine.com/?p=78016 Google is introducing passkey support to its Advanced Protection Program (APP), designed for individuals facing elevated risks of targeted attacks, including campaign workers, candidates, journalists, human rights activists, and others. The company reports that passkeys have authenticated users over 1 billion times across more than 400 million Google Accounts since the introduction of passkey support in 2022.

    ]]>
    Microsoft Blog: Microsoft introduces passkeys for consumer accounts https://fidoalliance.org/microsoft-blog-microsoft-introduces-passkeys-for-consumer-accounts/ Thu, 02 May 2024 23:13:21 +0000 https://fidodev.wpengine.com/?p=77971 Ten years ago, Microsoft envisioned a bold future: a world free of passwords. Every year, we celebrate World Password Day by updating you on our progress toward eliminating passwords for good. Today, we’re announcing passkey support for Microsoft consumer accounts, the next step toward our vision of simple, safe access for everyone.

    ]]>