12/11/2024 | Press release | Distributed by Public on 12/11/2024 17:12
Traditional password-based authentication methods, once considered the cornerstone of online security, are increasingly failing in the face of sophisticated cyberattacks. Often, the first hurdle in user engagement is the login password. Not only is creating and managing passwords a major annoyance, but the login password is also notoriously vulnerable to data breaches.
To combat this, the FIDO (Fast Identity Online) Alliance is at the forefront of a transformative movement in online security, dedicated to revolutionizing authentication protocols. As the number of data breaches soar, the FIDO Alliance has developed authentication standards that use public key cryptography to create a more secure and user-friendly alternative to traditional passwords and one-time passcodes (OTP) sent by SMS.
FIDO Authentication is a global authentication standard. With FIDO Authentication, traditional authentication methods, such as passwords stored on servers, SMS OTP, and knowledge-based authentication (KBA), are replaced by on-device authentication. This ensures that authentication data remains stored on the user's device - not on a server. Whether your user is a customer or employee, they can now access cryptographic login credentials using local biometrics, PINs, or other mechanisms.
FIDO Authentication offers an interoperable and standardized ecosystem of authenticators. With it, organizations can deploy strong authentication (also known as multi-factor authentication or MFA) for login, without the incremental cost of in-house development.
The availability of FIDO2 passkeys signifies a departure from conventional password-based authentication methods. FIDO2 passkeys offer a passwordless authentication solution that is both highly secure and user-friendly.
At the heart of FIDO2 passkeys lies public key cryptography, an encryption method that uses pairs of cryptographic keys to authenticate users.
When setting up a FIDO2 passkey, a unique pair of keys is generated: a public key stored securely with the online service and a private key retained by the user's device.
During authentication, the user's device signs a challenge issued by the service using the private key, and the service verifies the signature using the stored public key. This process eliminates the need for passwords entirely and is considered phishing-resistant as it greatly reduces the risk of unauthorized access.
In addition to reducing the risk of unauthorized access, FIDO2 passkeys offer the following benefits:
FIDO2 combines the W3C's (World Wide Web Consortium) Web Authentication (WebAuthn) specification and the FIDO Alliance's Client-to-Authenticator Protocol (CTAP). Together, these specifications enable FIDO2 passkeys to seamlessly integrate with web-based authentication workflows. The result is a secure, straightforward, and scalable authentication process.
W3C, WebAuthn, and CTAP work together in the following ways:
FIDO2 passkeys are often referred to as the gold standard in protecting employees and consumers against phishing attacks. Unlike passwords, which can be easily phished or intercepted, FIDO2 passkeys rely on public key cryptography to authenticate users securely. This means that even if a malicious actor attempts to trick someone into providing their passkey through a phishing website or email, the cryptographic nature of FIDO2 passkeys safeguards that sensitive authentication information.
We live in a time when generative AI and machine learning are exploited by fraudsters to create more sophisticated and personalized phishing campaigns. The cryptographic underpinnings of FIDO2 passkeys make them resistant to automated phishing attempts. As an additional security measure, FIDO2 passkeys can be setup to require user interaction at the time of authentication, thwarting malicious bots seeking to exploit vulnerabilities.
By mitigating the risk of phishing attacks, FIDO2 passkeys bolster online security, providing a better user experience and greater peace of mind for business and government organizations.
As a board member of the FIDO Alliance and an active participant in multiple FIDO2 working groups, OneSpan is part of FIDO's initiative to standardize the authentication industry. OneSpan's first addition to its FIDO2 passkey portfolio is DIGIPASS FX1 BIO. This cutting-edge physical passkey with fingerprint scan empowers organizations to embrace passwordless authentication while providing the strongest security against social engineering and account takeover attacks.
OneSpan also offers full FIDO capabilities as part of OneSpan Mobile Security Suite. This means organizations can implement passwordless authentication to enhance both the customer and employee experience. By replacing static passwords with modern capabilities, such as biometrics, organizations can also protect their mobile apps against phishing, adversary-in-the-middle, and replay attacks.
FIDO-certified authentication methods are supported out-of-the box and can work with any of the user's devices (iOS and Android), operating systems, and authenticators. This gives organizations and service providers a plethora of choices on how to approach passwordless authentication.
Learn more about FIDO for passwordless login, including FIDO2, FIDO U2F (universal second factor), and FIDO UAF (universal authentication framework) solutions.
Go passwordless with DIGIPASS FX authenticators. Improve the user experience and thwart account takeover and advanced phishing schemes.
Learn moreHear OneSpan's Field CTO discuss FIDO on this podcast, first published in July 2024 on Expert Insights.