{"id":231,"date":"2020-10-09T11:32:24","date_gmt":"2020-10-09T11:32:24","guid":{"rendered":"https:\/\/thenextweb.com\/?p=1322565"},"modified":"2020-10-09T11:32:24","modified_gmt":"2020-10-09T11:32:24","slug":"inside-fido-alliances-vision-of-a-future-free-of-passwords","status":"publish","type":"post","link":"https:\/\/www.londonchiropracter.com\/?p=231","title":{"rendered":"Inside FIDO Alliance\u2019s vision of a future free of passwords"},"content":{"rendered":"\n<p>Most services you use on your phone or laptop, from email providers to food delivery providers, require you to have a password. With so many services and websites, it\u2019s hard to come up with unique passwords and remember all of them.<\/p>\n<p>So, a lot of people end up using the same password for multiple services \u2014 and that\u2019s a threat. If one website is compromised, your other accounts can be at risk too. A 2019 Verizon report suggests that <a href=\"https:\/\/www.infosecurity-magazine.com\/blogs\/pwned-passwords-business-risk\/#:~:text=The%20Verizon%202019%20Data%20Breach,were%20utilizing%20already%20compromised%20passwords.\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">80% of hacking-related breaches<\/a> are caused by using weak or compromised passwords.<\/p>\n<p>That\u2019s why the&nbsp;<a href=\"https:\/\/fidoalliance.org\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">FIDO (Fast IDentity Online) Alliance<\/a> is trying to get rid of passwords altogether.<\/p>\n<p>The organization was founded in 2013 by Lenovo, Agnitio, Infineon, Nok Nok Labs, PayPal, and Validity Sensors. Since then a number of big-name partners such as Google, Apple, Microsoft, and Intel have joined the organization to support a password-less&nbsp;future.<\/p>\n<p>I talked to Andrew Shikiar, executive director of the FIDO Alliance, and its partner and hardware security key maker&nbsp;Yubico, about authentication without passwords through the FIDO2 standard. But before we look at what companies are doing to allow users to login to services in different ways, let\u2019s look at what FIDO2 is and how it works.<\/p>\n<h2>What is FIDO2?<\/h2>\n<p>To solve the problem of authentication through passwords, the&nbsp;World Wide Web Consortium (W3C) and FIDO Alliance came up with the FIDO2 standard. It\u2019s a combination of W3C\u2019s Web Authentication (WebAuthn) specification and FIDO Alliance\u2019s corresponding Client-to-Authenticator Protocol (CTAP). This allows you to use your phone or laptop to identify yourself safely to a web service.<\/p>\n<p>To reduce the risk of phishing or any other attacks, the FIDO2 method doesn\u2019t involve storing your credentials on a server. Instead, it uses features such as biometric authentication to validate your identity so the password never leaves your device.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-1322571 lazy\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3.jpg\" alt width=\"1024\" height=\"391\" sizes=\"(max-width: 1024px) 100vw, 1024px\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3.jpg 1024w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3-280x107.jpg 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3-540x206.jpg 540w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3-270x103.jpg 270w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/FIDO2-Graphic-v3-796x304.jpg 796w\"><figcaption>Credit: FIDO<\/figcaption><figcaption><a href=\"https:\/\/thenextweb.com\/security\/2020\/10\/09\/inside-fido-alliances-vision-of-a-future-free-of-passwords\/#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2020%2F10%2F09%2Finside-fido-alliances-vision-of-a-future-free-of-passwords%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: FIDO2 flow with WebAuthn and CTAP\" data-title=\"Share FIDO2 flow with WebAuthn and CTAP on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share FIDO2 flow with WebAuthn and CTAP on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"><\/i><\/a>FIDO2 flow with WebAuthn and CTAP<\/figcaption><\/figure>\n<p>As shown in the diagram below, the WebAuthn part handles talking to services through browser or web services in a secure way. And CTAP allows you to use your phone to talk to WebAuthn and complete your authentication.<\/p>\n<p>FIDO2 is also compatible with FIDO UAF and FIDO U2F-based hardware security keys. So, you can use a hardware key to login to services through your laptop or your phone. I\u2019ve been using Yubico\u2019s 5c NFC key for over a month to login to some services such as Microsoft accounts and Twitter through my phone and laptop.<\/p>\n<h2>How the alliance is working with companies to spread FIDO2<\/h2>\n<p>Andrew Shikiar, executive director of the FIDO alliance, believes that everyday devices such as phones play an important role in creating a password-less&nbsp;future:<\/p>\n<blockquote readability=\"6\">\n<p>Industry has found that public-key cryptography that allows consumers to use everyday devices is the preferred mechanism for stronger user authentication.<\/p>\n<\/blockquote>\n<p>He said that if the authentication method is too hard, you\u2019ll opt-out or find a way around it, and that\u2019s the challenge FIDO is trying to overcome. It helps its partners with best practices and user-friendly ways to implement authentication through FIDO2 and other compatible standards.<\/p>\n<p>Earlier this year, during its World Wide Developer Conference (WWDC), Apple announced that it was going to support the <a href=\"https:\/\/thenextweb.com\/apple\/2020\/06\/25\/safari-will-soon-log-you-into-websites-with-face-id-and-touch-id\/\">FIDO2 standard on iOS and macOS through Safari 14<\/a>.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-1322575 lazy\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0.jpeg\" alt width=\"500\" height=\"500\" sizes=\"(max-width: 500px) 100vw, 500px\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0.jpeg 500w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-96x96.jpeg 96w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-210x210.jpeg 210w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-270x270.jpeg 270w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-135x135.jpeg 135w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-192x192.jpeg 192w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/0-470x470.jpeg 470w\"><figcaption>Credit: LinkedIN<\/figcaption><figcaption><a href=\"https:\/\/thenextweb.com\/security\/2020\/10\/09\/inside-fido-alliances-vision-of-a-future-free-of-passwords\/#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2020%2F10%2F09%2Finside-fido-alliances-vision-of-a-future-free-of-passwords%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: Andrew Shikiar, executive director at FIDO Alliance\" data-title=\"Share Andrew Shikiar, executive director at FIDO Alliance on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share Andrew Shikiar, executive director at FIDO Alliance on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"><\/i><\/a>Andrew Shikiar, executive director at FIDO Alliance<\/figcaption><\/figure>\n<p>What that means is that you can use biometric methods (such as FaceID and Touch ID) or hardware keys (such as the ones from Yubico) to login to websites without a password.<\/p>\n<p>Apple\u2019s not the only one to adopt this, Google Chrome, Mozilla Firefox, and Microsoft Edge already support WebAuthn, and to some extent FIDO2.<\/p>\n<p>Last year, <a href=\"https:\/\/fidoalliance.org\/android-now-fido2-certified-accelerating-global-migration-beyond-passwords\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">FIDO Alliance declared Android as FIDO2 certified<\/a>, paving the way for many devices to be used for authentication and allow users to login to services through biometrics. Later, Google started allowing users to <a href=\"https:\/\/thenextweb.com\/google\/2019\/08\/13\/google-will-let-you-sign-in-to-some-services-with-fingerprint-on-android\/\">login through biometric authentication<\/a> to some of its services on Chrome for Android.<\/p>\n<p>In addition to this, Microsoft\u2019s Windows 10 is also FIDO2 approved. So, you can use its Windows Hello to login to a machine through facial recognition or a fingerprint scanner.<\/p>\n<h2>Security and productivity benefits<\/h2>\n<p>A lot of us use two-factor authentication (2FA) to login to our accounts. However, we still rely on SMS-based authentication, and that\u2019s prone to attacks. Instead of that, FIDO2-based authentication allows you to use your phone or a hardware key, saving users a lot of time and effort. Plus, it\u2019s more reliable and secure than SMS.<\/p>\n<p>Often when I am logging into services like Twitter, I don\u2019t get an authentication SMS for a long time. In these cases, if I use a hardware key as my secondary authentication, the whole process is very fast.<\/p>\n<figure class=\"post-image post-mediaBleed aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"size-full wp-image-1322573 lazy\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/Screenshot-2020-10-09-at-3.57.29-PM.png\" alt width=\"579\" height=\"419\" sizes=\"(max-width: 579px) 100vw, 579px\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/Screenshot-2020-10-09-at-3.57.29-PM.png 579w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/Screenshot-2020-10-09-at-3.57.29-PM-280x203.png 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/Screenshot-2020-10-09-at-3.57.29-PM-373x270.png 373w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2020\/10\/Screenshot-2020-10-09-at-3.57.29-PM-187x135.png 187w\"><figcaption><a href=\"https:\/\/thenextweb.com\/security\/2020\/10\/09\/inside-fido-alliances-vision-of-a-future-free-of-passwords\/#\" data-url=\"https:\/\/twitter.com\/intent\/tweet?url=https%3A%2F%2Fthenextweb.com%2Fsecurity%2F2020%2F10%2F09%2Finside-fido-alliances-vision-of-a-future-free-of-passwords%2F&amp;via=thenextweb&amp;related=thenextweb&amp;text=Check out this picture on: Yubico\u2019s 5 series of Yubikey hardware authentication devices\" data-title=\"Share Yubico\u2019s 5 series of Yubikey hardware authentication devices on Twitter\" data-width=\"685\" data-height=\"500\" class=\"post-image-share popitup\" title=\"Share Yubico\u2019s 5 series of Yubikey hardware authentication devices on Twitter\"><i class=\"icon icon--inline icon--twitter--dark\"><\/i><\/a>Yubico\u2019s 5 series of Yubikey hardware authentication devices<\/figcaption><\/figure>\n<p>Shikiar said that FIDO2-based authentication is seeing a lot of traction with enterprise customers as well. Because of the COVID-19 pandemic, a lot of people have to work from home in an environment that might not be as secure as the office. Plus, with the rising number of cyberattacks this year, it\u2019s important for companies to protect their data.<\/p>\n<p>John Gilbert, General Manager, UK&amp;I at <a href=\"https:\/\/www.yubico.com\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Yubico<\/a>, a company that makes FIDO-certified hardware security key, agrees:<\/p>\n<blockquote readability=\"9\">\n<p>Because of the pandemic, convergence between our work lives and our home is happening in a much more concentrated way.&nbsp;So there\u2019s the need to ensure that we have the same sort of levels of security available to us. I think what Yubico does and what we\u2019ve always done is to provide something that is very simple and easy to use.<\/p>\n<\/blockquote>\n<p>The FIDO Alliance executive said that while it\u2019s hard to know exactly what happened when <a href=\"https:\/\/thenextweb.com\/security\/2020\/07\/16\/everything-we-know-about-how-twitters-biggest-hack-went-down\/\">Twitter was hacked in <\/a><a href=\"https:\/\/thenextweb.com\/security\/2020\/07\/16\/everything-we-know-about-how-twitters-biggest-hack-went-down\/\">July<\/a>,&nbsp;and accounts belonging to Elon Musk and Jeff Bezos were compromised, he believes that if the company had used security keys for sensitive programs, the breach wouldn\u2019t have taken place.<\/p>\n<p>Gilbert told me that hardware security keys are one of the most secure ways of authentication because they\u2019re off the network and, unlike your phone, a hacker can\u2019t attack them. Plus, these keys don\u2019t rely on any kind of network or battery life. So, you can use them at any time.<\/p>\n<p>A study from Yubico released last year suggested that <a href=\"https:\/\/www.yubico.com\/wp-content\/uploads\/2019\/01\/Ponemon-Authentication-Report.pdf\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">an average employee spends almost 11 hours per year entering or resetting passwords<\/a>, resulting in a productivity loss of millions of dollars. That figure can make a lot of enterprises think about going password-less.<\/p>\n<h2>Challenges to adopting a password-less future<\/h2>\n<p>Until now, FIDO\u2019s standards have mostly been used as a second-factor authentication method in tandem with passwords. The alliance\u2019s next challenge is to completely get rid of password or knowledge-based (login methods asking for details such as your pet\u2019s name) mechanisms.<\/p>\n<p>Some companies are now allowing customers to get rid of passwords. Last year, Japan\u2019s networking giant <a href=\"https:\/\/fidoalliance.org\/ntt-docomo-introduces-passwordless-authentication-for-d-account\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">NTT DOCOMO introduced password-less logins<\/a> for its customers. CVS Health now has over <a href=\"https:\/\/www.hypr.com\/cvs-health-h-isac-webcast\/\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">10 million customers<\/a> who don\u2019t use any password to attain its services.<\/p>\n<p>Microsoft also allows customers to <a href=\"https:\/\/thenextweb.com\/security\/2019\/05\/09\/passwordless-web-gets-a-boost-from-windows-hello-fido2-certification\/\">use biometric authentication or security keys on Windows 10<\/a> to login to some of its services such as Microsoft online accounts without passwords. I\u2019ve used this service with Yubico\u2019s key on a Windows machine and it works efficiently. eBay is also allowing customers to login using biometric authentication on iOS and Android.<\/p>\n<p><figure class=\"post-image post-mediaBleed aligncenter\"><img decoding=\"async\" loading=\"lazy\" class=\"aligncenter size-full wp-image-1205458 lazy\" src=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed.jpg\" alt width=\"1200\" height=\"628\" sizes=\"(max-width: 1200px) 100vw, 1200px\" data-lazy=\"true\" data-srcset=\"https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed.jpg 1200w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed-280x147.jpg 280w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed-516x270.jpg 516w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed-258x135.jpg 258w, https:\/\/cdn0.tnwcdn.com\/wp-content\/blogs.dir\/1\/files\/2019\/05\/windows-hello-hed-796x417.jpg 796w\"><figcaption>Credit: <a href=\"https:\/\/www.microsoft.com\/en-za\/windows\/windows-hello\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Windows Hello<\/a><\/figcaption><\/figure>\n<\/p>\n<p>While we\u2019re starting to see some services adopting this kind of login, the majority of websites and apps still rely on passwords.<\/p>\n<p>Another challenge is that not all desktop systems have biometric authentication. A lot of Windows 10-based laptops and Chromebooks allow you to login using a fingerprint scanner or a face recognition system that can be leveraged for authentication on websites too.<\/p>\n<p>Apple has also started to include TouchID in recently released MacBooks. However, there\u2019s a long way to go until the majority of desktop computers would feature some kind of biometric authentication.<\/p>\n<p>It\u2019s also important to convince users to move away from passwords, and it\u2019s hard to change a habit that\u2019s been instilled for years. That\u2019s why FIDO is putting out <a href=\"https:\/\/youtu.be\/k55tRpnI-6o\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">educational material<\/a> to instruct consumers and enterprises.<\/p>\n<p>Gilbert believes that within the next year or so, we\u2019ll see the industry consistently move towards embedding FIDO2 standards in operating systems and a range of applications it controls.<\/p>\n<p>Shikiar is optimistic about the password-less future. He expects 90% of major web services to offer authentication that don\u2019t require passwords within the next five years.<\/p>\n<p>If this happens, it would be easier and far more secure for people to log in to services.<\/p>\n<p>\u201cWhat\u2019s interesting is, I\u2019m seeing that companies are quickly adopting password-less authentication, they\u2019re looking at this not just as a security component, but also as a usability and brand building component. In the near future, it might put service to a competitive disadvantage if it doesn\u2019t have a password-less login option,\u201d he said.<\/p>\n<p class=\"post-article-read-next\"> <b>Read next:<\/b> <a class=\"gtm-article-read-next\" data-event-category=\"Article\" data-event-action=\"Next post\" data-event-label data-event-non-interaction=\"true\" href=\"https:\/\/thenextweb.com\/growth-quarters\/2020\/10\/09\/using-jargon-to-sound-smart-science-says-youre-just-insecure\/\"> Using jargon to sound smart? Science says you\u2019re just insecure <\/a>\n<\/p>\n<p> <a href=\"https:\/\/thenextweb.com\/security\/2020\/10\/09\/inside-fido-alliances-vision-of-a-future-free-of-passwords\/\">Source<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Most services you use on your phone or laptop, from email providers to food delivery providers, require you to have a password. With so many services and websites, it\u2019s hard to come&#8230;<\/p>\n","protected":false},"author":1,"featured_media":232,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":[],"categories":[1],"tags":[],"_links":{"self":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts\/231"}],"collection":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=231"}],"version-history":[{"count":0,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/posts\/231\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=\/wp\/v2\/media\/232"}],"wp:attachment":[{"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.londonchiropracter.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}