FIDO

The Room Where Security Met the Human

For decades, the security industry operated on a quiet assumption: that users were the problem. Passwords existed because systems couldn’t trust people. The more secure something was, the more friction it imposed — and that friction was accepted as the price of protection.

The FIDO Alliance was founded on a different premise. Security and convenience are not opposites. They fail together or they succeed together. If authentication is too hard, people abandon it. If people abandon it, security fails. The only path forward was to build something people would actually use — because it was effortless.

Philip Andreae believed that. From 2014 to 2017, he held one of the governance seats where that argument was being settled.

Oberthur at the Founding Table

The FIDO Alliance launched in February 2013. Within its first eight months it exceeded 50 members, with Oberthur Technologies — one of the world’s largest manufacturers of smart cards and secure elements — appointed to the Board of Directors. A colleague from Oberthur’s North American telecom leadership held the seat at the outset. Others worked the technical working groups. Philip would follow, carrying the same conviction in a different direction: toward payments, toward identity, toward the human at the end of every transaction.

Seoul, October 2014 — The First Meeting

Philip’s first FIDO Alliance plenary was in Seoul, South Korea, hosted by CrucialTec, one of Korea’s leading fingerprint sensor manufacturers. Approximately 100 member organizations were in the room — engineers, executives, and standard-setters from across the globe who had gathered because they believed passwords were a problem worth solving at scale.

It was the right moment to enter. Two months later, in December 2014, the Alliance published its foundational 1.0 specifications:

  • FIDO UAF (Universal Authentication Framework) — passwordless authentication through biometrics: fingerprint, face, voice.
  • FIDO U2F (Universal 2nd Factor) — hardware security keys that made phishing mathematically impossible.

These were not incremental improvements. They were a new architecture — one that moved the cryptographic burden from the user’s memory to the secure hardware already in their device. Philip had spent eighteen years thinking about exactly this. He ran for the Board.

Secretary of the Board, 2014–2017

He won the seat. For three years Philip served as Secretary of the Board of the FIDO Alliance — one of the governing officers alongside representatives from Google, Microsoft, PayPal, Samsung, MasterCard, and Visa.

The Secretary’s role was not ceremonial. It was the connective tissue of governance — ensuring that what was agreed became what was recorded, what was recorded became what was acted on, and what was acted on became what the world eventually deployed.

The argument Philip kept making: the standard had to work for the person who didn’t care about cryptography. It had to work for the grandmother and the child, the banker in Lagos and the student in Seoul. Authentication should ask no more of a person than they already do naturally — touch your phone, look at a camera, press your thumb. The secure element handles the cryptography. The person just shows up.

Security made user-centric. Convenience made secure. Not contradictions. The whole point.

Making the Case — Publicly

Philip carried the FIDO message beyond the plenary room to financial institutions, government audiences, and the payments industry:

Industry white papers (as contributor): Smart Card Technology and the FIDO Protocols (STA, 2016) · Mobile Identity Authentication (STA) · Host Card Emulation 101 (STA, 2014) · Contactless Payments: Proposed Implementation (STA, 2018)

What Those Four Years Built

Philip’s term as Secretary ended in September 2017. The specifications he helped steward are now the foundation of passkeys — deployed by Apple, Google, Microsoft, and hundreds of financial institutions worldwide. Five billion passkeys are in active use as of 2026.

The grandmother argument won.


Philip remains available to advise on FIDO, passkeys, WebAuthn, digital identity architecture, and the governance of authentication standards.

Contact → | Senior Advisor Profile → | Prior Art & My Wallet → | Identity → | All Speaking Engagements →