Passkeys the Future of Authentication

Several years ago I had the opportunity to sit on the FIDO Alliance Board. While there we debated the future of authentication and commissioned the work to develop FIDO 2. I walked away from that experienced convinced that multi-factor authentication should and now could replace the insecure use of passwords without a second factor like the use of our secure thing [device, card, or dongle], or our unique biometric(s).

Recent my colleague Jeff and I have been trying to understand how the various enhancements to Webauthn, FIDO 2, and CTAP will allow users to use multiple devices without having to register each device with its unique public private key pair.

As a result of our conversations and research, it is clear a single provider such as Apple can within their proprietary environment enable the ability to access a Relying Party RP from multiple devices with each challenge authenticated with one Public Key.

Concepts like Keychains and the use of secure chains enabled via BLE, Cable or QR code are clear. Ideas like Signed Assertions often appear as tools capable of proving the device knows of the existence of the Private Key resident in the secure element of one of the user’s devices.

the FIDO alliance is focused on solving these challenges

It is time to move to Multi-Factor Authentication built on a Restricted Operating Environment

Passwords should become a thing of the past. Here’s why

This morning one of my Google alerts found a blog coming from the World Economic Forum.  It reminds us of the inventor of the password Fernando Corbato.  In an interview with the Wall Street Journal, he said passwords have become “a nightmare”.

The open question is how do we solve for the nightmare of password management we have created that is both effortless and secure.

This article calls for private enterprise and our governments to find answers.  I hope in finding these answers capitalism and profit do not become the reason to act.  I hope social responsibility and community action drive all to find answers that are affordable, convenient, secure and more importantly consumer-friendly.