FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Throughout Totally different Platforms

Oct 16, 2024Ravie LakshmananKnowledge Privateness / Passwordless

The FIDO Alliance mentioned it is working to make passkeys and different credentials extra simpler to export throughout totally different suppliers and enhance credential supplier interoperability, as greater than 12 billion on-line accounts turn into accessible with the passwordless sign-in technique.

To that finish, the alliance mentioned it has revealed a draft for a new set of specs for safe credential alternate, following commitments amongst members of its Credential Supplier Particular Curiosity Group (SIG).

Cybersecurity

This contains 1Password, Apple, Bitwarden, Dashlane, Enpass, Google, Microsoft, NordPass, Okta, Samsung, and SK Telecom.

“Secure credential exchange is a focus for the FIDO Alliance because it can help further accelerate passkey adoption and enhance user experience,” the FIDO Alliance mentioned in a press release.

“Sign-ins with passkeys reduce phishing and eliminate credential reuse while making sign-ins up to 75% faster, and 20% more successful than passwords or passwords plus a second factor like SMS OTP.”

Whereas passkeys have the benefit of being safe and phishing-resistant, they’re primarily locked in to the working system or the password supervisor service, making it unimaginable to switch them when switching platforms and, subsequently, requiring customers to create new passkeys per gadget.

The brand new specification proposed by the FIDO Alliance goals to deal with this hole with the Credential Trade Protocol (CXP) and Credential Trade Format (CXF).

They “define a standard format for transferring credentials in a credential manager including passwords, passkeys, and more to another provider in a manner that ensures transfer are not made in the clear and are secure by default,” it mentioned.

Cybersecurity

The event comes as Amazon revealed that greater than 175 million prospects have enabled passkeys on their accounts, almost one yr after the preliminary rollout.

“Passkeys fundamentally shift the way we sign in to our online accounts for the better — and seeing Amazon roll out passkeys is evidence of its commitment to its customers’ time, experiences, and security across Amazon web and mobile shopping experiences,” mentioned Andrew Shikiar, chief govt officer of FIDO Alliance.

Discovered this text fascinating? Comply with us on Twitter and LinkedIn to learn extra unique content material we put up.

Recent articles

Google: 70% of exploited flaws disclosed in 2023 have been zero-days

Mandiant safety analysts warn of a worrying new pattern...

10 Greatest Challenge Portfolio Administration (PPM) Software program for 2024

Challenge portfolio administration (PPM) assists managers in figuring out...

SolarWinds Net Assist Desk flaw is now exploited in assaults

CISA has added three flaws to its 'Recognized Exploited...

North Korean Hackers Deploy Linux FASTCash Malware for ATM Cashouts

North Korean hackers goal Linux-based cost switches with new...