Close Menu
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Facebook X (Twitter) LinkedIn
Facebook X (Twitter) LinkedIn
Information Security BuzzInformation Security Buzz
  • Home
  • Articles
    • Attacks
      • BEC
      • Data Breach
      • DDoS
      • Evasion Attacks
      • Injection
      • Malware
      • MITM
      • Phishing
      • Ransomware
      • RCE
      • Social Engineering
      • Spoofing
      • Spyware
    • Business and Policy
      • BCP and DRP
      • GRC
      • Regulations
    • Data Protection
      • DLP
      • DRM
      • Encryption
      • IAM
    • Future, Trends and Insight
      • AI
      • Events & Community
      • Emerging Tech
      • Expert Panel
      • Interviews With Experts
      • Insights
      • Study & Research
    • Resources
      • Guides
      • Tools
      • Training & Education
    • Security
      • API
      • Apps
      • Cloud
      • Critical Infrastructure
      • Endpoint
      • Hardware
      • IoT
      • Mobile
      • Network
      • OT
      • Port Security
      • Security Architecture
      • Software Development
      • Supply Chain
      • Zero Trust
    • Threats and Vulnerabilities
      • Emerging Threats
      • Insider Threats
      • Risk Management
      • Threat Intelligence
      • Zero Day
  • News and Exclusives
    • Latest News
    • ISB Exclusive
    • Positive News
  • Who We Are
    • About Us
    • Information Security Buzz Expert Panel​
    • Write for Us
    • Media Pack
  • Contact Us
  • Newsletter
Subscribe
Information Security BuzzInformation Security Buzz
Home - Identity & Access Management - The time is NOW to Support Passkeys for Your Customer Authentication!
Identity & Access Management Articles Data Protection Security

The time is NOW to Support Passkeys for Your Customer Authentication!

Vishnu GutthaBy Vishnu GutthaJuly 22, 2024Updated:November 8, 20245 Mins Read
Share LinkedIn Twitter Facebook Copy Link Email
Authentication
Share
Facebook Twitter LinkedIn Email Copy Link
Quick AI Summary
ChatGPTClaudeGeminiGrokPerplexityDeepSeekCopilot

The human factor often plays a role in data breaches, primarily because their inherent biases can be exploited. This vulnerability is especially pronounced in the digital age, where user authentication is a cornerstone of online applications and services. The most common method, static passwords, epitomizes this issue – users must create, remember, and enter these passwords to access their accounts and sensitive information. However, password fatigue, the tendency to reuse or choose weak passwords due to the overwhelming number of accounts and complexity requirements, undermines their effectiveness.

The Evolution of Authentication Methods

Single-Factor Authentication

When used with a username, passwords alone are considered Single-Factor Authentication (SFA). Over the years, various policies have been introduced to enhance password security, including NIST special publication (800-63B). These policies have since evolved, but passwords remain a weak link in security. The 2024 Data Breach Investigation Report (DBIR) highlights that 68% of breaches involved a non-malicious human element, such as falling victim to social engineering attacks.

Two-Factor and Multi-Factor Authentication

To mitigate issues with password-only authentication, companies across the globe have started requiring additional factors to authenticate their users. One widely used mechanism is dynamically generated One-Time Passcodes (OTP) sent to phones or emails. However, any OTP-based MFA still falls short in preventing phishing or password replay attacks. OTPs are also prone to attack types, such as Man-in-the-middle and SIM swapping. This attack works successfully even with one-time use and short-lived OTPs.

What is a Good MFA Strategy?

So, how can one design a strong MFA strategy that addresses the problems discussed above without letting customers assume that their data is protected with OTP-based MFA? Generally, when it comes to factor types used in authentication, there are three types: something you know, something you have, and something you are. To effectively use these factors and raise the authentication bar, the industry has developed several approaches, with three main ones frequently mentioned in the Information Security space: Web Authentication (WebAuthn), FIDO2, and the latest buzzword, Passkeys.

Web Authentication (WebAuthn) and FIDO2

FIDO2, WebAuthn, and Passkeys are related but distinct concepts that leverage Public Key Infrastructure (PKI) to provide better and stronger authentication factors to users. The goal is to eliminate password usage, as we all know it. FIDO2 is the overarching standard developed by a joint effort between the Fast IDentity Online (FIDO) Alliance and the World Wide Web Consortium (W3C).

PKI is at the heart of these technologies, providing cryptographic support for secure authentication. When a user triggers a registration event with a FIDO2-enabled service, the WebAuthn API facilitates the creation of a unique public-private key pair for that specific domain. The authenticator generates the key pair, stores the private key securely on the device, and sends the public key to the service, which verifies and stores it for eventual authentication attempts. These keys are tied to the web service domain name and cannot be used on other services with different domains, providing strong protection against phishing attacks.

Passkeys: Spearheading the Passwordless Movement

The concept of passkeys was first introduced in May 2022 by Apple, Google, and Microsoft in a joint effort to expand support for passwordless sign-in authenticators. Users are not against security features; they want them to be easy to adopt. Passkeys are built to be more user-friendly and widely adoptable, improving the usability model of FIDO2 and WebAuthn. They do not require purchasing new hardware, remember long forms of multiple strings, and can be stored in password managers or devices they already own—for instance, Apple and Google support syncing passkeys across user devices through their secure technologies. Apple’s implementation uses iCloud Keychain to sync passkeys created on one device, like a MacBook, to another, like an iPhone.

Conclusion

Passkeys provide a great alternative solution to passwords; not only do they provide significant security benefits, but they also come with excellent user convenience. Passkeys align with fundamental yet highly effective cybersecurity practices. They are backed by leading tech companies committed to making it a successful attempt to eliminate passwords. Because of these reasons, the time is NOW for enterprises to consider providing passkey as an option for their users. Passkeys align with basic but very effective cybersecurity practices. A simple Google search will reveal that complex account creation and weak login practices can negatively impact the business’s revenue. This underscores the importance of providing simple to-adopt, more secure signup, and login options using solutions such as passkeys.

Many major customer-focused services already support passkeys, including Amazon, Microsoft, Google, Apple, DocuSign, PayPal, and Shopify, to name a few. A community-driven Bitwarden passkey index tracks which platforms and websites currently support passkeys. If your enterprise isn’t on the list, now is the time to join the passkey revolution. Security practitioners and application developers with influence should prioritize passkey support by adding it to their roadmap items. To learn how to deploy or convert password-based authentication to support passkeys, explore the resources at passkeys.dev. By taking this step, you can contribute to a more secure, passwordless future, protecting users and their data from evolving cyber threats.

Opinions expressed in this article are solely the Author’s own and do not express the views or opinions of the Author’s employer.

Vishnu Guttha

Vishnu currently works as a Security Engineer and very passionate about Identity and Access Management space. He also holds a CISSP certification.

    The opinions expressed in this post belong to the individual contributors and do not necessarily reflect the views of Information Security Buzz.

    Share. Facebook Twitter LinkedIn Email Copy Link

    Related Posts

    The Real Cost of Inconsistent Third-Party Access

    December 18, 20255 Mins Read

    What Happens When Devices Cross Borders? The Role of Geofencing in Global IT

    August 7, 20256 Mins Read

    The Evolving Importance of Identity Governance in FinTech

    July 10, 20258 Mins Read
    ISB-Bora-Side-Bar

    No se ha podido establecer conexión. Error 429

     
    ISB-Bora-Side-Bar
    Black ISB Logo

    Information Security Buzz is an independent resource that provides the experts’ comments, analysis, and opinion on the latest Cybersecurity news and topics

    X (Twitter) LinkedIn Facebook RSS

    Working With Us

    • About Us
    • Advertise With Us
    • Contact Us

    Write For Us

    • How To Contribute

    The Pages

    • Privacy Policy
    • Cookie Policy
    • AI Policy
    • Terms & Conditions
    • Copyright Notice

    Information Security Buzz and all its contents are copyright © 2014-2025. All rights reserved. All third-party trademarks are recognized.

    Type above and press Enter to search. Press Esc to cancel.

    Manage Consent
    To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}