SlideShare a Scribd company logo
All Rights Reserved | FIDO Alliance | Copyright 20181
BEYOND PASSWORDS:
FIDO & THE FUTURE OF
CONSUMER
AUTHENTICATION
DAVE BOSSIO
HEAD OF OPERATING SYSTEM SECURITY, MICROSOFT
SEPTEMBER 19, 2018
All Rights Reserved | FIDO Alliance | Copyright 20182
THE WORLD HAS A PASSWORD PROBLEM
Data breaches in 2016
that involved weak,
default, or stolen
passwords1
81%
Phishing attacks were
successful in 20161 Breaches in 2017, a 45%
increase over 20162
1 IN 14
1,579
CLUMSY | HARD TO REMEMBER | NEED TO BE CHANGED ALL THE TIME
All Rights Reserved | FIDO Alliance | Copyright 20183
THE SOLUTION: SIMPLER *AND* STRONGER
open standards for
simpler, stronger
authentication
using public key
cryptography
Single Gesture
Phishing-resistant MFA
=
SECURITY
USABILITY
Poor Easy
WeakStrong
All Rights Reserved | FIDO Alliance | Copyright 20184
FIDO IS “HIGH-ASSURANCE STRONG AUTHENTICATION”
Javelin Strategy & Research, 2017 State of Authentication Report
High-assurance strong authentication =
✓ Use of two + factors
✓ At least one leverages public key cryptography
✓ Not susceptible to phishing, man-in-the-middle
and/or other attacks targeting credentials
All Rights Reserved | FIDO Alliance | Copyright 20185
FIDO ECOSYSTEM STATUS
CERTIFICATIONS
MEMBERS & PARTNERS
DEPLOYMENTSREGULATORY FIT
SPECIFICATIONS
All Rights Reserved | FIDO Alliance | Copyright 20186
BOARD MEMBERS LEADING THE WAY
CONSUMER ELECTRONICS SECURITY & BIOMETRICS HIGH-ASSURANCE SERVICES
LIAISON PROGRAM
All Rights Reserved | FIDO Alliance | Copyright 20187
All Rights Reserved | FIDO Alliance | Copyright 20188
FIDO CERTIFIED ECOSYSTEM (SAMPLE)
PHONES, PCs, & BROWSERS SECURITY KEYS CLOUD/SERVER SOLUTIONS
All Rights Reserved | FIDO Alliance | Copyright 20189
EARLY ADOPTERS DEPLOYING (SAMPLE)
Past Testing/Pilot/PoC stage…
Becoming mainstream “best practice”
All Rights Reserved | FIDO Alliance | Copyright 201810
FIDO’S IMPACT ON GOVERNMENT POLICIES
US (NIST/OMB): Technology now enables two secure,
distinct authentication factors in a single device (2014)
US Commission: Emphasizes authentication, cites
open-source standards and specifications such as
FIDO Authentication as best models (2016)
US Senate: Senator Ron Wyden issues letter to bank
regulators, asking for support of U2F (2017)
US (NIST/OMB): FIDO Authentication meets new
Authenticator Assurance Level 3 requirements (2017)
All Rights Reserved | FIDO Alliance | Copyright 201811
FIDO’S IMPACT ON GOVERNMENT POLICIES
UK Government: Cites emerging industry standards
such as FIDO for future to replace passwords (2016)
European Banking Authority PSD2: Accepts
one device two-factor authentication (2017)
Taiwan Bank Assoc. and Financial Supervisory Commission: Client-side
biometrics are appropriate to use for e-Banking applications (2016)
Korean Internet Security Agency: Embraces FIDO Specifications as part of a
broader, more modern and vendor-neutral approach to authentication (2017)
All Rights Reserved | FIDO Alliance | Copyright 201812
HOW DOES FIDO WORK?
AuthenticatorUser verification FIDO Authentication
Require user gesture before
private key can be used
Challenge
(Signed) Response
Private key
dedicated to one
app Public key
All Rights Reserved | FIDO Alliance | Copyright 201813
FIDO SPECIFICATIONS
Passwordless Experience (UAF Standards)
Authenticated Online
3
Biometric User Verification*
21
?
Authentication Challenge Authenticated Online
3
Second Factor Challenge Insert Dongle* / Press Button
Second Factor Experience (U2F Standards)
*There are other types of authenticators
21
All Rights Reserved | FIDO Alliance | Copyright 201814
WEB AUTHENTICATION SPECIFICATION BRINGS
FIDO TO THE PLATFORM
Participation from all
of these platform
providers
World Wide Web
Consortium (W3C)
developing a Web
Authentication
specification based
on 3 FIDO Alliance
technical
specifications
A new standard
JavaScript API
Works with all FIDO2
platforms and
authenticators ?
Candidate
Recommendation
All Rights Reserved | FIDO Alliance | Copyright 201815
FIDO SPECIFICATIONS
FIDO2 (CTAP & Web Authentication)
All Rights Reserved | FIDO Alliance | Copyright 201816
FIDO CERTIFIED PROGRAMS
• Functional Interoperability Testing:
• Enables servers, clients, SDKs and authenticators to officially
be identified as FIDO Certified
• Ensures interoperability across the FIDO ecosystem
• 475+ Certified implementations to date
• Certified Authenticator Levels
• Assure that authenticator secrets are protected on all FIDO
Implementation Types
• Based on third-party laboratory verification of FIDO Security
Requirements
• Done in coordination with existing security programs
• Universal Server:
• Ensures compatibility with all FIDO Certified Authenticators
17
CERTIFIED AUTHENTICATOR LEVELS DETAILS
All Rights Reserved | FIDO Alliance | Copyright 201818
BIOMETRIC CERTIFICATION
• First of its kind program
• Empirically validates biometrics components
through third-party labs
• Assures that biometrics correctly identify users
regardless of modality on all FIDO Implementation
Types
All Rights Reserved | FIDO Alliance | Copyright 201819
FIDO:
THE FUTURE OF
CONSUMER
AUTHENTICATION
FIDO Authentication is the industry’s
response to the password problem
• INDUSTRY SUPPORT - FIDO represents the efforts of some of the world’s largest companies whose very
businesses rely upon better user authentication
• THOUSANDS OF SPEC DEVELOPMENT HOURS - Now being realized in products being used every day
• ONGOING INNOVATION - Specifications, certification programs, and deployment working groups
establishing best implementation practices
• ENABLEMENT - Leading service providers representing billions of user identities are already FIDO-
enabling their authentication processes
All Rights Reserved | FIDO Alliance | Copyright 201820
Join the FIDO Ecosystem
www.fidoalliance.org
Deploy
Take Part in FIDO Events
Build FIDO Certified Solutions
Join the Alliance

More Related Content

PPTX
FIDO Masterclass
PDF
FIDO Authentication in a Mobile Network
PDF
FIDO Authentication and GDPR
PDF
FIDO Support for the GDPR
PDF
FIDO and Adaptive Authentication
PDF
Javelin Research's State of Strong Authentication 2019 Report Webinar
PDF
FIDO UAF Adoption in Hong Kong
PDF
FIDO UAF and PKI in Asia: A Case Study and Recommendations
FIDO Masterclass
FIDO Authentication in a Mobile Network
FIDO Authentication and GDPR
FIDO Support for the GDPR
FIDO and Adaptive Authentication
Javelin Research's State of Strong Authentication 2019 Report Webinar
FIDO UAF Adoption in Hong Kong
FIDO UAF and PKI in Asia: A Case Study and Recommendations

What's hot (20)

PDF
FIDO's Role in the Global Regulatory Landscape for Strong Authentication
PDF
2018 12-07 tokyo-seminar Brett McDowell
PDF
FIDO and the Future of User Authentication
PPTX
Fido Technical Overview
PDF
Deployment Snapshot from Japan: NTT DOCOMO, Yahoo! Japan
PPTX
FIDO Alliance Vision and Updates
PPTX
FIDO Alliance Webinar: Catch Up WIth FIDO
PDF
Integrating FIDO & Federation Protocols
PPTX
Global Regulatory Landscape for Strong Authentication
PDF
Deployment Case Study: Login.gov & FIDO2
PDF
FIDO Alliance Vision and Status
PPTX
Introduction to FIDO's Identity Verification & Binding Initiative
PDF
FIDO as Regtech - Addressing Government Requirements
PDF
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
PDF
Introduction to FIDO Biometric Authentication
PDF
Deploying FIDO Authentication - Business Considerations
PPTX
Introducing FIDO Device Onboard (FDO)
PDF
FIDO Authentication in the Shifting Regulatory Landscape
PDF
The State of FIDO
PPTX
Introduction to FIDO Alliance
FIDO's Role in the Global Regulatory Landscape for Strong Authentication
2018 12-07 tokyo-seminar Brett McDowell
FIDO and the Future of User Authentication
Fido Technical Overview
Deployment Snapshot from Japan: NTT DOCOMO, Yahoo! Japan
FIDO Alliance Vision and Updates
FIDO Alliance Webinar: Catch Up WIth FIDO
Integrating FIDO & Federation Protocols
Global Regulatory Landscape for Strong Authentication
Deployment Case Study: Login.gov & FIDO2
FIDO Alliance Vision and Status
Introduction to FIDO's Identity Verification & Binding Initiative
FIDO as Regtech - Addressing Government Requirements
FIDO & PSD2 – Achieving Strong Customer Authentication Compliance
Introduction to FIDO Biometric Authentication
Deploying FIDO Authentication - Business Considerations
Introducing FIDO Device Onboard (FDO)
FIDO Authentication in the Shifting Regulatory Landscape
The State of FIDO
Introduction to FIDO Alliance
Ad

Similar to Beyond Passwords: FIDO & the Future of Consumer Authentication (20)

PDF
FIDO And the Future of User Authentication
PDF
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
PDF
Introduction to the FIDO Alliance
PDF
Beyond Passwords: FIDO and the Future of User Authentication
PDF
Beyond Passwords: FIDO and the Future of User Authentication
PPTX
Introduction to the FIDO Alliance: Vision & Status
PPTX
Strong Authentication Trends in Government
PDF
FIDO Technical Specifications Overview
PDF
FIDO Technical Specifications Overview
PPTX
FIDO Alliance: Year in Review Webinar slides from January 20 2016
PDF
FIDO Authentication Technical Overview
PDF
FIDO Authentication Technical Overview
PPTX
FIDO Webinar – A New Model for Online Authentication: Implications for Policy...
PPTX
Getting to Know the FIDO Specifications - Technical Tutorial
PDF
Introduction to FIDO Authentication
PPTX
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
PDF
Fido Overview: Status and Future
PDF
FIDO Alliance Vision and Status
PDF
Tokyo Seminar: FIDO Alliance Vision and Status
PPTX
Introduction to FIDO: A New Model for Authentication
FIDO And the Future of User Authentication
FIDO Workshop at the Cloud Identity Summit: FIDO Alliance Overview
Introduction to the FIDO Alliance
Beyond Passwords: FIDO and the Future of User Authentication
Beyond Passwords: FIDO and the Future of User Authentication
Introduction to the FIDO Alliance: Vision & Status
Strong Authentication Trends in Government
FIDO Technical Specifications Overview
FIDO Technical Specifications Overview
FIDO Alliance: Year in Review Webinar slides from January 20 2016
FIDO Authentication Technical Overview
FIDO Authentication Technical Overview
FIDO Webinar – A New Model for Online Authentication: Implications for Policy...
Getting to Know the FIDO Specifications - Technical Tutorial
Introduction to FIDO Authentication
Introduction to FIDO Alliance: Vision and Status -Tokyo Seminar -Brett McDowell
Fido Overview: Status and Future
FIDO Alliance Vision and Status
Tokyo Seminar: FIDO Alliance Vision and Status
Introduction to FIDO: A New Model for Authentication
Ad

More from FIDO Alliance (20)

PPTX
Securing Account Lifecycles in the Age of Deepfakes.pptx
PPTX
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
PPTX
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
PPTX
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
PPTX
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
PPTX
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
PPTX
FIDO Alliance Seminar State of Passkeys.pptx
PPTX
FIDO Munich Seminar: FIDO Tech Principles.pptx
PPTX
FIDO Munich Seminar: Securing Smart Car.pptx
PPTX
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
PPTX
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
PPTX
FIDO Munich Seminar Workforce Authentication Case Study.pptx
PPTX
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
PPTX
FIDO Munich Seminar FIDO Automotive Apps.pptx
PPTX
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
PPTX
FIDO Munich Seminar Introduction to FIDO.pptx
PPTX
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
PPTX
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
PPTX
UX Webinar Series: Aligning Authentication Experiences with Business Goals
PDF
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf
Securing Account Lifecycles in the Age of Deepfakes.pptx
FIDO Seminar: Perspectives on Passkeys & Consumer Adoption.pptx
FIDO Seminar: Evolving Landscape of Post-Quantum Cryptography.pptx
FIDO Seminar: Targeting Trust: The Future of Identity in the Workforce.pptx
FIDO Seminar: New Data: Passkey Adoption in the Workforce.pptx
FIDO Seminar: Authentication for a Billion Consumers - Amazon.pptx
FIDO Alliance Seminar State of Passkeys.pptx
FIDO Munich Seminar: FIDO Tech Principles.pptx
FIDO Munich Seminar: Securing Smart Car.pptx
FIDO Munich Seminar: Strong Workforce Authn Push & Pull Factors.pptx
FIDO Munich Seminar: Biometrics and Passkeys for In-Vehicle Apps.pptx
FIDO Munich Seminar Workforce Authentication Case Study.pptx
FIDO Munich Seminar In-Vehicle Payment Trends.pptx
FIDO Munich Seminar FIDO Automotive Apps.pptx
FIDO Munich Seminar Blueprint for In-Vehicle Payment Standard.pptx
FIDO Munich Seminar Introduction to FIDO.pptx
UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your...
UX Webinar Series: Drive Revenue and Decrease Costs with Passkeys for Consume...
UX Webinar Series: Aligning Authentication Experiences with Business Goals
FIDO Alliance Osaka Seminar: The WebAuthn API and Discoverable Credentials.pdf

Recently uploaded (20)

PPT
250152213-Excitation-SystemWERRT (1).ppt
PPTX
newyork.pptxirantrafgshenepalchinachinane
PDF
Exploring VPS Hosting Trends for SMBs in 2025
PPTX
Power Point - Lesson 3_2.pptx grad school presentation
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PPTX
artificialintelligenceai1-copy-210604123353.pptx
PPTX
artificial intelligence overview of it and more
PPTX
t_and_OpenAI_Combined_two_pressentations
PDF
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
PPTX
SAP Ariba Sourcing PPT for learning material
PPT
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
PPT
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
PDF
The Evolution of Traditional to New Media .pdf
PDF
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
PPTX
Layers_of_the_Earth_Grade7.pptx class by
PPT
Design_with_Watersergyerge45hrbgre4top (1).ppt
PDF
SASE Traffic Flow - ZTNA Connector-1.pdf
PDF
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
PDF
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
PDF
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf
250152213-Excitation-SystemWERRT (1).ppt
newyork.pptxirantrafgshenepalchinachinane
Exploring VPS Hosting Trends for SMBs in 2025
Power Point - Lesson 3_2.pptx grad school presentation
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
artificialintelligenceai1-copy-210604123353.pptx
artificial intelligence overview of it and more
t_and_OpenAI_Combined_two_pressentations
SlidesGDGoCxRAIS about Google Dialogflow and NotebookLM.pdf
SAP Ariba Sourcing PPT for learning material
FIRE PREVENTION AND CONTROL PLAN- LUS.FM.MQ.OM.UTM.PLN.00014.ppt
isotopes_sddsadsaadasdasdasdasdsa1213.ppt
The Evolution of Traditional to New Media .pdf
Session 1 (Week 1)fghjmgfdsfgthyjkhfdsadfghjkhgfdsa
Layers_of_the_Earth_Grade7.pptx class by
Design_with_Watersergyerge45hrbgre4top (1).ppt
SASE Traffic Flow - ZTNA Connector-1.pdf
Smart Home Technology for Health Monitoring (www.kiu.ac.ug)
📍 LABUAN4D EXCLUSIVE SERVER STAR GAMING ASIA NO.1 TERPOPULER DI INDONESIA ! 🌟
The Ikigai Template _ Recalibrate How You Spend Your Time.pdf

Beyond Passwords: FIDO & the Future of Consumer Authentication

  • 1. All Rights Reserved | FIDO Alliance | Copyright 20181 BEYOND PASSWORDS: FIDO & THE FUTURE OF CONSUMER AUTHENTICATION DAVE BOSSIO HEAD OF OPERATING SYSTEM SECURITY, MICROSOFT SEPTEMBER 19, 2018
  • 2. All Rights Reserved | FIDO Alliance | Copyright 20182 THE WORLD HAS A PASSWORD PROBLEM Data breaches in 2016 that involved weak, default, or stolen passwords1 81% Phishing attacks were successful in 20161 Breaches in 2017, a 45% increase over 20162 1 IN 14 1,579 CLUMSY | HARD TO REMEMBER | NEED TO BE CHANGED ALL THE TIME
  • 3. All Rights Reserved | FIDO Alliance | Copyright 20183 THE SOLUTION: SIMPLER *AND* STRONGER open standards for simpler, stronger authentication using public key cryptography Single Gesture Phishing-resistant MFA = SECURITY USABILITY Poor Easy WeakStrong
  • 4. All Rights Reserved | FIDO Alliance | Copyright 20184 FIDO IS “HIGH-ASSURANCE STRONG AUTHENTICATION” Javelin Strategy & Research, 2017 State of Authentication Report High-assurance strong authentication = ✓ Use of two + factors ✓ At least one leverages public key cryptography ✓ Not susceptible to phishing, man-in-the-middle and/or other attacks targeting credentials
  • 5. All Rights Reserved | FIDO Alliance | Copyright 20185 FIDO ECOSYSTEM STATUS CERTIFICATIONS MEMBERS & PARTNERS DEPLOYMENTSREGULATORY FIT SPECIFICATIONS
  • 6. All Rights Reserved | FIDO Alliance | Copyright 20186 BOARD MEMBERS LEADING THE WAY CONSUMER ELECTRONICS SECURITY & BIOMETRICS HIGH-ASSURANCE SERVICES
  • 7. LIAISON PROGRAM All Rights Reserved | FIDO Alliance | Copyright 20187
  • 8. All Rights Reserved | FIDO Alliance | Copyright 20188 FIDO CERTIFIED ECOSYSTEM (SAMPLE) PHONES, PCs, & BROWSERS SECURITY KEYS CLOUD/SERVER SOLUTIONS
  • 9. All Rights Reserved | FIDO Alliance | Copyright 20189 EARLY ADOPTERS DEPLOYING (SAMPLE) Past Testing/Pilot/PoC stage… Becoming mainstream “best practice”
  • 10. All Rights Reserved | FIDO Alliance | Copyright 201810 FIDO’S IMPACT ON GOVERNMENT POLICIES US (NIST/OMB): Technology now enables two secure, distinct authentication factors in a single device (2014) US Commission: Emphasizes authentication, cites open-source standards and specifications such as FIDO Authentication as best models (2016) US Senate: Senator Ron Wyden issues letter to bank regulators, asking for support of U2F (2017) US (NIST/OMB): FIDO Authentication meets new Authenticator Assurance Level 3 requirements (2017)
  • 11. All Rights Reserved | FIDO Alliance | Copyright 201811 FIDO’S IMPACT ON GOVERNMENT POLICIES UK Government: Cites emerging industry standards such as FIDO for future to replace passwords (2016) European Banking Authority PSD2: Accepts one device two-factor authentication (2017) Taiwan Bank Assoc. and Financial Supervisory Commission: Client-side biometrics are appropriate to use for e-Banking applications (2016) Korean Internet Security Agency: Embraces FIDO Specifications as part of a broader, more modern and vendor-neutral approach to authentication (2017)
  • 12. All Rights Reserved | FIDO Alliance | Copyright 201812 HOW DOES FIDO WORK? AuthenticatorUser verification FIDO Authentication Require user gesture before private key can be used Challenge (Signed) Response Private key dedicated to one app Public key
  • 13. All Rights Reserved | FIDO Alliance | Copyright 201813 FIDO SPECIFICATIONS Passwordless Experience (UAF Standards) Authenticated Online 3 Biometric User Verification* 21 ? Authentication Challenge Authenticated Online 3 Second Factor Challenge Insert Dongle* / Press Button Second Factor Experience (U2F Standards) *There are other types of authenticators 21
  • 14. All Rights Reserved | FIDO Alliance | Copyright 201814 WEB AUTHENTICATION SPECIFICATION BRINGS FIDO TO THE PLATFORM Participation from all of these platform providers World Wide Web Consortium (W3C) developing a Web Authentication specification based on 3 FIDO Alliance technical specifications A new standard JavaScript API Works with all FIDO2 platforms and authenticators ? Candidate Recommendation
  • 15. All Rights Reserved | FIDO Alliance | Copyright 201815 FIDO SPECIFICATIONS FIDO2 (CTAP & Web Authentication)
  • 16. All Rights Reserved | FIDO Alliance | Copyright 201816 FIDO CERTIFIED PROGRAMS • Functional Interoperability Testing: • Enables servers, clients, SDKs and authenticators to officially be identified as FIDO Certified • Ensures interoperability across the FIDO ecosystem • 475+ Certified implementations to date • Certified Authenticator Levels • Assure that authenticator secrets are protected on all FIDO Implementation Types • Based on third-party laboratory verification of FIDO Security Requirements • Done in coordination with existing security programs • Universal Server: • Ensures compatibility with all FIDO Certified Authenticators
  • 18. All Rights Reserved | FIDO Alliance | Copyright 201818 BIOMETRIC CERTIFICATION • First of its kind program • Empirically validates biometrics components through third-party labs • Assures that biometrics correctly identify users regardless of modality on all FIDO Implementation Types
  • 19. All Rights Reserved | FIDO Alliance | Copyright 201819 FIDO: THE FUTURE OF CONSUMER AUTHENTICATION FIDO Authentication is the industry’s response to the password problem • INDUSTRY SUPPORT - FIDO represents the efforts of some of the world’s largest companies whose very businesses rely upon better user authentication • THOUSANDS OF SPEC DEVELOPMENT HOURS - Now being realized in products being used every day • ONGOING INNOVATION - Specifications, certification programs, and deployment working groups establishing best implementation practices • ENABLEMENT - Leading service providers representing billions of user identities are already FIDO- enabling their authentication processes
  • 20. All Rights Reserved | FIDO Alliance | Copyright 201820 Join the FIDO Ecosystem www.fidoalliance.org Deploy Take Part in FIDO Events Build FIDO Certified Solutions Join the Alliance