In this episode, John Bradley, Senior Standard Architect at Yubico and author of many important specifications pertaining to identity management including FIDO2, talks about the origins and development of FIDO2 and WebAuthn, the flow of exchanging objects between the front end and back end of a website, RFID chip implants for contactless payments, and ongoing work and new features in WebAuthn and FIDO2.
FIDO2 and WebAuthn are standards developed to enable passwordless login experiences and enhance security, encryption, data protection, and usability.
Account recovery in FIDO and WebAuthn authentication requires the registration of multiple phishing-resistant authentication methods and the consideration of federated accounts as backup options.
Deep dives
The Evolution of FIDO and WebAuthn
The podcast episode discusses the evolution of FIDO (Fast Identity Online) and WebAuthn (Web Authentication). FIDO was initially developed by Google and PayPal to eliminate passwords and enable biometric authentication on mobile devices. U2F (Universal Second Factor) authentication, where a security key is used as a second factor, became a part of FIDO. Eventually, U2F and the original FIDO standards merged to form Fido2, which is commonly referred to as Fido2. WebAuthn, part of the W3C (World Wide Web Consortium) standard, was developed to enable browser buy-in and facilitate the interaction between relying parties and web browsers. CTAP (Client to Authenticator Protocol) allows the browser to communicate with authenticators. FIDO authentication is now being integrated into various platforms, like Apple's Face ID, to offer passwordless login experiences.
Account Recovery and Challenges
The podcast addresses the challenges of account recovery in FIDO and WebAuthn authentication. Multiple phishing-resistant authentication methods should be registered to ensure recovery options. Recovery through email or single SMS is not sufficient, as attackers can target email accounts for privilege escalation. Having multiple authenticators registered and considering federated accounts as backup options are viable strategies. However, account recovery remains a significant concern, and the industry needs to develop practices to ensure users can access their accounts securely without creating backdoors. The integration of FIDO authenticators into various devices, such as rings, earrings, and even medical monitors, is being explored. As the technology becomes more ubiquitous, recovering strong credentials and managing account security will continue to evolve.
Future Developments and Benefits
The podcast mentions future developments and benefits in FIDO and WebAuthn. Level 2 of WebAuthn and CTAP version 2.1 are close to finalization, introducing new features. The integration of Web Authentication with Web Payments is being explored. SSH certificates can be attached to FIDO credentials for phishing-resistant server administration. New privacy features, enterprise functionalities, and key derivation functionality for password managers and SAS services are being added. These developments aim to enhance security, encryption, data protection, and usability. The goal is to eventually have widespread adoption of FIDO and WebAuthn, enabling users to log in easily and securely without depending on passwords.
In this episode of Identity. Unlocked, principal architect at Auth0 and podcast host, Vittorio Bertocci, has a conversation with John Bradley. John is the Senior Standard Architect at Yubico and the author of many important specifications pertaining to identity management including FIDO2.
Like this episode? Be sure to leave a five-star review and share Identity, Unlocked with your community! You can connect with Vittorio on Twitter at @vibronet, John at @ve7jtb, or Auth0 at @auth0.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode