FIDO Multi Device Credentials with Andrew Shikiar and Tim Cappalli
Jun 14, 2022
auto_awesome
Andrew Shikiar and Tim Cappalli join host Vittorio Bertocci to discuss FIDO multi device credentials, the progress and challenges in the identity industry, the goal of FIDO Alliance to reduce data breaches through password replacement, the FIDO2 stack and secure authentication methods, the audacious goal of replacing passwords and SMS OTP with possession-based authentication, and the journey towards a passwordless future.
FIDO multi-device credentials provide a password alternative using asymmetric public-key cryptography and have broad support from major platforms like Apple, Google, and Microsoft.
Multi-device credentials simplify authentication implementation for developers by managing credentials and authenticators, allowing developers to focus on building applications and delivering secure, user-friendly authentication experiences.
Deep dives
Multi-Device Credentials and the Move Away from Passwords
Multi-device credentials, a key focus of this podcast episode, offer a potential alternative to passwords for consumer-grade applications. These credentials utilize user-friendly asymmetric public-key cryptography to replace passwords with a key pair. The authenticator holds a private key, while the server stores a public key. This approach simplifies and strengthens authentication, with deployment support from major platforms like Apple, Google, and Microsoft. WebAuthn, the browser API for WebAuthn authentication, provides developers with a simple interface for implementing advanced cryptography. Adoption has seen broad support in both enterprise and consumer applications, with an increasing focus on usability to drive wider adoption. The goal is to shift towards a world where passwords are eliminated, and FIDO's multi-device credential model is a step towards achieving this.
The Benefits for Developers
Developers can benefit from multi-device credentials by simplifying the implementation of authentication. With platforms managing the credentials and authenticators, developers no longer need to request specific credentials or worry about their origin. WebAuthn provides a client-to-authenticator protocol for developers responsible for relying parties or resources. SDKs and web frameworks further simplify the implementation process. These advancements enable developers to focus on building their applications while delivering secure, user-friendly authentication experiences.
Addressing Security and Usability Concerns
Multi-device credentials aim to strike a balance between security and usability. Through the introduction of device public keys, developers can have additional information about user devices, ensuring credentials are only used on known and authorized devices. This aspect addresses concerns about the security of multi-device credentials and supports identity management in enterprise environments. By ensuring the availability and compatibility of multi-device credentials across platforms, major vendors facilitate the adoption of these credentials on a large scale.
The Call to Action: Participate in the Dev Trial
The podcast concludes with a call to action for relying party developers to actively participate in the development and testing of multi-device credentials. Developers are encouraged to learn about the technology, provide feedback, and explore the opportunities for removing or reducing reliance on passwords. Collaboration and feedback will play a pivotal role in refining the specifications and driving wider adoption of multi-device credentials in the next 12 to 24 months.
On the first episode of the 4th season of Identity Unlocked, host Vittorio Bertocci, Principal Architect at Auth0, is joined by Andrew Shikiar, Executive Director & CMO, FIDO Alliance, and Tim Cappalli, Digital Identity Standards Architect at Microsoft. Vittorio, Andrew and Tim discuss the new FIDO multi device credentials, commonly known as passkey, a new FIDO feature that are an alternative to passwords in consumer grade applications.
Get the Snipd podcast app
Unlock the knowledge in podcasts with the podcast player of the future.
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode
Save any moment
Hear something you like? Tap your headphones to save it with AI-generated key takeaways
Share & Export
Send highlights to Twitter, WhatsApp or export them to Notion, Readwise & more
AI-powered podcast player
Listen to all your favourite podcasts with AI-powered features
Discover highlights
Listen to the best highlights from the podcasts you love and dive into the full episode