{"id":6248,"date":"2018-04-11T16:08:28","date_gmt":"2018-04-11T20:08:28","guid":{"rendered":"https:\/\/www.thesslstore.com\/blog\/?p=6248"},"modified":"2018-04-12T02:14:28","modified_gmt":"2018-04-12T06:14:28","slug":"webauthn-eliminate-passwords","status":"publish","type":"post","link":"https:\/\/www.thesslstore.com\/blog\/webauthn-eliminate-passwords\/","title":{"rendered":"New WebAuthn standard will attempt to eliminate passwords"},"content":{"rendered":"<h2>The FIDO Alliance and W3C are working towards stronger authentication to protect the web<\/h2>\n<p>Passwords suck. There seems to be little consensus about best practices when it comes to passwords. Make them difficult to guess. Use long strings of random characters. Never re-use the same passwords. Rotate passwords regularly. No, don\u2019t rotate passwords\u2014that\u2019s not safe. Passwords suck, but they are a fact of life when it comes to computers and the internet.<\/p>\n<p>But maybe not for much longer.<span id=\"newline\"><\/span><\/p>\n<p>The FIDO (Fast ID Online) Alliance and the Worldwide Web Consortium have announced a new standard that could replace passwords. Web Authentication (WebAuthn) is the result of a collaboration between the FIDO Alliance and W3C based off FIDO Web API specifications. WebAuthn has officially been moved to the Candidate Recommendations stage, which is a precursor to final approval.<\/p>\n<h2>What is WebAuthn?<\/h2>\n<p>WebAuthn is a standard web API that integrates with browsers and web platform infrastructure and gives users new methods to securely authenticate themselves on the internet.<\/p>\n<blockquote><p>&#8220;With the new FIDO2 specifications and leading web browser support announced today, we are taking a big step forward towards making FIDO Authentication ubiquitous across all platforms and devices,&#8221; <a href=\"https:\/\/www.w3.org\/2018\/04\/pressrelease-webauthn-fido2.html.en\" target=\"_blank\" rel=\"nofollow noopener\">said Brett McDowell, executive director of the FIDO Alliance<\/a>. &#8220;After years of increasingly severe data breaches and password credential theft, now is the time for service providers to end their dependency on vulnerable passwords and one-time-passcodes and adopt phishing-resistant FIDO Authentication for all websites and applications.&#8221;<\/p><\/blockquote>\n<p>Here&#8217;s how it works. Rather than try to remember a difficult password for each different website, application or platform you\u2019re attempting to access, users can instead rely on their biometrics, or a device in their possession, using Bluetooth, USB or NFC to authenticate instead.<\/p>\n<blockquote><p>&#8220;Security on the web has long been a problem which has interfered with the many positive contributions the web makes to society. While there are many web security problems and we can&#8217;t fix them all, relying on passwords is one of the weakest links. With WebAuthn&#8217;s multi-factor solutions we are eliminating this weak link,&#8221; stated W3C CEO Jeff Jaffe. &#8220;WebAuthn will change the way that people access the Web.&#8221;<\/p><\/blockquote>\n<h2>What are the benefits of WebAuthn?<\/h2>\n<p>The WebAuthn API can be integrated with browsers and other kinds of web infrastructure. It enables powerful, unique public key-based credentials for each platform, which eliminates the risks inherent with password usage. Basically any application running in a browser on a device with a FIDO authenticator can make calls to the WebAuthn API to enable authentication.<\/p>\n<ul>\n<li>Simpler Authentication \u2013 With a single gesture a user can authenticate themselves using a number of methods like biometrics, security keys and device-to-device authentication.<\/li>\n<li>Better Authentication \u2013 User credentials and biometrics are stored locally, never on someone else\u2019s servers. It\u2019s also much harder to compromise authentication when it\u2019s done this way.<\/li>\n<li>New options for Developers \u2013 Now developers can leverage FIDO authentication to better secure their apps and platforms.<\/li>\n<\/ul>\n<figure id=\"attachment_6249\" aria-describedby=\"caption-attachment-6249\" style=\"width: 2000px\" class=\"wp-caption alignnone\"><img loading=\"lazy\" decoding=\"async\" class=\"size-full wp-image-6249\" src=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/fido2-graphic2.png\" alt=\"WebAuthn\" width=\"2000\" height=\"1666\" srcset=\"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/fido2-graphic2.png 2000w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/fido2-graphic2-300x250.png 300w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/fido2-graphic2-768x640.png 768w, https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/fido2-graphic2-1024x853.png 1024w\" sizes=\"auto, (max-width: 2000px) 100vw, 2000px\" \/><figcaption id=\"caption-attachment-6249\" class=\"wp-caption-text\">Image courtesy of FIDO Alliance and W3C<\/figcaption><\/figure>\n<h2>Are passwords really dead?<\/h2>\n<p>No. Although this is an exciting new standard, it will likely be at least a few years before widespread adoption. And that\u2019s contingent on the standard actually sticking.<\/p>\n<p>That being said, this is a much needed advancement for web security. Right now, in 2018, you can\u2019t swing a dead cat at a security convention without hitting a keynote speaker presenting a password hacking talk. The technology used to hack passwords, typically with brute force, is advancing rapidly and with <a href=\"https:\/\/www.thesslstore.com\/blog\/googles-post-quantum-cryptography-experiment-successful\/\" target=\"_blank\" rel=\"noopener\">quantum computing on the horizon<\/a>, it\u2019s only going to keep getting easier. And faster.<\/p>\n<p>That\u2019s why moving away from passwords is so important. <a href=\"https:\/\/www.thesslstore.com\/blog\/quantum-computings-threat-public-key-cryptography-need-worry\/\" target=\"_blank\" rel=\"noopener\">We\u2019re worried about quantum computers being able to solve encryption<\/a>. Guessing passwords would be nothing.<\/p>\n<p>Hopefully WebAuthn is the first step towards a world where passwords are relegated to the waste bins of history.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The FIDO Alliance and W3C are working towards stronger authentication to protect the web Passwords suck. There seems to be little consensus about best practices when it comes to passwords&#8230;.<\/p>\n","protected":false},"author":6,"featured_media":6250,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"inline_featured_image":false,"footnotes":"","tve_updated_post":"","tve_custom_css":"","tve_user_custom_css":"","tve_globals":{},"tcb2_ready":0,"tcb_editor_enabled":0,"tve_landing_page":"","_tve_header":"","_tve_footer":""},"categories":[16],"tags":[330,2726],"class_list":["post-6248","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-hashing-out-cyber-security","tag-authentication","tag-passwords","post-with-tags"],"views":8418,"jetpack_featured_media_url":"https:\/\/www.thesslstore.com\/blog\/wp-content\/uploads\/2018\/04\/bigstock-178217236.jpg","_links":{"self":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6248","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/users\/6"}],"replies":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/comments?post=6248"}],"version-history":[{"count":0,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/posts\/6248\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media\/6250"}],"wp:attachment":[{"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/media?parent=6248"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/categories?post=6248"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.thesslstore.com\/blog\/wp-json\/wp\/v2\/tags?post=6248"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}