2022 15th International Conference on Information Security and Cryptography (ISCTURKEY) 2022
DOI: 10.1109/iscturkey56345.2022.9931832
|View full text |Cite
|
Sign up to set email alerts
|

Is FIDO2 Passwordless Authentication a Hype or for Real?: A Position Paper

Abstract: Operating system and browser support that comes with the FIDO2 standard and the biometric user verification options increasingly available on smart phones has excited everyone, especially big tech companies, about the passwordless future. Does a dream come true, are we finally totally getting rid of passwords? In this position paper, we argue that although passwordless authentication may be preferable in certain situations, it will be still not possible to eliminate passwords on the web in the foreseeable futu… Show more

Help me understand this report

Search citation statements

Order By: Relevance

Paper Sections

Select...
1

Citation Types

0
2
0

Year Published

2023
2023
2024
2024

Publication Types

Select...
3
2

Relationship

0
5

Authors

Journals

citations
Cited by 5 publications
(2 citation statements)
references
References 13 publications
0
2
0
Order By: Relevance
“…The recurring theme from the schemes reviewed suggests that a secure authentication system with great user experience appears to be a holy grail for security researchers, influencing the decision of technologies being combined in a myriad of ways to achieve the desired result. Conners et al (2022) [4] proposed the use of certificates issued by a CA (Certificate Authority) as an improvement to an existing password-less scheme-FIDO2 [10,11]. Considering that FIDO2 is dependent on hardware tokens and does not offer account recovery options besides registering at least a second token as backup, making it an expensive proposition, Conners et al (2022) [4], in their work, describe how certificates can address this gap, allowing users to potentially achieve password-less nirvana by combining a hardware token and a software authenticator, where the token is responsible for managing authenticators rather than authentication itself.…”
Section: Related Workmentioning
confidence: 99%
“…The recurring theme from the schemes reviewed suggests that a secure authentication system with great user experience appears to be a holy grail for security researchers, influencing the decision of technologies being combined in a myriad of ways to achieve the desired result. Conners et al (2022) [4] proposed the use of certificates issued by a CA (Certificate Authority) as an improvement to an existing password-less scheme-FIDO2 [10,11]. Considering that FIDO2 is dependent on hardware tokens and does not offer account recovery options besides registering at least a second token as backup, making it an expensive proposition, Conners et al (2022) [4], in their work, describe how certificates can address this gap, allowing users to potentially achieve password-less nirvana by combining a hardware token and a software authenticator, where the token is responsible for managing authenticators rather than authentication itself.…”
Section: Related Workmentioning
confidence: 99%
“…Important details for authentication protection include browser cross-checking domain origin hashes to prevent phishing attacks and using an incrementing counter to detect malicious imitations of authenticators [4].…”
mentioning
confidence: 99%