Advertisements

Tuesday, 26 February 2019

FIDO2 certification for Android to make passwords obsolete

FIDO Alliance has announced that Android is now FIDO2 Certified, meaning, any compatible device running Android 7.0+ is now FIDO2 Certified out of the box or after an automated Google Play Services update. This gives users the ability to leverage their device’s built-in fingerprint sensor and/or FIDO security keys for secure passwordless access to websites and native applications that support the FIDO2 protocols. Web and app developers can now add FIDO strong authentication to their Android apps and websites through a simple API call, to bring passwordless, phishing-resistant security to end users who already have leading Android devices and/or will upgrade to new devices in the future. FIDO is already supported on web browsers including Google Chrome, Microsoft Edge, and Firefox. FIDO2 is comprised of the World Wide Web Consortium’s (W3C) Web Authentication specification and the corresponding Client to Authenticator Protocol (CTAP) from FIDO Alliance. Collectively, these standards enable users to more easily and securely log in to online services with FIDO2-compliant devices such as fingerprint readers, cameras and/or FIDO security keys. FIDO2’s simple user experiences are backed by strong cryptographic security that is transparent to the user and protects against phishing, man-in-the-middle, and attacks using stolen credentials. Brett McDowell, Executive Director, FIDO Alliance said: FIDO2 was designed ...