FB pixel

Biometric login with WebAuthn online authentication standard gets final W3C approval

Categories Access Control  |  Biometrics News
 

The Web Authentication (WebAuthn) specification has been accepted as an official web standard, according to an announcement from the World Wide Web Consortium (W3C) and the FIDO Alliance, making the option to log in to web services and apps with biometrics, mobile devices, or FIDO security keys an official W3C Recommendation.

WebAuthn is a standard for platforms and browsers for simple and strong authentication. It is a core component of the FIDO2 specifications, and is already supported by Windows 10, Android, Google Chrome, Mozilla Firefox, Microsoft Edge, as well as in preview by Apple Safari.

“Now is the time for web services and businesses to adopt WebAuthn to move beyond vulnerable passwords and help web users improve the security of their online experiences,” comments Jeff Jaffe, W3C CEO. “W3C’s Recommendation establishes web-wide interoperability guidance, setting consistent expectations for web users and the sites they visit. W3C is working to implement this best practice on its own site.”

A recent study from Yubico shows that the average user spends 10.9 hours per year entering and resetting passwords, costing companies millions, while stolen, weak, or default passwords are blamed for 81 percent of data breaches in Verizon’s 2017 Data Breach Investigations Report. Traditional multi-factor authentication (MFA) methods such as SMS one-time codes are still vulnerable to phishing, are not simple to use, and have low use rates, according to the announcement.

“The Web Authentication component of FIDO2 is now an official web standard from W3C, an important achievement that represents many years of industry collaboration to develop a practical solution for phishing-resistant authentication on the web,” said Brett McDowell, executive director of the FIDO Alliance. “With this milestone, we’re moving into the next phase of our shared mission to deliver simpler, stronger authentication to everyone using the internet today, and for years to come.”

A pair of FIDO Alliance standards were recently established as official ITU standards, and a recent report from Javelin sponsored by the FIDO Alliance shows the use of public key cryptography has increased dramatically over the past year.

Related Posts

Article Topics

 |   |   |   |   |   | 

Latest Biometrics News

 

Report demystifies India’s unique face biometrics market beyond the benchmarks

Biometric authentication is taking off in India as the country’s government and market align around identity as a trust layer…

 

Trust inevitable in building human rights-sensitive digital ID systems

Some digital rights advocates who spoke at the recent ID4Africa 2026 AGM in Abidjan emphasized that for African governments to…

 

Nepalese raise concerns over new DPI loans amid previous project failures

Some experts have expressed apprehensions that the government of Nepal has contracted a new loan for the implementation of a…

 

GripID introduces ultra-compact multimodal biometric enrollment kit

France-based GripID has unveiled the compact V10 multimodal biometric enrollment kit for registration to national ID and civil digital identity…

 

Australia opens feedback on verifiable credential policy, trust framework proposals

Australia’s Department of Finance is inviting community feedback on a policy for using verifiable credentials proposed by the Commonwealth. The…

 

FBI warning on Kali365 phishing kit exposes limits of weaker authentication

A new Federal Bureau of Investigation (FBI) warning about a phishing-as-a-service kit targeting Microsoft 365 accounts is underscoring why major…

Comments

Leave a Reply

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Biometric Market Analysis and Buyer's Guides

Most Viewed This Week

Featured Company

Biometrics Insight, Opinion

Digital ID In-Depth

Biometrics White Papers

Biometrics Events