WebAuthn
- Date:June 21, 2018
- Author(s):
- Kyle Marchini
- Test
- Report Details: 4 pages, 0 graphics
- Research Topic(s):
- Fraud Management
- Fraud & Security
- PAID CONTENT
Overview
In April 2018, the World Wide Web Consortium (W3C) advanced the Web Authentication (WebAuthn) standard to the Candidate Recommendation stage.
This standard defines an application programming interface (API) that can be incorporated into browsers to facilitate public key cryptography-based authentication on laptop and desktop devices. Developed in conjunction with the FIDO Alliance, WebAuthn is a core component of the FIDO2 Project.
Notably, this API offers organizations a framework that can completely obviate passwords in customer authentication, although a number of factors, including customer expectations and hardware limitations, render it unlikely that any organization will eliminate passwords in the near future. Under WebAuthn, the site authenticating the user is able to directly interface with the authenticator, with passwords never making an appearance in the process.
Book a Meeting with the Author
Related content
Synthetic 2.0: Evolving Identities Challenge Fraud Prevention
Synthetic identity fraud is a rapidly growing criminal ecosystem powered by stolen data, AI, and sophisticated fraud networks. As losses go unreported or are categorized as bad deb...
Who’s Scamming Whom? Scam Ad Revenue Surges on Social Media
Scam advertisements on social media platforms are increasingly industrialized, prompting international law enforcement operations from the newly created U.S. Scam Center Strike For...
Money Mules: The Fraud-Laundering Connection
Money mules are no longer just a money laundering problem. They now sit at the center of scams, identity fraud, payment fraud, and organized financial crime, helping criminals move...
Make informed decisions in a digital financial world