3 ms·
I am surprised nobody has mentioned the FIDO Alliance and its Universal 2nd Factor, or it's successor work by the W3C. They're actively working on 'killing pass
by Rafert 10y ago
I am surprised nobody has mentioned the FIDO Alliance and its Universal 2nd Factor, or it's successor work by the W3C. They're actively working on 'killing passwords'.
U2F originated from Google when they wanted better 2FA for their internal services and they partnered with Yubikey to create the hardware. In a two years study it has been shown to be faster to easy, less prone to user error and more secure[1]. It's basically a client cert on a USB stick, but the standards allow for forms of other hardware as well.
U2F is a FIDO 1.0 standard, the 2.0 version is now being worked on by the W3C Web Authentication Working Group[2]. Microsoft has launched support for a draft of this spec in Windows 10 and Edge under the 'Windows Hello' banner[3].
[1]: https://www.yubico.com/2016/02/use-of-fido-u2f-security-keys-focus-of-2-year-google-study/ https://www.yubico.com/2016/02/use-of-fido-u2f-security-keys...
[2]: https://www.w3.org/blog/2015/11/w3c-fido/ https://www.w3.org/blog/2015/11/w3c-fido/
[3]: https://blogs.windows.com/msedgedev/2016/04/12/a-world-without-passwords-windows-hello-in-microsoft-edge/ https://blogs.windows.com/msedgedev/2016/04/12/a-world-witho...
- camillomiller 10y agoGeez, I even have a Yubikey and I didn't think of that. I use it so sporadically for my 2FA on gmail that it completely fell off of my mind...