Tales from a Passkey Provider Progress from Awareness to Implementation.pptx

FIDOAlliance 404 views 18 slides May 15, 2024
Slide 1
Slide 1 of 18
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18

About This Presentation

FIDO Seminar RSAC 2024


Slide Content

Tales from a Passkey Provider Progress from Awareness to Implementation May 2024

Nick Steele Staff Product Manager 1Password Today’s speakers Shane Weeden Senior Technical Staff Member IBM Megan Shamas (moderator) Senior Director of Marketing FIDO Alliance

Agenda Where we’ve been Where we’re at What you can do Panel Q&A

Where have we been?

We are still Pioneers

And sometimes it feels like this

U2F/CTAP UAF CTAP2 WebAuthn Passkeys ✨ Verifiable Credentials 👋 2014

Passkeys in the news September 2022 : iOS16 officially brings passkeys to Apple devices. October 2023 : Google makes passkeys the default sign-in option for all users, significantly boosting adoption. April 2024: X (formerly Twitter) rolls out global support for passkeys on IOS. October 2023 : Amazon begins supporting passkeys for all users.

2023: The year of the 3rd Party Passkey Provider Weak and stolen credentials remain the number one cause of breaches. Passkey Providers are the new Password Manager! Trial users who interact with our passkey features are ~20% more likely to convert to paying customers than those who do not. With new solutions, come new problems! Platforms & Hardware Tokens have different needs. Relying Party as a Service continues to flourish. We

Where are we at?

2024: Regulations, Enterprise, and Beyond(Corp) 400 Million Google Accounts, over 1 Billion authentications. Passkeys are officially AAL2 compliant! But MFA, especially for regulation, is still lagging. Passkeys are a replacement for passwords (and sometimes need MFA) Both B2B and B2C are still struggling with UX and UI regarding passkeys, especially in regulated industries. Starting to be co-opted into Zero Trust architectures and decision-making.

Looking Ahead: FIDO UCEP and UCEF FIDO Universal Credential Exchange Protocol & Format Aims to help address current issues around lock-in, insecure import/export, and other issues related to moving different types of credentials. Not limited by passkeys, but motivated by passkeys. Currently working on proof of concepts and testing with 5 companies, Expect V1 to be published in the next few weeks!

What you can do?

Where do you Start? Check out some RPaaS! (Insert shameless plug for Passage here) If you’re thinking about building your own solution, here are a few things we’ve learned: Basic implementations are not hard. The challenge is accounting for fallbacks, account recovery, and device edge cases. WebAuthn is an evolving standard, so keep an eye out for changes that can improve user experience. Additions like PublicKeyCredentialDescriptor could make identifying providers much easier. Poor implementations can cause conversions to drop. Educating users is a huge part of the shift, and one of the biggest hurdles.

What about your organization? If you’re going the in-house route. Get started now or catch up later As new features get released, don’t aim for a moving target. Savings can be more motivating than Security Reduce SMS OTP Fees. Passkeys provide 50% faster logins, 64% increase in login success. Shopify merchants that enabled passkeys for shoppers saw an 8% increase in conversion.

Tales from the Trail

Thank you!
Tags