UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your Consumer Authentication Strategy

FIDOAlliance 361 views 41 slides Jul 16, 2024
Slide 1
Slide 1 of 41
Slide 1
1
Slide 2
2
Slide 3
3
Slide 4
4
Slide 5
5
Slide 6
6
Slide 7
7
Slide 8
8
Slide 9
9
Slide 10
10
Slide 11
11
Slide 12
12
Slide 13
13
Slide 14
14
Slide 15
15
Slide 16
16
Slide 17
17
Slide 18
18
Slide 19
19
Slide 20
20
Slide 21
21
Slide 22
22
Slide 23
23
Slide 24
24
Slide 25
25
Slide 26
26
Slide 27
27
Slide 28
28
Slide 29
29
Slide 30
30
Slide 31
31
Slide 32
32
Slide 33
33
Slide 34
34
Slide 35
35
Slide 36
36
Slide 37
37
Slide 38
38
Slide 39
39
Slide 40
40
Slide 41
41

About This Presentation

UX Webinar Series: Essentials for Adopting Passkeys as the Foundation of your Consumer Authentication Strategy


Slide Content

Passkeys: the Foundation of Consumer Auth Strategy

Kevin Goldman Mitchell Galavan Chief Experience Officer Trusona Co-chair , UX Working Group FIDO Alliance Lead Authentication UXD Google Co-chair, UX Working Group FIDO Alliance James Hwang Senior Product Designer Microsoft UX Working Group FIDO Alliance

Welcome to the webinar All attendees are in listen-only mode Ask your questions in the question widget! The webinar is being recorded The webinar recording will be emailed to you and published following the event Please stay on to take the survey at the conclusion of the webinar

Passkey Design Webinar Series Join live or view on-demand! JUNE 18 Aligning Authentication Experiences with Business Goals Learn how to adapt your authentication experiences to better solve key metrics for consumer authentication. JUNE 25 Drive Revenue & Decrease Costs with Passkeys Learn how to drive revenue and decrease costs with passkeys for consumer authentication. JULY 2 Passkeys Design Guidelines: AMA (ask me anything!) The floor is yours to ask FIDO Alliance subject matter experts anything in an: “Ask Me Anything” format. 

Why passwords aren’t working

📝 Passwords are difficult for users to deal with Users often forget passwords and find them hard to manage. Paper is the go-to method for storing them.

💭 Passwords are easy to guess Around 33% of users in the US report having attempted to guess someone else’s password… with 73% of those attempts being successful!

🔁 Passwords tend to be reused Recycling passwords is risky, but it’s a symptom of how difficult it is to create & recall unique things every time Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123 Password123

Users are ready to move on from passwords

IT leaders globally agree: passwords are a weak way to secure data Source: Statista Source: Ping

Utilizing device biometrics or screen lock eliminates the hassle of recalling and entering credentials With passkeys, we can say goodbye to issues with fields being auto-filled incorrectly! Passkeys can help your service appear even more accessible and user-friendly Passkeys can simplify how users sign in

Transformation

Before: Find a place taxis might be Hail the taxi Explain where you want to go Understand what the cost may be Travel Understand what the cost is Pay by cash or credit card Wait for receipt or change Arrive After: (Previously) e nroll in the service Book (destination + costs + wait time) Travel Arrive

Before: Remember username Type username correctly Remember password Type password 40% to 65% re-type password Submit After: (Previously) enroll a passkey Gesture (same as unlocking device) 40+ actions 1 actions

Password sign in Passkey sign in

Why is Microsoft all in on passkeys?

115 attacks per second in 2015 4,000+ attacks per second in 2024 Password attacks are increasing

Passwordless is the way to go

Our passwordless journey

We love passkeys Easy to use while being more secure Standards based and i nteroperable across platforms Anticipated to save millions in SMS costs Simplifies our recovery story

Why is Google all in on passkeys?

Used over 1 billion times across 400 million Google Accounts Easy to use and phishing resistant 50% faster than passwords We are seeing signs of success at Google

Growing industry support for passkeys In just the last 12 months, Amazon, 1Password, Dashlane, Docusign, Kayak, Mercari, Shopify and Yahoo! JAPAN have started rolling out passkeys, joining early adopters like eBay, Uber, PayPal and Whatsapp. In fact, Dashlane is seeing a 70% increase in conversion with passkeys and Kayak users are signing in 50% faster than before.

Lost passwords creates support tickets, which creat churn and cost for support teams Passkeys are more phishing resistant than today’s authentication mods, putting users in more control of their accounts Passkeys are the only sustainable authentication method

Accessibility is improved with passkeys as authentication is handled at the platform level by a handful of Identity Providers. This eases pressure on each website to make usernames, passwords, and multi-factor screens accessible: we can help ensure accessibility from the start. Passkeys have accessibility built in

When a security process is transparent, easy-to-follow, and hassle-free, users are more likely to trust that their data is being handled securely. This is crucial for any system that aims to manage identity and authentication. Feeling safe is as important as being safe. Passkey authentication can build trust

Fast sign in wins users Why would a user go through the hassle of signing in, if they can get to a close enough outcome or experience without signing in? Is all this work to sign in really worth it? ***

First device Second device or service Example factors Generalized 2SV/MFA sign in journey This can have lots of permutations. SMS or the need for extra hardware can be a barrier.

Passkeys journey Sign in with a passkey Local passkey Passkey from another device

Design Guidelines

FIDO Alliance UX Working Group AgileBits, American Express, Apple, ASSA ABLOY, Axiad, Beyond Identity, Bitwarden, BlinkUX, CVS Health, Daon, Dashlane, Docusign, Duo, eBay, FIME SAS, Google, Guangdong, Huawei, IBM, Idemia, Intuit, JP Morgan Chase, Keeper Security, LastPass, Lenovo, Liaison, Mastercard, Mercari, Meta, Microsoft, Nok Nok, Okta, OneSpan, PayPal, RSA, Samsung, Sony, Swissbit, Target, TTA, TikTok, Trusona, U.S. Bank, VinCSS, Visa, Wells Fargo, Yubico Third party UX research firm: Blink FIDO Alliance member underwriters:

How FIDO produces Design Guidelines Curated 270 passkey touchpoints documented Grouped 7 themes identified Selected 6 design patterns to pursue in 2024 Built prototypes and ideated experiences Tested with a third party UX research firm and real users Publish 14 total patterns that drive business outcomes … 6x repeat … Consumer use case (unregulated), 16 U.S. consumers, iOS, Android, Windows, 8 service providers Audited 8 well-known passkey deployments

What’s included?

Get all the guidelines! fidoalliance.org/ design-guidelines

O pportunities

O pportunities Password first attacks are growing; protect you and your users Reduce phishing, credential stuffing, available attack surfaces Reduce costs like SMS and IT support for password resets Reduce abandonment (cart, sign in, after app download) and signed out users by lowering friction Customer loyalty and retention Increase ease of use, accessibility, and faster sign-in speed

Proven success 30% opt-in in first 24 hours 4.7x improvement time to complete & improvement in success rate 50% reduction in abandonment rates Reduced account recovery calls and call center attacks 4x improvement in sign-in success rate (vs passwords) ½ the sign-in time Passkeys have been used to authenticate people more than 1 billion times across over 400 million Google Accounts Within the first few months… 97% login success rate 14% eligible user adoption rate 2% reduction in SMS OTP login Sign-in success rate grew from 67.7% (SMS 2FA) to 82.5% -- over a 21% improvement Authentication time decreased from 17s (SMS 2FA) to 4.4s – nearly 4x faster

Q&A

Thank you!
Tags