FIDO Alliance Introduces Fresh Protocol to Streamline Passkey Transfers Across Various Platforms

Oct 16, 2024Ravie LakshmananData Privacy / Passwordless

The FIDO Alliance announced its efforts to simplify the export of passkeys and other login details across multiple providers to enhance interoperability among credential providers.

FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms

Oct 16, 2024Ravie LakshmananData Privacy / Passwordless

FIDO Alliance Drafts New Protocol to Simplify Passkey Transfers Across Different Platforms

The FIDO Alliance announced its efforts to simplify the export of passkeys and other login details across multiple providers to enhance interoperability among credential providers. This move aims to make over 12 billion online accounts accessible through the passwordless sign-in method.

In line with this objective, the alliance unveiled a preliminary new set of technical specifications for secure credential exchange. These specifications were developed following agreements among members of its Credential Provider Special Interest Group (SIG).

Cybersecurity

The list of supported providers includes 1Password, Apple, Bitwarden, Dashlane, Enpass, Google, Microsoft, NordPass, Okta, Samsung, and SK Telecom.

“The FIDO Alliance is focusing on secure credential exchange to expedite the adoption of passkeys and improve the user experience,” stated the FIDO Alliance in a recent communication.

“Login sessions using passkeys reduce the risk of phishing attacks, eliminate password reuse, and make sign-ins up to 75% quicker and 20% more successful compared to traditional passwords or passwords coupled with a second factor like SMS OTP,” they added.

Although passkeys offer enhanced security and resistance to phishing attempts, they are typically tied to either the operating system or a specific password manager service, restricting users from transferring them when changing platforms. As a result, users are forced to create new passkeys for each device.

The newly proposed specification by the FIDO Alliance aims to bridge this gap through the introduction of the Credential Exchange Protocol (CXP) and Credential Exchange Format (CXF).

These specifications “establish a standardized format for securely transferring credentials—from passwords to passkeys—in a credential manager to another provider in a secure manner that ensures transfers are encrypted and secure by default,” as per the alliance.

Cybersecurity

These developments coincide with Amazon’s recent announcement that over 175 million customers have activated passkeys on their accounts, almost a year after the initial launch.

“The introduction of passkeys marks a significant improvement in how we access our online accounts. Amazon’s integration of passkeys demonstrates its dedication to enhancing its customers’ convenience and security on both its web and mobile shopping platforms,” commented Andrew Shikiar, CEO of FIDO Alliance.

Found this article captivating? Follow us on Twitter and LinkedIn for more exclusive updates.

About Author

Subscribe To InfoSec Today News

You have successfully subscribed to the newsletter

There was an error while trying to send your request. Please try again.

World Wide Crypto will use the information you provide on this form to be in touch with you and to provide updates and marketing.