On the morning of May 31, on World Password Day in early May, the security agency FIDO received new support from Apple, Google, and Microsoft, and these major technology companies announced that they are expanding their support for password-free login standards. Users may no longer have to enter passwords, but some people are worried that a world without passwords may further lock users into the Apple and Google ecosystems.
Ben Lovejoy, an author of foreign media 9to5mac, discussed this matter.
“A world without passwords”
A world without passwords is the mission of the FIDO Alliance (Fast IDentity Online).
Currently, to log into a website or app, we usually enter our username and password. Passwords have been a terrible form of security for years — and become even more so with every additional service we use. Security questions, as a crude form of authentication, are also a mess.
What FIDO does is allow our devices to authenticate users. Taking the iPhone that supports face recognition as an example, the logic is as follows:
The website or app asks you to identify and prove your identity.
Your iPhone will receive the request and activate Face ID.
If the faces match, the iPhone tells the website who you are and allows entry.
There are no passwords involved: Authentication is performed on the device, not on the website server. The web server trusts the user's iPhone, a bit like a payment terminal trusts the phone so that Apple Pay transactions don't require a password.
As early as 2019, Apple tried this approach and began to support the FIDO standard. Other technology giants have also begun to support it, such as Amazon, Arm, Facebook, Google, Intel, Microsoft and Samsung. FIDO board members include financial institutions such as American Express, ING, Mastercard, PayPal, Visa and Wells Fargo.
Device-to-device authentication does remove the need for a password. However, there is currently no mention of switching between ecosystems in the standard. The key is stored on the user's device, which could be a bit problematic if you want to switch from an iPhone to an Android phone, or vice versa.
FIDO's current solution does not have a mechanism for bulk transfer of keys between ecosystems. If you want to switch from an Android phone to an iPhone (or vice versa), you can't move all your keys. Passwords, by contrast, are much easier to transfer.
“We don’t really have a bulk export method right now,” said Andrew Shikiar, executive director of the FIDO Alliance. “I think that could be a future iteration.”
In theory, this is an easy problem to solve: just allow passwords to be exported and imported in the same way as passwords are today. But given that FIDO is meant to be more secure than passwords, the alliance is reluctant to allow this. If users can easily import/export all their keys between devices, hackers could potentially exploit this feature.
This limits users to the current ecosystem and makes it difficult for them to switch systems.
Previous article:Tap to Pay feature begins trial in US Apple Stores
Next article:Apple's antitrust lawsuit against Cydia, a jailbreak app store, was rejected
Recommended ReadingLatest update time:2024-11-16 13:57
- Apple faces class action lawsuit from 40 million UK iCloud users, faces $27.6 billion in claims
- Apple and Samsung reportedly failed to develop ultra-thin high-density batteries, iPhone 17 Air and Galaxy S25 Slim phones became thicker
- Micron will appear at the 2024 CIIE, continue to deepen its presence in the Chinese market and lead sustainable development
- Qorvo: Innovative technologies lead the next generation of mobile industry
- BOE exclusively supplies Nubia and Red Magic flagship new products with a new generation of under-screen display technology, leading the industry into the era of true full-screen
- OPPO and Hong Kong Polytechnic University renew cooperation to upgrade innovation research center and expand new boundaries of AI imaging
- Gurman: Vision Pro will upgrade the chip, Apple is also considering launching glasses connected to the iPhone
- OnePlus 13 officially released: the first flagship of the new decade is "Super Pro in every aspect"
- Goodix Technology helps iQOO 13 create a new flagship experience for e-sports performance
- Innolux's intelligent steer-by-wire solution makes cars smarter and safer
- 8051 MCU - Parity Check
- How to efficiently balance the sensitivity of tactile sensing interfaces
- What should I do if the servo motor shakes? What causes the servo motor to shake quickly?
- 【Brushless Motor】Analysis of three-phase BLDC motor and sharing of two popular development boards
- Midea Industrial Technology's subsidiaries Clou Electronics and Hekang New Energy jointly appeared at the Munich Battery Energy Storage Exhibition and Solar Energy Exhibition
- Guoxin Sichen | Application of ferroelectric memory PB85RS2MC in power battery management, with a capacity of 2M
- Analysis of common faults of frequency converter
- In a head-on competition with Qualcomm, what kind of cockpit products has Intel come up with?
- Dalian Rongke's all-vanadium liquid flow battery energy storage equipment industrialization project has entered the sprint stage before production
- Allegro MicroSystems Introduces Advanced Magnetic and Inductive Position Sensing Solutions at Electronica 2024
- Car key in the left hand, liveness detection radar in the right hand, UWB is imperative for cars!
- After a decade of rapid development, domestic CIS has entered the market
- Aegis Dagger Battery + Thor EM-i Super Hybrid, Geely New Energy has thrown out two "king bombs"
- A brief discussion on functional safety - fault, error, and failure
- In the smart car 2.0 cycle, these core industry chains are facing major opportunities!
- The United States and Japan are developing new batteries. CATL faces challenges? How should China's new energy battery industry respond?
- Murata launches high-precision 6-axis inertial sensor for automobiles
- Ford patents pre-charge alarm to help save costs and respond to emergencies
- New real-time microcontroller system from Texas Instruments enables smarter processing in automotive and industrial applications
- 1602 display dht11 temperature and humidity
- CircuitPython 6.1.0 released
- 【RT-Thread Reading Notes】+ Pain and Happiness
- Data acquisition technology based on SDI-12 bus (communication protocol)
- 04. WS2812B driver implementation of SPI
- 315Mhz wireless module microcontroller soft decoding receiving program
- Learning experience of MSP430F5529 clock module
- Noise suppression solution example in automotive power circuits
- How can wireless monitoring systems minimize latency?
- Power amplifier circuit composed of operational amplifier and NMOS