<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic WebAuthn gets approved!! in Tech Talk</title>
    <link>https://community.isc2.org/t5/Tech-Talk/WebAuthn-gets-approved/m-p/19842#M935</link>
    <description>&lt;P&gt;I've been a fan of FIDO and Yubico for years. I have 5 Yubi keys and am looking at getting a couple of their new units. I am NOT on the Yubico payroll in case you are wondering!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was announced that the &lt;A href="https://www.theverge.com/2019/3/4/18249895/web-authentication-webauthn-world-wide-web-consortium-w3c-standard-browsers" target="_blank" rel="noopener"&gt;Webauthn&lt;/A&gt; was approved.&amp;nbsp; This is huge.&amp;nbsp; There is no reason for the issues that exist now with password use to continue in the future. Software companies should insist on end users employing a key. If the user isn't interested then the access to that website isn't that important.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could be crippling my own daily use with this policy recommendation as I am not allowed any USB devices, cell phones, digital cameras, etc. at my location.&amp;nbsp; It would be worth it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MFA to the rescue!&lt;/P&gt;</description>
    <pubDate>Mon, 09 Oct 2023 09:08:04 GMT</pubDate>
    <dc:creator>Flyslinger2</dc:creator>
    <dc:date>2023-10-09T09:08:04Z</dc:date>
    <item>
      <title>WebAuthn gets approved!!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/WebAuthn-gets-approved/m-p/19842#M935</link>
      <description>&lt;P&gt;I've been a fan of FIDO and Yubico for years. I have 5 Yubi keys and am looking at getting a couple of their new units. I am NOT on the Yubico payroll in case you are wondering!&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;It was announced that the &lt;A href="https://www.theverge.com/2019/3/4/18249895/web-authentication-webauthn-world-wide-web-consortium-w3c-standard-browsers" target="_blank" rel="noopener"&gt;Webauthn&lt;/A&gt; was approved.&amp;nbsp; This is huge.&amp;nbsp; There is no reason for the issues that exist now with password use to continue in the future. Software companies should insist on end users employing a key. If the user isn't interested then the access to that website isn't that important.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;I could be crippling my own daily use with this policy recommendation as I am not allowed any USB devices, cell phones, digital cameras, etc. at my location.&amp;nbsp; It would be worth it.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;MFA to the rescue!&lt;/P&gt;</description>
      <pubDate>Mon, 09 Oct 2023 09:08:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/WebAuthn-gets-approved/m-p/19842#M935</guid>
      <dc:creator>Flyslinger2</dc:creator>
      <dc:date>2023-10-09T09:08:04Z</dc:date>
    </item>
    <item>
      <title>Re: WebAuthn gets approved!!</title>
      <link>https://community.isc2.org/t5/Tech-Talk/WebAuthn-gets-approved/m-p/19866#M936</link>
      <description>&lt;BLOCKQUOTE&gt;&lt;P&gt;&lt;SPAN&gt;It was announced that the &lt;/SPAN&gt;&lt;A href="https://www.theverge.com/2019/3/4/18249895/web-authentication-webauthn-world-wide-web-consortium-w3c-standard-browsers" target="_blank" rel="noopener"&gt;Webauthn&lt;/A&gt;&lt;SPAN&gt; was approved.&amp;nbsp; This is huge.&amp;nbsp; There is no reason for the issues that exist now with password use to continue in the future.&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Yes, it eliminates the risks of using passwords, and would certainly appeal to most people who don't want to have to handle complex passwords.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;P&gt;Software companies should insist on end users employing a key. If the user isn't interested then the access to that website isn't that important.&lt;/P&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;While that would be a significant enhancement to security, companies may not be eager to mandate it --- unless there are regulations to comply with or their services are limited to employees.&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;P&gt;&lt;SPAN&gt;MFA to the rescue!&lt;/SPAN&gt;&lt;/P&gt;&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;&lt;P&gt;Availing of WebAuthn by itself is a bit of a risk --- if you lose a key and don't have a backup you'll be locked out until a recovery can be done, which might take some time if you haven't set recovery options properly. It would certainly be wiser to combine this with other forms of authentication.&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2019 07:14:04 GMT</pubDate>
      <guid>https://community.isc2.org/t5/Tech-Talk/WebAuthn-gets-approved/m-p/19866#M936</guid>
      <dc:creator>Shannon</dc:creator>
      <dc:date>2019-03-07T07:14:04Z</dc:date>
    </item>
  </channel>
</rss>

