FIDO UAF

From MgmtWiki
Jump to: navigation, search

Full Title or Meme

Universal Authentication Framework provides a guide for Fast ID Online (FIDO).

Content

The following is from the FIDO docs.

The UAF protocol allows online services to offer password-less and multi-factor security. The user registers their device to the online service by selecting a local authentication mechanism such as swiping a finger, looking at the camera, speaking into the mic, entering a PIN, etc. The UAF protocol allows the service to select which mechanisms are presented to the user.

Once registered, the user simply repeats the local authentication action whenever they need to authenticate to the service. The user no longer needs to enter their password when authenticating from that device. UAF also allows experiences

Problems

http://www.zeropasswords.com/pdfs/WHATisWRONG_FIDO.pdf

Solutions

References

  • Also see the page FIDO U2F for the 2nd factor description.