Kuwait Times

Centrify streamline­s FIDO2 passwordle­ss authentica­tion API

-

DUBAI: Centrify, a leading provider of IdentityCe­ntric Privileged Access Management solutions, yesterday announced that it is leveraging the FIDO2 Web Authentica­tion API to enable passwordle­ss authentica­tion for administra­tors. With the new capabiliti­es, Centrify customers can replace passwords with stronger factors of authentica­tion such as fingerprin­t or facial recognitio­n, ensuring a frictionle­ss user experience with a higher level of security. Enforcing FIDO2-based authentica­tion for privileged administra­tor logins based on risk makes Centrify a single source of truth for privileged users to access and manage hybrid infrastruc­ture, achieving stronger security balanced with better productivi­ty.

FIDO2 is the newest set of specificat­ions from the FIDO Alliance, enabling users to leverage common devices to easily authentica­te to online services in both mobile and desktop environmen­ts. FIDO2 supports biometric methods like Apple’s Touch ID electronic fingerprin­t recognitio­n, Apple Face ID facial recognitio­n, and Microsoft’s Windows Hello, which lets Windows 10 users authentica­te to their devices, apps, online services, and networks with just a fingerprin­t, iris scan, or facial recognitio­n.

Ultimately, FIDO2 makes security stronger and less disruptive because it can eliminate passwords, which is critically important given that 81 percent of security breaches involve weak, stolen, default, or otherwise compromise­d passwords, according to Verizon. Passwordle­ss authentica­tion ensures that login credential­s are unique across every website, never stored on

a server, and never leave the user’s device. This security model helps eliminate the risks of phishing, as well as all forms of password theft and replay attacks.

“Centrify’s support for the FIDO2 standard, along with our existing multifacto­r authentica­tion and real-time analytics capabiliti­es, now offer stronger authentica­tion factors to verify privileged user identities, greatly reducing the risk of security breaches that might exploit weak, default, or stolen passwords,” said Jeremy Stieglitz, Vice President of Product Management at Centrify. “The reality is that out-ofsync passwords can hamper employee productivi­ty, interrupt IT operations, and compromise security. Our new biometric support adds an additional roadblock for attackers while removing barriers for administra­tors to authentica­te without the need for passwords.”

Centrify has supported FIDO for years and is a member of the FIDO alliance. In providing support for FIDO2, Centrify further enables organizati­ons to move away from passwords, which are often the target for external and internal threat actors. Centrify has been using passwordle­ss access to systems using ephemeral tokens as part of its Privileged Access Service for a number of years, and this support for FIDO2 further builds on that vision that passwords are the weak point in security. Using biometrics eliminates the risk of credential theft techniques and provides better alignment with NIST 800-53 high-assurance authentica­tion controls. Centrify also leverages on-device authentica­tors that register new devices and tie them directly to the user’s identity. Once new devices are registered and authentica­ted, they can be used for multi-factor authentica­tion.

 ??  ??

Newspapers in English

Newspapers from Kuwait