#webauthn

6 posts · Last used 15d

Back to Timeline
World Wide Web Consortium @w3c@w3c.social · Jul 30, 2026
The W3C Team proposes advancing Web Authentication: An API for accessing Public Key Credentials Level 3 to W3C Recommendation. This specification was published by the Web Authentication Working Group as a Candidate Recommendation Snapshot on 26 May 2026. It defines an API enabling the creation and use of strong, attested, scoped, public key-based credentials by web applications, for the purpose of strongly authenticating users. https://www.w3.org/news/2026/proposed-advancement-of-webauthn-3-to-w3c-recommendation/ #WebAuthn #WebStandards
10
1
11
Scott Wilson 🌈 @scottwilson@infosec.exchange · Jul 24, 2026
Friends, I need some help and advice. Microsoft recently announced retirement of Microsoft-provided SMS and voice authentication in Entra ID. Of course, "good", you say -- me, too. But I'm working with an organization that has some extremely non-techie employees, and I've got to figure out the easiest path to help them get properly on-boarded with Passkeys. Microsoft Authenticator seems to support Passkeys natively (the key is stored IN MS Authenticator). Is this the best way to do this? My non-techie users are primarily mobile phone users on Exchange Plan 1 (no "fat" client). Help! #passkeys #webauthn #fido #microsoft #mfa #lazyweb #help References: https://www.microsoft.com/en-us/security/blog/2026/07/13/microsoft-entra-id-security-updates-passkeys-are-the-default-authentication-method-in-entra-id/ https://mc.merill.net/message/MC1426371
0
0
0
Zimmie @bob_zim@infosec.exchange · Jul 21, 2026
Two of my banks recently implemented #passkeys, and the contrast between them is stark. I went to log in to one and they wouldn’t let me in until I “verified my identity” using a text message code to a phone number they apparently got from some data broker or by uploading my government ID and a video (obviously not happening). When I eventually got their support to let me in, the site forced passkey setup with no options at all. There’s no way to set up more than one passkey, no way to revoke access from the one I set up, and no way to log in via password anymore. They made every single decision in the most incorrect way possible. Utter garbage. Unfortunately, they’re the only option available to me for the particular account I have, so I’m stuck with them. Meanwhile, Wealthfront reopened a support ticket I filed years ago requesting passkey support to let me know they had added it. I logged in with a password, and the site offered to set up a passkey. In my user profile’s authentication page, there’s a section listing all my passkeys (and app-specific password names, etc.). It allows me to specify friendly names to track which is which, add more, and remove keys I no longer control. It’s pretty much perfect! #passkey #webauthn
0
0
0
IAMDevBox @iamdevbox@mastodon.social · Jul 15, 2026
0
0
0
IAMDevBox @iamdevbox@mastodon.social · Jul 13, 2026
Explore how to implement robust multi-factor authentication using TOTP and WebAuthn to enhance your application's security. https://iamdevbox.com/posts/building-multi-factor-authentication-with-totp-and-webauthn/?utm_source=mastodon&utm_medium=social&utm_campaign=blog_post #security #mfa #totp #webauthn
0
0
0
Daily CyberSecurity @DailyCyberSecurity@infosec.exchange · Jul 02, 2026
A critical OpenAM WebAuthn RCE flaw (CVE-2026-45051) allows code execution via Java deserialization. Update OpenAM to 16.1.1 to stay protected. #OpenAM #WebAuthn #RCE #CVE202645051 #CyberSecurity #InfoSec https://securityonline.info/openam-webauthn-rce/?utm_source=mastodon&utm_medium=jetpack_social
0
0
0

You've seen all posts