21581 - SCTE Broadband August2022 COMPLETE v1

16 Vol. 44 No. 3 - September 2022 Issue The recent announcement from the FIDO Alliance promises to do away with post-it notes, memorable words and password-reset emails clogging up your in-box, as soon as next year. Forgetful people the world over will be dancing in the streets. Surely it can’t be that straightforward? Melissa Cogavin reports. Forgot Password? As the Digital Revolution and daily life rattle along at breakneck speed, between software updates and handset upgrades it’s easy to miss the little details. Those small announcements that pop up on your phone fleetingly and are gone almost immediately (often hard to find again afterwards or is that just me), such is the nature of 24 rolling news, the never-ending onslaught of over-reaction to the smallest event, driven by the media whose life depends on your outrage. It is unsurprising therefore, that the FIDO Alliance press release perhaps did not receive the attention it deserves. It should have received a lot more. FIDO stands for Fast Identity Online and is an industry association launched in February 2013, based in Oregon, in the US. FIDO’s membership is jaw- dropping: containing the world’s largest and most prestigious brands and the most recognisable household names, on the Board alone sits Amazon, American Express, Apple, Intel, Google, Meta, Microsoft, PayPal, Samsung, Mastercard and VISA. FIDO’s mission is to “develop and promote authentication standards that “help reduce the world’s over-reliance on passwords”. FIDO addresses the “lack of interoperability among devices that use strong authentication and reduces the problems users face creating and remembering multiple usernames and passwords.” Andrew Shikiar, CEO of FIDO, broke it down for Broadband Journal. “There are three forms of online authentication. It’s essentially what you know, like a password, which is knowledge-based. Then there is what you have, which is proven possession, like your date of birth or zip code. Then finally it’s who you are, which is inherent, and that’s your biometric (your fingerprint, your voice, your face). Multifactor authentication has, by definition, two of those things. Our initial second factor thing is a what you know plus what you have. But all you’re doing is literally touching this thing. It’s proving that you’re in possession of the device.” Shikiar says this new announcement means there is “a new approach on top of the existing FIDO specs that are being taken by Apple, Google and Microsoft, that will allow for the private key to be securely synced across their device cloud. Such that if you log on with one device, say your MacBook, and you log into your bank account there, then you log into Amazon via your phone, for example, then you go to your other MacBook, all you need to do is present your biometric and your logged into that website immediately.” Jared Newman, a US based technology journalist summed the transition up this way in a recent article in Fast Company magazine. “Imagine, for instance, that you want to create a Twitter account. Rather than making you set up a password scte long read By Melissa Cogavin, Managing Editor, SCTE

RkJQdWJsaXNoZXIy OTIxNzg=