The U.S. Department of Agriculture (USDA) has adopted FIDO authentication protocols to bolster its defenses against phishing attacks, marking a significant advancement in federal cybersecurity implementation. This move is part of the agency’s efforts to implement phishing-resistant multi-factor authentication (MFA) for employees who cannot use Personal Identity Verification (PIV) cards, aligning with President Biden’s executive order on strengthening federal cybersecurity.
The USDA’s workforce includes seasonal and specialized employees working in environments where PIV cards are not practical, such as forest service workers and field researchers. By integrating FIDO authentication, approximately 40,000 users can now securely access the agency’s systems without relying on traditional credentials. The FIDO protocols utilize public key cryptography and device-native biometric capabilities, making them significantly more resistant to credential theft and man-in-the-middle attacks compared to password-based systems.
The adoption of FIDO authentication standards has been growing rapidly in recent years, with significant momentum building around passkeys as a secure and user-friendly alternative to traditional passwords. Just two years after their introduction, passkey awareness has increased by 50 percent, from 39 percent in 2022 to 57 percent in 2024, reflecting growing public understanding of passwordless authentication benefits.
Major organizations across various sectors have embraced FIDO authentication standards. Mastercard has launched its Payment Passkey Service, eliminating the need for one-time passwords by leveraging device-native biometric capabilities, while Visa is implementing similar solutions. Samsung is integrating passkeys into smart home devices like TVs and refrigerators, demonstrating the technology’s versatility beyond traditional computing devices. In the aviation industry, Air New Zealand has transitioned to a fully passwordless authentication system using passkeys, showcasing the potential for large-scale enterprise deployment.
The FIDO Alliance reports that 20 percent of the world’s top 100 websites and services already support passkeys, indicating a significant shift towards passwordless authentication in the digital landscape. This adoption has been further accelerated by NIST’s recent inclusion of passkey considerations in its Digital Identity Guidelines, providing federal agencies with clear guidance for implementing these advanced authentication methods. The growing adoption is driven by several factors, including increased cybersecurity threats, consumer demand for user-friendly security, and the push for biometric authentication that offers both convenience and enhanced security.
Source: PaymentsJournal
–
December 4, 2024 – by Cass Kennedy
Follow Us