无密码登录

Passwords have been the root cause of all major security and privacy breaches. But this is about to change once passwordless logins are implemented on a worldwide scale. Recently, the World Wide Web Consortium (W3C) and the FIDO Alliance announced a new authentication standard – Web Authentication (WebAuthn) specification – for the web and other platforms.

The World Wide Web Consortium (W3C) is an international community that operates under a code of ethics and the professional conduct to develop open standards and also to ensure the long-term growth of the Web. The FIDO Alliance is also an open industry association made of tech giants with a mission of developing authentication standards to help reduce the world’s over-reliance on passwords.

什么是无密码登录?

As the name suggests, it’s a way of login into your accounts without using passwords. This method uses the Web Authentication (WebAuthn) specification which is part of the FIDO2 specification. That’s, FIDO2 specifications use the W3C’s Web Authentication specification (WebAuthn) and FIDO’s corresponding Client-to-Authenticator Protocol (CTAP) to authenticate users to online services via commonly used devices easily. WebAuthn gets rid of passwords and instead it employs the use of one-time auth tokens each time you log in.

Instead of passwords, two major forms of authentication are used; biometrics – such as fingerprints and facial recognition – and also hardware security tokens such as USB keys.

无密码登录如何操作?

In a nutshell, passwordless logins work by having a trusted authenticator, i.e., your fingerprint sensor or hardware token. When you log into sites or apps that support passwordless logins, you will be asked to prove your identity. For instance, the browser or the app will require the trusted authenticator to prove who you are – you will then be required to scan your fingerprint or your face or insert your hardware token. After you have scanned your fingerprint or provided the token, you have proven your identity.

Unlike passwords which require you to be online for authentication, your fingerprint stays on your device, and this minimizes phishing risks. 

无密码登录的好处

According to the FIDO alliance, passwordless logins are the ultimate solution that averts password phishing, theft and even replay attacks. Also entering passwords is a time-consuming endeavor that also drains resources. Here are some WebAuthn benefits according to FIDO;

  • Security: FIDO2 cryptographic login credentials are unique across every website, biometrics or other secrets like passwords never leave the user’s device and are never stored on a server. This security model eliminates the risks of phishing, all forms of password theft and replay attacks.
  • Privacy: Because FIDO cryptographic keys are unique for each internet site, they cannot be used to track users across sites.
  • Convenience: Users log in with simple methods such as fingerprint readers, cameras, FIDO security keys, or their personal mobile device.
  • Scalability: websites can enable FIDO2 via simple API call across all of supported browsers and platforms on billions of devices consumers use every day.

在哪里可以使用无密码登录?

您可以在任何支持的平台上使用这种登录方式。目前,Windows 10、运行 Android 7 或更高版本的 Android 设备、Mozilla Firefox、Google Chrome、Apple Safari 和 Microsoft Edge 都支持这种登录方式。此外,许多应用程序(尤其是银行应用程序)都采用了这种登录方式。例如,PayPal 可以让您使用指纹通过应用程序登录。

Use a VPN if there’s no passwordless login – IPBurger VPN

IPBurger VPN uses the unbreakable AES 256 bit standard to encrypt your internet traffic. This secures your passwords and other login information as they traverse the internet to their destination. This encryption ensures prying eyes such as cybercriminals have no access to your data. And if they intercept it, they won’t be able to decrypt it since they won’t have the key.

在本文中:
告别复杂的网络搜索。
选择 IPBurger 先进的网络智能解决方案,轻松收集实时公共数据。
注册

更深入地了解

代理
AJ Tait
可靠性、速度和透明度最佳的 HydraProxy 替代方案

为什么越来越多的用户在寻找 HydraProxy 替代品 乍一看,HydraProxy 似乎是一个不错的选择。它价格实惠,提供旋转和静态的住宅代理服务器,并通过 "即用即付 "的定价方式为用户提供灵活性。对于普通用户来说?这就足够了。但对于数据刮擦人员、运动鞋抄袭者、搜索引擎优化专家和自动化用户来说,他们需要

代理
AJ Tait
道德、可扩展和高性能代理的最佳 Rayobyte 替代方案

为什么越来越多的用户在寻找Rayobyte的替代品 Rayobyte作为一个受人尊敬的代理服务器供应商,为需要大量IP的企业和个人提供数据中心、ISP和住宅代理服务器。凭借极具竞争力的价格和多种代理类型,它已成为许多网络用户的首选。

利用全球最先进的
代理扩展您的业务
加入屡获殊荣的第一代理网络