While any multifactor authentication (MFA) is beneficial, phishing-resistant options like passkeys are especially valuable, said Arynn Crow, senior manager of user authentication products for AWS identity. They provide a secure, user-friendly solution suitable for a wide range of users, from individuals to large enterprises.
“Using some form of multifactor authentication at all is the most important thing. But we especially recommend phishing-resistant authentication to everyone,” Crow told SDxCentral.
With the rise of credential-based exploits, phishing and social engineering attacks targeting users who rely on one-time PINs (OTPs) for MFA, passkeys are a great option to balance user experience and security for most people, she argues in a blog post.
Passkey “makes strong, phishing resistant authentication more accessible to all types of customer personas, from the individual developers … the smaller use cases, all the way up onto larger size enterprises,” Crow said.
What are passkeys? Passkeys are cryptographic tokens that use your face, fingerprint or device PIN to sign into accounts. They are stored on a user’s device and can be used to authenticate to websites and apps without the need for a password. Passkeys are more secure than passwords because they are not vulnerable to phishing attacks or data breaches. They are also more convenient because users do not need to remember or type in long and complex passwords.
Large tech companies are playing a leading role in the adoption of passkeys and their passwordless authentication. Apple rolled out its passkey option with the release of iOS 16. Google started the Passkey support on Chrome and Android devices in October 2022, and Microsoft and AWS have made passkeys available for their platforms since that same year.
Choosing the right authentication tools If organizations are already using another form of MFA like a non-syncable FIDO2 hardware security key or authenticator app, the question of whether or not migrating to syncable passkeys depends on an organization's specific needs and security requirements.
“It’s also important to understand that the passkey providers’ security model, such as what requirements the provider places for accessing or recovering access to the key vault, are now important considerations in your overall security model when you decide what kinds of MFA to deploy or to use going forward,” Crow pointed out.
Smaller customers and developers will benefit from the ease and security of passkeys, often without even realizing they are using them. For larger enterprises, factors such as regulatory obligations and threat models may influence the choice of MFA, she added.
“In our larger cases, like business work forces, there may be parts of their security model that suggest that syncable passkeys right now are not the most appropriate choice for them, if they have a consideration in a threat model that says that my users should not be able to sync and share their passkeys across devices or across users, that would be a reason to use a different form of phishing resistant authentication, like the hardware security keys, which are bound to the device that creates them,” Crow said.
“And then there are also the regulatory concerns … that may dictate what type of MFA they can use to meet their regulatory obligations,” she added.
AWS identity access management (IAM) supports passkeys Earlier this year, AWS started a program enforcing MFA for root user accounts within AWS Organizations — a tool designed to manage multiple AWS accounts. Building on this foundation, the cloud provider recently announced at re:Inforce that AWS IAM now supports passkeys as a secondary authentication method.
Addressing why AWS chose to support passkeys as a secondary rather than primary authentication factor, Crow explains, “Our main focus at this point in time with the campaign is to ensure that all of our customers have a second factor of authentication that is covered by multifactor authentication.”
“We're going to be listening to our customers and their feedback about how they would like to use passkeys in their security strategy and how they'd like to see it evolve, and we'll continue to iterate based on their feedback and how they'd like to see past keys be deployed,” she said.
Comments