Some in the cybersecurity landscape are betting that passkeys are just around the corner as a replacement for password authentication, and I couldn’t agree more. Today, organizations are embarking on a password-less journey to deliver a frictionless and secure modern user experience (UX) in their Customer Identity and Access Management (CIAM) stacks. In this blogpost, I will tell you why you should be using, or at least thinking about, passkeys as part of your CIAM password-less journey.
Customers want to know their data is safe. IBM has reported that in 2022, the average cost of a data breach to be over 9 million dollars, mostly attributed to compromised passwords. [1]
In order to combat this threat, security teams have put in place strong authentication flows with password policies that require more stringent passwords and additional steps in the flow with MFA. Even with these endeavors, compromised passwords are still plaguing the industry.
Consumers don’t want a lot of friction when signing up for or signing in to their account. If they get frustrated with the user interface, they may choose to go elsewhere, which will result in lost revenue for you. For every dollar you invest in your user experience, your company can earn additional revenue due to less abandonments and more customer loyalty.
A survey of 3,400 consumers in the U.S., UK, Australia, France and Germany conducted by Ping Identity and Wakefield Research in mid-2021 found that “56% of online consumers have abandoned an online service when logging in was too frustrating,” and that “63% of consumers are likely to leave an online service for a competitor who makes it significantly easier to authenticate.” [2]
The short answer is a resounding: Yes! In March 2022, the FIDO Alliance – an industry group dedicated to “solving the world’s password problem”, which Apple, Google and Microsoft belong to – announced that they created a way to store digital keys securely and let them sync between users’ devices, which they called “multi-device FIDO credentials” or simply “passkeys”. [3] Passkeys solve the problem by making the process simpler and stronger by using asymmetric (public-key) cryptography for multi-factor authentication.
A FIDO alliance survey of over 1000 consumers conducted by NextTech Communication during beginning of 2023 provided the following key points as part of an Executive Summary [4]:
Each passkey consists of two interlocking parts (Public key cryptography). The first part, the private key, is bound to a trusted platform module (TPM) and synced with the user’s platform account such as the iCloud key chain. The second part, the public key, is shared with the application or website that you have an account with. When you want to sign in, your device will prompt you to verify your identity using biometrics. Both parts of your passkey are then used to generate an authentication token for the app or website you’re signing in to.
There are certain requirements that must be met to support Passkey usage:
Now that you know the benefits and have a general understanding of what is involved with implementing passkeys, let me demonstrate how you can use PingOne’s Davinci service to make this a reality:
PingOne’s DaVinci service is an orchestration identity platform that uses a visual programming drag and drop interface. This allows you to create a seamless UX as part of your consumer sign-up and sign-in flows without having to write your own code.
All you need to do is embed a javascript widget in your web application that reaches PingOne Davinci Cloud service for login and registration flows. The PingOne Davinci cloud service can do all the heavy lifting by implementing the previously mentioned requirements while choreographing a great UX.
Get in contact with our iC Consult experts so we can help you understand passkeys more in-depth and how to implement them as part of your CIAM journey. We can show you a demo of a typical CIAM implementation that uses passkeys to provide a seamless, more secure IDAM environment and help you plan or get you started with your CIAM passkey journey. What are you waiting for? Your consumers will appreciate the seamless experience. Don’t let your competitors beat you to this game changing technology.