The Password Problem
Passwords are broken:
- 81% of data breaches involve weak or stolen passwords (Verizon DBIR)
- The average user has 100+ passwords — and reuses them
- Phishing works because passwords are shareable secrets
FIDO’s thesis: Something you know is the weakest factor. Eliminate it.
How FIDO Works
FIDO authentication uses asymmetric cryptography — the same math that secures HTTPS (W3C WebAuthn).
Registration
sequenceDiagram
participant User
participant Browser as Browser (navigator.credentials.create)
participant Auth as Authenticator<br/>(TPM / Secure Enclave)
participant Server as Relying Party
User->>Browser: Click "Register FIDO key"
Browser->>Server: Request registration options
Server->>Browser: challenge + RP ID + user info
Browser->>Auth: Create key pair for origin + RP ID
Auth->>User: Verify presence (touch / PIN / biometric)
User->>Auth: Consent
Auth->>Auth: Generate key pair
Auth->>Browser: publicKey + credentialId + attestation
Browser->>Server: Send publicKey + credentialId
Server->>Server: Store publicKey for user
Server->>Browser: Registration complete
Browser->>User: FIDO key registered
Authentication
sequenceDiagram
participant User
participant Browser as Browser (navigator.credentials.get)
participant Auth as Authenticator
participant Server as Relying Party
User->>Browser: Click "Sign in with FIDO"
Browser->>Server: Request authentication challenge
Server->>Browser: challenge + RP ID (+ allowCredentials)
Browser->>Auth: Sign this challenge for RP ID
Auth->>User: Verify presence (touch / PIN / biometric)
User->>Auth: Consent
Auth->>Browser: { credentialId, signature, authenticatorData }
Browser->>Server: Send assertion
Server->>Server: Verify signature with stored publicKey
Server->>Server: Check RP ID + origin match
Server->>Browser: Authentication success
Browser->>User: Signed in
On registration:
- Your device generates a public/private key pair specifically for this website (RP ID)
- The private key stays on your device (secure enclave / TPM)
- The public key is sent to the server
To authenticate:
- The server sends a challenge: “Sign this random message”
- Your device signs it using the private key — only after you prove presence (touch, PIN, fingerprint)
- The server verifies the signature against your stored public key
FIDO2 / WebAuthn
FIDO2 is the latest specification, consisting of:
- WebAuthn — W3C standard API in browsers (
navigator.credentials.create()/.get()) - CTAP2 (Client-to-Authenticator Protocol) — How the browser talks to the hardware key (FIDO Alliance)
This means you can use a FIDO2 security key (like a YubiKey) or a platform authenticator (Windows Hello, Touch ID, Android fingerprint) without any drivers or plugins — it just works in Chrome, Safari, Firefox, and Edge.
Types of FIDO Authenticators
FIDO authenticators fall into two broad classes, each with different use cases (FIDO classifications):
Platform Authenticators (Internal)
Built into the device. Cannot be removed without destroying the hardware.
| Type | Examples | User Verification |
|---|---|---|
| Biometric | Touch ID, Face ID, Windows Hello, Android fingerprint | Fingerprint / face scan |
| PIN-based | Windows Hello PIN, device unlock code | Device PIN / password |
The private key is stored in the device’s secure enclave or TPM. Best for personal devices. If the device is lost, credentials are lost unless backed up via passkey sync.
Roaming Authenticators (Cross-Platform / Security Keys)
Portable hardware tokens that can be used across multiple devices.
| Transport | Example | Range | Typical Use |
|---|---|---|---|
| USB-A / USB-C | YubiKey 5, Google Titan | Wired | Desktops, laptops |
| NFC | YubiKey 5 NFC | Tap (< 10 cm) | Mobile phones |
| BLE | Feitian, SoloKey | ~10 m | Phones, tablets |
The private key lives on the token. User presence is proved by touching the key (USB), tapping (NFC), or pressing a button (BLE). Ideal for shared workstations, kiosks, and backup credentials.
User Verification Methods
| Method | FIDO Term | How It Works |
|---|---|---|
| Touch | userPresence (UP) | Tap the key or insert USB — minimal friction |
| PIN | userVerification (UV) | Enter PIN on device keypad or host |
| Biometric | userVerification (UV) | Fingerprint, face scan, iris — highest assurance |
Relying parties specify the required verification level via the userVerification parameter (required, preferred, discouraged).
Passkeys: Synced Authenticators
Passkeys (FIDO Alliance) are a third category: software authenticators whose private keys are synced (end-to-end encrypted) via the cloud provider’s keychain:
- Apple — iCloud Keychain (syncs across iPhone, iPad, Mac)
- Google — Google Password Manager (syncs across Android, Chrome, macOS, Windows)
- Microsoft — Windows Hello / Microsoft Authenticator
This solves the backup problem — lose your phone and your passkeys are still on your laptop. However, the key material is only as secure as the cloud provider’s E2EE implementation.
What Makes FIDO Phishing-Resistant
| Attack | Why It Fails |
|---|---|
| Phishing site | The key pair is scoped to the origin (https://example.com). It won’t sign for https://examp1e.com |
| Credential stuffing | No reusable password to stuff |
| Man-in-the-middle | The signature is bound to the specific challenge and origin |
| SIM swap | No SMS involved |
| Database leak | Only public keys are stored — useless to attackers |
Passkeys: FIDO Goes Mainstream
Apple, Google, and Microsoft have standardised on passkeys (FIDO passkeys) — FIDO credentials that sync across devices via the cloud. Instead of a password, you authenticate with Face ID / Touch ID / PIN, and the private key is synced (encrypted end-to-end) across all devices.
Passkeys are already supported on over 4 billion devices. They eliminate both phishing and password spray attacks by removing the shared secret entirely.
What FIDO Doesn’t Solve
- Account recovery — If you lose all devices with no backup, you can’t recover the key. Providers need fallback flows (recovery codes, secondary email).
- Legacy system integration — Older protocols (LDAP, RADIUS, NTLM) don’t speak WebAuthn. You need a broker or proxy.
- Cost of hardware keys — Software passkeys solve this, but high-assurance environments still want dedicated hardware tokens like YubiKey.
FIDO is the phishing-resistant MFA layer recommended in our OIDC/OAuth and PKI posts.
FIDO2 represents the first real opportunity to kill the password at scale. With passkeys baked into every major OS and browser, passwords are finally starting to fade.
References
- W3C WebAuthn Level 2 — Browser API specification
- FIDO Alliance Specifications — CTAP2, FIDO2, U2F
- FIDO Passkeys Overview
- YubiKey — FIDO2 Hardware Keys
- Verizon Data Breach Investigations Report
- Password Spray Attacks — Why FIDO eliminates the threat
- OIDC / OAuth — SSO with FIDO
- PKI Smart Cards & Challenge-Response