{"id":15535,"date":"2024-10-17T12:56:48","date_gmt":"2024-10-17T16:56:48","guid":{"rendered":"https:\/\/authenticatecon.com\/?p=15535"},"modified":"2024-10-23T17:35:38","modified_gmt":"2024-10-23T21:35:38","slug":"authenticate-2024-day-3-recap","status":"publish","type":"post","link":"https:\/\/authenticatecon.com\/authenticate-2024-day-3-recap\/","title":{"rendered":"Authenticate 2024: Day 3 Recap"},"content":{"rendered":"\n<p>By: FIDO staff<\/p>\n\n\n\n<p>The third and final day of Authenticate 2024 was another jam-packed bonanza of content and insights. If you missed Day 1, <a href=\"https:\/\/authenticatecon.com\/authenticate-2024-day-1-recap\/\" target=\"_blank\" rel=\"noreferrer noopener\">check out the recap here<\/a>. The recap for <a href=\"https:\/\/authenticatecon.com\/authenticate-2024-day-2-recap\/\" target=\"_blank\" rel=\"noreferrer noopener\">Day 2 is here<\/a>.<\/p>\n\n\n\n<p>Multiple users came up on the stage to detail how passkeys have made a difference in consumer, enterprise, and government use cases, and what lessons have been learned. There was also a \u201cPasskeys for Payments\u201d track, where speakers from Visa and Mastercard detailed the challenges and opportunities in the space. Digital identity was another core theme of the day with multiple sessions and a final keynote panel.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"404\" height=\"352\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.49.14\u202fAM.png\" alt=\"\" class=\"wp-image-15536\" style=\"width:162px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.49.14\u202fAM.png 404w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.49.14\u202fAM-300x261.png 300w\" sizes=\"auto, (max-width: 404px) 100vw, 404px\" \/><\/figure>\n<\/div>\n\n\n<p>Among the many users that spoke was Elizabeth Beasley, Senior Content Designer at<strong> <\/strong>Intuit. She shared insights on implementing passkeys, emphasizing the importance of organization and user testing.&nbsp;<\/p>\n\n\n\n<p>User Experience (UX) really matters too, and to that end, Beasley stressed the value and importance of the FIDO UX Working Group and the passkeys design guidelines that it has produced.&nbsp;<\/p>\n\n\n\n<p>&#8220;When you go to <a href=\"http:\/\/passkeycentral.org\" target=\"_blank\" rel=\"noreferrer noopener\">passkeycentral.org<\/a>, you can see the stuff that this group has helped create, and we&#8217;re going to keep creating more,&#8221; Beasley said.&nbsp;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">How Swiss Marketplace Group (SMG) is Embracing Passkeys<\/h2>\n\n\n\n<p>Swiss Marketplace Group (SMG) is a group of marketplaces based in Switzerland. SMG is implementing and rolling out passwordless authentication for its workforce to reduce risk and improve security as well as user experience.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"484\" height=\"432\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.50.41\u202fAM.png\" alt=\"\" class=\"wp-image-15537\" style=\"width:159px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.50.41\u202fAM.png 484w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.50.41\u202fAM-300x268.png 300w\" sizes=\"auto, (max-width: 484px) 100vw, 484px\" \/><\/figure>\n<\/div>\n\n\n<p>Mikel Grabocka, Security Architect, Identity and Trust at SMG Swiss Marketplace Group AG, explained that the passkey rollout is happening across the company&#8217;s users. The target state is to have passwordless alongside managed devices across the entire company.<\/p>\n\n\n\n<p>The initial rollout has been very strong, with 30% of eligible users adopting passwordless within the first month of it being available. He noted that the key focus for the deployment is taking a gradual, well-documented, and iterative approach, with a strong emphasis on user awareness and adoption. SMG plans to have 100% of its employees passwordless by the end of the year.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Bringing Passkeys to DocuSign&nbsp;<\/h2>\n\n\n\n<p>DocuSign, one of the world&#8217;s leading e-signature providers, is also adopting passkeys.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"396\" height=\"358\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.51.17\u202fAM.png\" alt=\"\" class=\"wp-image-15538\" style=\"width:159px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.51.17\u202fAM.png 396w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.51.17\u202fAM-300x271.png 300w\" sizes=\"auto, (max-width: 396px) 100vw, 396px\" \/><\/figure>\n<\/div>\n\n\n<p>&#8220;Safety and trust is the foundation of everything that we do,&#8221; Sarah Zou, lead product manager at DocuSign said. &#8220;That&#8217;s why we decided to invest in passkey. We wanted to make sure the first step of getting users into the signing ceremony, they feel welcome with a seamless protected experience, knowing that they&#8217;re using the most innovative new industry standard &#8211; passkey.&#8221;<\/p>\n\n\n\n<p>DocuSign has also implemented passkey as a service, allowing the company to leverage it beyond just the login flow. DocuSign is using passkey to unlock other use cases, such as the DocuSign ID Wallet in the European market. The ID Wallet allows users to create, manage, and store their digital identity, which can then be used for identity verification before signing&nbsp;documents. Passkey is used to secure access to the ID Wallet.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">The Intersection of Passkey and Payments<\/h2>\n\n\n\n<p>The intersection of passkey and secure payment was a topic of discussion across multiple sessions on day 3 of Authenticate 2024.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"328\" height=\"292\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.52.09\u202fAM.png\" alt=\"\" class=\"wp-image-15539\" style=\"width:162px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.52.09\u202fAM.png 328w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.52.09\u202fAM-300x267.png 300w\" sizes=\"auto, (max-width: 328px) 100vw, 328px\" \/><\/figure>\n<\/div>\n\n\n<p>Among the foundational specifications in payments today is EMV-3D Secure. In a session, Henna Kapur, Director, Product Management at Visa,<strong> <\/strong>highlighted the potential for FIDO passkey adoption in financial services through an integration with EMV-3D Secure.<\/p>\n\n\n\n<p>Jonathan Grossar, Vice President, Product Management at Mastercard, provided insight into how the Secure Payment Confirmation (SPC) specification will help improve payment security.<\/p>\n\n\n\n<p>&#8220;SPC implements passkeys &#8211; but with additional security and better user experience,&#8221; Grossar said.<\/p>\n\n\n\n<p>The enhancements that SPC provide include:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>Cross-origin authentication<\/strong> &#8211; It provides the ability for merchants to invoke payment passkeys for authentication without the need to redirect to the Relying Party (Bank or Payment network).<\/li>\n\n\n\n<li><strong>Dynamic linking<\/strong> &#8211; Transaction amount and merchant identifier are approved by the consumer and included in the FIDO passkey assertion.<\/li>\n<\/ul>\n\n\n\n<p>The final keynotes also include a panel on payments where the importance of the intersection between passkeys and payment security was reiterated.<\/p>\n\n\n\n<p>&#8220;One of the things that is pervasive in both areas are the terms trust and managing risk,&#8221; Sean Estrada, Head of Industry Advocacy at Stripe said. &#8220;So I think that is really fundamental to a well-functioning ecosystem, and I think passkeys have a very useful position in there.&#8221;<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"611\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.53.45\u202fAM-1024x611.png\" alt=\"\" class=\"wp-image-15540\" style=\"width:482px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.53.45\u202fAM-1024x611.png 1024w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.53.45\u202fAM-300x179.png 300w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.53.45\u202fAM-768x459.png 768w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.53.45\u202fAM.png 1206w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Passkeys are Good, Now Prove Your Identity<\/h2>\n\n\n\n<p>Identity security was another hot topic on the final day of Authenticate 2024.<\/p>\n\n\n\n<p>In a session, Abbie Barbir from the ADIA Association and Rolf Lindemann, VP Products at Nok Nok discussed the concept of Reusable Identity, also sometimes referred to as Decentralized Identity.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"402\" height=\"356\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.54.29\u202fAM.png\" alt=\"\" class=\"wp-image-15541\" style=\"width:173px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.54.29\u202fAM.png 402w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.54.29\u202fAM-300x266.png 300w\" sizes=\"auto, (max-width: 402px) 100vw, 402px\" \/><\/figure>\n<\/div>\n\n\n<p>While passkeys provide strong authentication for access, the question that can sometimes remain is whether the passkey holder is in fact the rightful holder of the passkey. That&#8217;s where reusable identity plays a crucial role.<\/p>\n\n\n\n<p>Reusable identity is a standard-based credential that can be attested and verified to enable interoperability. It allows users to prove their identity without having to repeatedly go through identity-proofing processes, reducing friction and over-sharing of personal data. Lindemann explained that it is enabled by decentralized identifiers (DIDs) that are unique, can be bound to a user&#8217;s devices and allow for key rotation if compromised.<\/p>\n\n\n\n<p>Identity and the concept of a digital wallet for identity was the topic of one of the final keynote panels as well. Key points included the lack of a standardized definition for wallets, with opinions ranging from government-issued identity systems to cryptographic containers for verified attributes.&nbsp;<\/p>\n\n\n\n<p>The conversation highlighted the importance of trust, security, and interoperability, noting the challenges of market-driven standards and the need for global perspectives. Despite these challenges, the panelists agreed on the potential benefits of wallets for convenience and control, emphasizing the need for ethical and inclusive development.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-large is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"1024\" height=\"519\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.04\u202fAM-1024x519.png\" alt=\"\" class=\"wp-image-15542\" style=\"width:468px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.04\u202fAM-1024x519.png 1024w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.04\u202fAM-300x152.png 300w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.04\u202fAM-768x389.png 768w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.04\u202fAM.png 1244w\" sizes=\"auto, (max-width: 1024px) 100vw, 1024px\" \/><\/figure>\n<\/div>\n\n\n<p><\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Toward a Phishing Resistant User<\/h2>\n\n\n\n<p>Passkeys offer the promise of phishing-resistant authentication. While that&#8217;s extremely helpful in reducing risk, there is still more that&#8217;s needed to help create a phishing-resistant user, according to Derek Hanson<strong> from Yubico.<\/strong><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"alignright size-full is-resized\"><img loading=\"lazy\" decoding=\"async\" width=\"380\" height=\"340\" src=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.39\u202fAM.png\" alt=\"\" class=\"wp-image-15543\" style=\"width:167px;height:auto\" title=\"\" srcset=\"https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.39\u202fAM.png 380w, https:\/\/authenticatecon.com\/wp-content\/uploads\/2024\/10\/Screenshot-2024-10-17-at-9.55.39\u202fAM-300x268.png 300w\" sizes=\"auto, (max-width: 380px) 100vw, 380px\" \/><\/figure>\n<\/div>\n\n\n<p>In the closing keynote session, Hanson emphasized the need to<strong> <\/strong>remove phishing from the end-to-end risk profile of a user.<\/p>\n\n\n\n<p>&#8220;The point being if I&#8217;ve given you a very secure method to sign in and I gave you a password on a sticky note to recover access, that&#8217;s going to be where the system falls down,&#8221; Hanson said. &#8220;We need to remove phishing from the end-to-end life cycle, that is how we can actually transform businesses and remove risk.&#8221;<\/p>\n\n\n\n<h2 class=\"wp-block-heading\">Stay Connected and Stay Engaged!<\/h2>\n\n\n\n<p>Overall Authenticate 2024 was a stellar event with 120 sessions and 150 speakers across the three-day conference.<\/p>\n\n\n\n<p><a href=\"https:\/\/authenticatecon.com\/\" target=\"_blank\" rel=\"noreferrer noopener\">Authenticate<\/a> will be back October 13-16, 2025. Between now and then, the FIDO Alliance will be sharing lots of informative content and hosting educational events. Stay connected and <a href=\"https:\/\/authenticatecon.com\/event\/authenticate-2024-conference\/#sign-up\" target=\"_blank\" rel=\"noreferrer noopener\">sign up for Authenticate 2025 news here<\/a>. See you next year!<\/p>\n\n\n\n<div class=\"wp-block-buttons is-content-justification-center is-layout-flex wp-container-core-buttons-is-layout-16018d1d wp-block-buttons-is-layout-flex\">\n<div class=\"wp-block-button\"><a class=\"wp-block-button__link has-vivid-green-cyan-background-color has-background wp-element-button\" href=\"https:\/\/youtu.be\/_oGD8LO05ts\" target=\"_blank\" rel=\"noreferrer noopener\">Watch the 3-Day Recap Video<\/a><\/div>\n<\/div>\n\n\n\n<div style=\"height:42px\" aria-hidden=\"true\" class=\"wp-block-spacer\"><\/div>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter is-resized\"><img decoding=\"async\" src=\"https:\/\/lh7-rt.googleusercontent.com\/docsz\/AD_4nXf9oXjjxHe0NGi8UWO7i5AygIhMpFnouiiEUKHIKVxrhY-dcGPXSwdvzeDbTc5W4T-t_-ngD3_R7q5pEpeISAI_xiVBo9DtR6ON1CkmmSpxy3eE0B6nM653L2CWuVfgrAo22FMoYO--jw9LXLaP90ICx9QZ?key=floJEW2h9kAygq1dK6xd7w\" alt=\"\" style=\"width:461px;height:auto\" title=\"\"><\/figure>\n<\/div>","protected":false},"excerpt":{"rendered":"<p>By: FIDO staff The third and final day of Authenticate 2024 was another jam-packed bonanza of content and insights. If you missed Day 1, check out the recap here. The recap for Day 2 is here. Multiple users came up on the stage to detail how passkeys have made a difference in consumer, enterprise, and [&hellip;]<\/p>\n","protected":false},"author":5,"featured_media":14580,"comment_status":"closed","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"inline_featured_image":false,"footnotes":""},"categories":[66],"tags":[],"class_list":["post-15535","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-authenticate-2024-conference"],"acf":{"intro_text":""},"_links":{"self":[{"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/posts\/15535","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/users\/5"}],"replies":[{"embeddable":true,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/comments?post=15535"}],"version-history":[{"count":0,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/posts\/15535\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/media\/14580"}],"wp:attachment":[{"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/media?parent=15535"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/categories?post=15535"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/authenticatecon.com\/wp-json\/wp\/v2\/tags?post=15535"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}