The Gaza Post|The News of Palestine-Palestine
With Mozilla’s release of Firefox 60 on Wednesday, web browsers will start letting you log into websites without a password — an important change in authentication technology that could help curtail costly phishing attacks.
Firefox 60 supports technology called Web Authentication, or WebAuthn for short, that can be used to grant you access to websites with a physical authentication device like a YubiKey dongle, biometric identity proof using an Android phone’s fingerprint reader or the iPhone’s Face ID, and some other alternatives to passwords.
Passwords are a particular problem on the web. Fake websites can coax you to type in credentials that then can be used to steal money from your bank account or snoop your email — a problem called phishing. Even if you pick hard-to-guess passwords, never reuse them on multiple sites and always remember them, passwords still aren’t that strong a foundation for security these days. We’re still a long way away from a post-password future, but WebAuthn is an important step, if nothing else, in making sites more secure.
“It might be that, in a few years time, a significant number of people have a passwordless experience with at least one site that they use regularly. That’ll be exciting,” Google security expert Adam Langley said in a March blog post.
One WebAuthn fan is data-sync service Dropbox.
“As a user, you’ll enjoy much stronger sign in security on more browsers,” Dropbox programmer Brad Girardeau said in a blog post Tuesday. “You can feel confident when signing in that it’s really us, and we can be confident it’s really you.”
Mozilla boasts that Firefox is the first browser out of the gate to support WebAuthn, but it’s coming to Google’s Chrome — the next version, due this month — and Microsoft’s Edge, too. That should improve web authentication compared to earlier attempts to support the technology.
WebAuthn is “significantly more capable” than earlier attempts to support physical authentication keys, Langley said. Happily, WebAuthn supports earlier authentication hardware, so people who have invested in the technology won’t have to start from scratch.