Some federal websites now allowing users to login via secure USB keys
Full article539 words · extracted from cyberscoop.com · click to collapse
Get our latest cybersecurity news first on Google.
Three federal agencies have signed up to let the public use keysticks conforming to the Universal Second Factor standard.
For the first time, Americans will have the option to use a cryptographically secure USB keystick to protect their online accounts on federal government websites.
Owners of online accounts protected by identity-proofing start up ID.me will be able to use keysticks conforming to the Universal Second Factor, or U2F, standard promulgated by the Fast IDentity Online, or FIDO Alliance, ID.me announced Tuesday.
The option will be available to users alongside existing two-factor services, such as a code sent by SMS text message, or a call to a landline, the company said. It’s the first time U2F keysticks — considered a gold-standard protection against phishing and other forms of online identity theft — have been available for use with federal online services.
ID.me did not disclose the three federal agencies it said were buying the company’s identity proofing services — but it has in the past done very public work to provide veterans secure logins on vets.gov. On Thursday, ID.me CEO Blake Hall, himself a veteran, will lead a session titled “‘Un-Phishable’ Authentication at the VA,” moderated by U.S. Digital Service official Julie Meloni, at the AFCEA Federal Identity Summit.
“Thieves can guess or steal passwords from a database and they can spoof biometrics,” Hall said in a statement. “A physical FIDO U2F security key is ‘un-phishable’ – it must be physically stolen from you to compromise your account. ”
Stina Ehrensvard, CEO and Founder of Yubico, the company that co-authored the U2F standard and now makes U2F-compliant keysticks, called the news a “great milestone for open internet security standards, and an important step towards a more secure internet for everyone.”
The U.K. government rolled out U2F-compliant keysticks as its preferred second factor earlier this year. Google, Facebook and other major online services also offer users the option of a keystick to replace phishable or spoofable second-factors like SMS messages or app notifications.
Latest Podcasts
Government
FBI officials say AI is bolstering adversaries, emphasizing need to focus on cyber basics, patching
Feds accuse China of ‘systematic’ distillation of U.S. AI models
CIA’s Michael Ellis says cyber intelligence is changing how the agency operates
The G7 tells industry to hurry up and prep for post-quantum encryption
Technology
Threats
Chinese espionage groups swarm to exploit triple-link chain of zero-days
Microsoft discloses two actively exploited zero-days among 974 vulnerabilities
Russian national extradited to US for alleged involvement in bank-account takeover scheme
Attackers exploit zero-days in consistently besieged SonicWall product
Policy
Whistleblower says USPS deploying new, ‘untested’ IT systems governing mail-in ballots
‘Watershed 250’ test program in Texas looks to private sector for water cybersecurity help
Former sexual abuse victims say Grok used their images, videos to train deepfake capabilities
Cyber threats nudge Trump to sign executive order on foreign equipment in U.S. energy infrastructure
Text extracted automatically; images, tables and formatting may be missing. Original: https://cyberscoop.com/u2f-us-government-websites-id-me/