Jump to content
Sign in to follow this  
kya100

Firefox moves browsers into post-password future with WebAuthn tech

Recommended Posts

 

images.jpg

With Mozilla's release of Firefox 60 on Wednesday, web browsers will start letting you log into websites without a password -- an important change in authentication technology that could help curtail costly phishing attacks.  

Firefox 60 supports technology called Web Authentication, or WebAuthn for short, that can be used to grant you access to websites with a physical authentication device like a YubiKey dongle, biometric identity proof using an Android phone's fingerprint reader or the iPhone's Face ID, and some other alternatives to passwords.

Passwords are a particular problem on the web. Fake websites can coax you to type in credentials that then can be used to steal money from your bank account or snoop your email -- a problem called phishing. Even if you pick hard-to-guess passwords, never reuse them on multiple sites and always remember them, passwords still aren't that strong a foundation for security these days. We're still a long way away from a post-password future, but WebAuthn is an important step, if nothing else, in making sites more secure.

"It might be that, in a few years time, a significant number of people have a passwordless experience with at least one site that they use regularly. That'll be exciting," Google security expert Adam Langley said in a March blog post.

 

One WebAuthn fan is data-sync service Dropbox. 

"As a user, you'll enjoy much stronger sign in security on more browsers," Dropbox programmer Brad Girardeau said in a blog post Tuesday. "You can feel confident when signing in that it's really us, and we can be confident it's really you."

With WebAuthn technology, USB security keys like this YubiKey from Yubico can be used in place of a password or in addition to one.

Mozilla boasts that Firefox is the first browser out of the gate to support WebAuthn, but it's coming to Google's Chrome -- the next version, due this month -- and Microsoft's Edge, too. That should improve web authentication compared to earlier attempts to support the technology.

WebAuthn is "significantly more capable" than earlier attempts to support physical authentication keys, Langley said. Happily, WebAuthn supports earlier authentication hardware, so people who have invested in the technology won't have to start from scratch.

 

Hello, Firefox advertising

Firefox 60 also introduces new sponsored links -- ads -- on the new-tab page. Only a test group of Firefox users in the US will see them to start as Mozilla refines the technology, but expect it to spread as the nonprofit seeks to diversify revenue sources besides Google and other search engines that pay Mozilla when Firefox sends our queries their way.

Mozilla tried ads on the new-tab page in 2014 but dumped the project because of problems coming up with ads that were a good match. This time, though, Firefox will offer sponsored links based on its own assessment of our interests as informed by its Pocket service, through which you can flag sites you find interesting.

Even if you're not seeing ads on the new-tab page, Firefox will show more personalized suggestions for websites there, Mozilla said.

 

Share this post


Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
Sign in to follow this  

×