Biometrics and Passkeys: Making Security Simple

Do you hate passwords? Here’s good news: Solutions called “biometrics” and “passkeys” help make cybersecurity easier.

Passwords are part of the authentication process that establishes the identity of a user. Multifactor authentication is stronger, requiring two or more authentication factors – something the user knows, something the user is, and something the user has.

  • Biometrics are another way to identify a user by using physical characteristics like fingerprints, facial scans or eye scans. It requires hardware and software that reads the characteristic, like the features on some laptops, tablets, and smartphones.
  • Passkeys, an emerging technology, replace passwords by allowing users to prove their identity by using biometrics combined with their mobile device.

When creating an online account, a users register their mobile device with the website instead of creating a password. When a user later logs on to the website, it reads a unique key (based on encryption) to authenticate the user. The user uses biometrics to log on to the mobile device, then each website or service with which they have registered reads the unique key for that site or service. No password is needed.

See this article for more.

This tip courtesy of the ACBA Legal Technology and e-Discovery Committee, and the Jan. 4, 2023 SANS Institute “OUCH!” newsletter.