


Don Reisinger 2018年04月18日


制定互聯(lián)網(wǎng)標(biāo)準(zhǔn)的組織FIDO聯(lián)盟和W3C聯(lián)合推出了一個(gè)新的認(rèn)證標(biāo)準(zhǔn),允許網(wǎng)頁瀏覽器和網(wǎng)站支持以生物辨識技術(shù)替代登陸密碼。這項(xiàng)名為WebAuthn的標(biāo)準(zhǔn)其實(shí)是一種應(yīng)用程序接口(API),網(wǎng)頁開發(fā)者可以應(yīng)用在網(wǎng)站上,通過指紋識別、甚至像蘋果Face ID一樣的面部掃描技術(shù)確認(rèn)用戶的身份。



去年9月,蘋果發(fā)布新款iPhone,當(dāng)時(shí)詳細(xì)介紹了生物識別安全技術(shù)。蘋果表示,如果使用iPhone的Touch ID指紋掃描技術(shù),每5萬次識別之中可能會(huì)失敗一次。而如果采用Face ID掃描面部,失敗比例會(huì)下降到百萬分之一。兩種方式不管選哪種,都比單單一個(gè)密碼要強(qiáng)。




Some of the most popular Web browsers are trying to kill your passwords.

Internet standards organizations the FIDO Alliance and W3C have launched a new specification that allows Web browsers and websites to support biometric encryption methods in place of passwords. The specification, called WebAuthn, is an application programming interface (API) that Web developers can integrate into their websites and allow fingerprint readers and even face scanners like Apple’s Face ID to verify a person’s identity.

According to Engadget, which earlier reported on WebAuthn, Firefox already works with the technology. Google’s Chrome and Microsoft Edge are slated to add support for WebAuthn within the next few months. Apple, which operates its Safari browser, has yet to announce support for WebAuthn.

The move could technically create a more secure Internet. As the rash of hacks, scams, and data breaches have shown over the last several years, passwords alone are not necessarily a suitable safeguard for data. Companies have moved to two-factor authentication, which requires users to input a code sent to their smartphones in addition to a password to verify their authenticity, but that still isn’t as secure as biometrics.

At its iPhone unveiling in September last year, Apple talked in detail about biometric security. The company said that its Touch ID fingerprint scanner could be duped in 1 in 50,000 cases. That jumped to 1 in 1 million cases with its Face ID face scanner. Either way, that’s better than a simple password.

Still, passwords aren’t dying anytime soon. While WebAuthn has officially launched, it’s still considered a “recommendation” and could be modified before it becomes a standard. The recommendation paves the way for websites and browsers to support alternatives to passwords, but now the onus is on website owners and browser companies to support it.

