Conference Venue: RAI Amsterdam, Europaplein 24, 1078 GZ Amsterdam, The Netherlands

Book Hotel click HERE
Back To Schedule
Thursday, September 26 • 11:55am - 12:40pm
WebAuthn: Strong authentication vs. privacy vs. convenience

Sign up or log in to save this to your schedule, view media, leave feedback and see who's attending!

Feedback form is now closed.
WebAuthn is the new API now widely available in browsers, enabling strong, public-key based authentication that has the potential to strengthen, if not replace, password-based authentication mediums. It further allows for convenient and fast authentications with via biometric readers built into devices, like Apple’s Touch ID. But now the device itself can be the authentication medium; how does WebAuthn deal with all of the potential privacy implications therein? How do users and relying parties deal with lost, or stolen devices? In this talk I will give an overview of WebAuthn, and then do a deep dive into the security properties of the API, and how it delegates responsibilities to browsers, authenticators, relying parties, and users in order to build a balance between privacy, strength, and convenience.

avatar for Suby Raman

Suby Raman

Software Engineer, Duo Security
Suby Raman is a full-stack software engineer working for Duo Security out of Ann Arbor, Michigan. He has helped lead development of Duo's implementation of WebAuthn, now being widely used in Duo's two-factor authentication prompt. He is also the author of Webauthn.Guide, a developer... Read More →

Thursday September 26, 2019 11:55am - 12:40pm CEST