Our blog

Resources and insights

The latest industry news, interviews, technologies, and resources.
View all
Company Announcements
Regulatory News
Passkeys
Business Value
Product
Fraud
Passkeys
Maranda Manning
May 6, 2026
7 min read
Passkeys

Device-Bound vs Synced Passkeys: Banking Comparison

Synced passkeys solve a real usability problem and are a clear upgrade from OTP, TOTP, and push. But sync moves the security boundary of the credential to the user's cloud account. For financial services, that matters. Here is why device-bound passkeys close the gap.
Greg Storm
May 6, 2026
8 min read
Passkeys

Device Fingerprinting vs Authentication: Fraud Signal or MFA?

Device fingerprinting is a useful fraud signal, not a possession factor for authentication. It is probabilistic, spoofable at scale, and excluded from the regulatory definition of strong authentication. Here is where it fits in a 2026 financial services architecture.
Toby Rush
May 6, 2026
7 min read
Passkeys

Passkeys vs Hardware Security Keys: Cost and Deployment Comparison for Banks

Hardware security keys introduce deployment, cost, and usability barriers impractical for consumer banking at scale. Software passkeys deliver equivalent cryptographic security through device secure enclaves while reducing support costs by 75%.
Greg Storm
May 6, 2026
8 min read
Passkeys

TOTP vs Passkeys: Are Authenticator Apps Enough for Banks?

TOTP and authenticator apps were a meaningful upgrade from SMS OTP, but the underlying threat model has not changed. AiTM phishing defeats TOTP, the seed is exposed at enrollment, and cloud-synced apps create a single point of failure. Here is what comes next.
Toby Rush
May 6, 2026
8 min read
Passkeys

Why Banks Are Replacing SMS OTP With Passkeys in 2026

NIST has classified SMS OTP as a restricted authenticator, adversary-in-the-middle phishing routinely defeats both SMS and email codes, and financial services authentication is moving to phishing-resistant, device-bound credentials. Here is a practical roadmap for the migration.
Greg Storm
May 6, 2026
8 min read
Passkeys

AI Agents Need Authentication Too: The Emerging Passkey and OAuth Problem

Toby Rush
March 6, 2026
9 min read
Passkeys

Passkeys and Payment Authentication: Where SPC, 3DS, and FIDO Converge

Secure Payment Confirmation, expanding Visa and Mastercard passkey programs, and FIDO2's growing role in 3DS flows are converging toward a single credential layer at checkout. For financial institutions, understanding how these pieces fit together is no longer optional - it is a core architectural question.
Greg Storm
March 6, 2026
9 min read
Passkeys

What Actually Works When Banks Deploy Passkeys: A Practitioner's Playbook

The five practices that separate high-adoption passkey deployments from stalled ones. A practitioner's playbook grounded in FIDO Alliance guidance and real implementation patterns.
Toby Rush
February 10, 2026
7 min read
Passkeys

15 Billion Accounts and Counting: What Passkey-Ready Scale Means for Banks

The FIDO Alliance reports over 15 billion accounts can now use passkeys. That number changes the calculus for every bank still debating whether to deploy.
Tim Massey
February 10, 2026
4 min read

The Passkey Adoption Bottleneck

Greg Storm
January 8, 2026
5 min

Making Passkeys the Default Without Breaking Trust

Toby Rush
December 22, 2025
6 min

Encouraging passkey adoption without forcing it

Maranda Manning
December 22, 2025
5 min
Passkeys

Q&A with Andrew Shikiar, CEO of FIDO

Maranda Manning
October 1, 2025
5 min
Product

Passkeys in Emerging Markets

Toby Rush
September 16, 2025
3 min
Passkeys

Making Passkeys Bank-Grade: The Missing Ingredient

This fourth blog in a five-part series that explores the current state of passkeys and why enhanced implementations, what we call Passkeys+, are essential for meeting the security and compliance demands of
Maranda Manning
July 8, 2025
2 min
Passkeys

The Passkey Shift - Passkeys Inevitable Triumph over Passwords

For decades, passwords were the default key to the digital world. Easy to implement and familiar to users, they offered convenience, but at a steep cost. As our digital footprints grew, passwords became both a security liability and a user burden. Complex requirements, frequent resets, and rampant reuse opened the floodgates to breaches, phishing attacks, and endless frustration.
Toby Rush
June 19, 2025
5 min