
NIST Fireside Chat: A discussion about draft NIST 800-63-4 and all things digital identity
Source: YouTube · FIDO Alliance · published Feb 6, 2025 · 25:39
The Authenticate public sector track highlights the federal transition from passwords to phishing-resistant Passkeys, addressing NIST SP 800-63-4 updates, legacy system challenges, and the integration of verifiable credentials.
Key Takeaways:
• The session introduces the public sector focus, featuring federal speakers and discussions on Passkeys and NIST guidelines 0:09.
• Moderators Jeremy Grant and Zack Martin emphasize a tight schedule and direct virtual attendees to use the conference app for questions 0:22.
• Andy Yegnanian clarifies that Passkeys presented with user verification constitute Multi-Factor Authentication (MFA), countering market skepticism 2:45.
• Adoption of phishing-resistant technologies in government is hindered by legacy IT debt, complex procurement, and the need to modernize identity stacks 5:12.
• Verifiable credentials and mobile driver's licenses (MDLs) are best suited for identity proofing, while Passkeys are preferred for subsequent authentication 7:30.
• NIST’s new Attribute Validation List supports identity proofing by standardizing how government services verify individual attributes 10:15.
• The discussion concludes with insights on balancing security complexity with usability and preparing for post-quantum cryptography 11:00.
This track underscores the urgent need for the public sector to modernize identity infrastructure by adopting phishing-resistant standards and leveraging emerging credential types.
Sources:
- 0:09 Introduction of the public sector track and speaker lineup.
- [0:22](https://www
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
uh welcome to uh day two of the sessions here at authenticate uh this room for the rest of the day is going to be hosting the public sector track we've got a great lineup of speakers uh many from uh uh the federal government we've got somebody from the state of Michigan as well talking about pass Keys uh and a number of folks who are sort of in and around the public sector ecosystem I'm Jeremy Grant uh along with my colleague Zack Martin from Venable will be your moderators for this session track we're going to try and keep things very tight on Pace because we got people virtually uh to that point if you have questions please uh submit them through the app and then we will uh through all of the sessions basically pull things off the app and uh and ask them to the extent we have time so uh …