
Detecting Compromise of Synced Passkeys
Source: YouTube · FIDO Alliance · published Feb 6, 2025 · 22:05
Authentication enables users to prove their identity to a relying party through credentials and verifiers. During registration, a credential-verifier pair is established, such as hashing a password for future verification 0:06.
Key Takeaways:
• Authentication involves proving identity via a credential-verifier pair agreed upon during registration 0:09.
• In password authentication, the relying party stores the hash of the password as the verifier 0:45.
• The authentication process requires the user to present the credential, which the relying party verifies using the stored verifier 0:30.
This process ensures secure identity verification by validating credentials against stored verifiers.
Sources:
Generate CPE Credits
Generate a professional CPE document from this video's transcript.
Estimated credit: 0.5 CPE hours
Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.
Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.
Free account. One generation at a time, with a daily limit.
CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.
Transcript Preview
First 800 characters of the transcript
okay I have a lot of share today so I let's get started okay authentication basically allows the user uh to prove to the Reliant party that they are the person they claim to be so to do this during registration the user um and the real party would agree on a pair of credential and verifier payer um so during authentication uh the real say hey can you show me your credential the US show the credential and the real party verifies the credential uh use the corresponding verifier and let's take password as example so during registration the user uh sends uh like picks password and send it to the REI party and say hey this is my uh fa password and the Reliant party saves the hash of the password as a verifier and during authentication um the real say hey can you show me that you know that passw…