Detecting Compromise of Synced Passkeys

Detecting Compromise of Synced Passkeys

Source: YouTube · FIDO Alliance · published Feb 6, 2025 · 22:05

Identity & Access Management
No ratings yet Log in to rate
Transcript Available
Description

Authentication enables users to prove their identity to a relying party through credentials and verifiers. During registration, a credential-verifier pair is established, such as hashing a password for future verification 0:06.

Key Takeaways:
• Authentication involves proving identity via a credential-verifier pair agreed upon during registration 0:09.
• In password authentication, the relying party stores the hash of the password as the verifier 0:45.
• The authentication process requires the user to present the credential, which the relying party verifies using the stored verifier 0:30.

This process ensures secure identity verification by validating credentials against stored verifiers.

Sources:

  • 0:06 Definition of authentication
  • 0:09 Credential-verifier pair concept
  • 0:30 Authentication verification step
  • 0:45 Password hashing example

Generate CPE Credits

Generate a professional CPE document from this video's transcript.

Estimated credit: 0.5 CPE hours

Estimate uses the video runtime (1 hour ≈ 1 CPE, rounded to the nearest 0.5, minimum 0.5, maximum 2.0). The final amount can be lower after review, never higher.

Topic: Identity & Access Management. Commonly maps to: Identity and Access Management (IAM), Security Architecture and Engineering. Exact CISSP domains are assigned during generation.

CISSP Domain Mapping
Learning Objectives
Self-Assessment Questions
PDF Export Ready

Free account. One generation at a time, with a daily limit.

CPEBuddy is independent and not affiliated with or endorsed by ISC2, ISACA, or any certification body. Exports are formatted for common CPE submissions; acceptance is at your certification body's discretion.

Watch on YouTube

Transcript Preview

First 800 characters of the transcript

okay I have a lot of share today so I let's get started okay authentication basically allows the user uh to prove to the Reliant party that they are the person they claim to be so to do this during registration the user um and the real party would agree on a pair of credential and verifier payer um so during authentication uh the real say hey can you show me your credential the US show the credential and the real party verifies the credential uh use the corresponding verifier and let's take password as example so during registration the user uh sends uh like picks password and send it to the REI party and say hey this is my uh fa password and the Reliant party saves the hash of the password as a verifier and during authentication um the real say hey can you show me that you know that passw…