Tech News
← Home  ·  All topics

Fido2

3 GoKawiil briefs on this topic

Microsoft sets February 2027 deadline to retire SMS sign-in for Entra ID

Microsoft has told IT administrators to move Entra ID users off SMS and voice-based first-factor sign-in before it shuts the option down in February 2027. Alternatives include passkeys, QR code authentication, and FIDO2 security keys, and the change applies even to organizations using their own telephony providers for multifactor authentication. The retirement covers only workforce tenant scenarios, not customer identity products like Entra External ID.

Researchers Catalog 39 Attack Techniques Targeting Passkey Systems

Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.

New AC2 Protocol Adds Cryptographic Human Approval Layer to AI Agents

AC2 is a new open protocol designed to let AI agents request verifiable human sign-off before taking consequential actions, such as merging code, sending client messages, calling APIs, or executing payments. It installs into existing frameworks via a plugin and single command, using DIDComm v2.0 messaging and passkey authentication through Liquid Auth (FIDO2/WebAuthn), without needing a central relay server or blockchain.