Passkeys are in use in your Microsoft Tenant, here's how to set policy effectively.
Meha Bouazizi Meha Bouazizi

Passkeys are in use in your Microsoft Tenant, here's how to set policy effectively.

During a normal login, synced and device-bound passkeys behave identically. The difference appears at registration, and it comes down to attestation.

A device-bound authenticator can present an attestation statement when it registers: cryptographic proof, chained back to the manufacturer, of exactly what hardware generated the credential. The relying party validates that chain against the FIDO Alliance Metadata Service and knows with certainty that this is a genuine security key of model X, certified to level Y, holding a private key that cannot be exported.

Read More
Passkeys are here. Settle for Synced or go Device-Bound?
Meha Bouazizi Meha Bouazizi

Passkeys are here. Settle for Synced or go Device-Bound?

If you have signed into Google, Microsoft, or your bank recently, you have probably been nudged to create a passkey. Maybe you did, with a fingerprint or a face scan, and it felt almost suspiciously easy. So what did you actually create?

Read More
Implementing FIDO2 for admins is a tactical move. Implementing FIDO2 for everyone is strategic
Guest User Guest User

Implementing FIDO2 for admins is a tactical move. Implementing FIDO2 for everyone is strategic

The reality is that most modern attacks do not begin with the administrator account. They begin with ordinary users. Finance teams receive invoice fraud attempts. HR staff receive malicious attachments and credential harvesting emails. Procurement and customer support teams are targeted through supplier impersonation and SaaS account compromise campaigns. Remote employees routinely interact with cloud services outside traditional network boundaries. In real life, the workforce itself has become the primary attack surface.

Read More
Scammers love the holiday shopping season
Guest User Guest User

Scammers love the holiday shopping season

The holiday season should be about joy, not dealing with fraud or identity theft. Staying alert and using phishing-resistant security might be the line between your end-of-year celebrations, and account recovery emails.

Read More
Anni Råberg Anni Råberg

Spear Innovations Oy Ltd Launches Project for Cybersecurity Keys Made in Finland.



Pori, Finland – 10.12.2025 – A new project was started in July 2025 to create a high-security authentication token that supports both FIDO2 and PKI standards. The target result of the project will be a line of SpearID® security keys that are manufactured in Finland.

Read More
Dealing with real-time attacks on user accounts
Guest User Guest User

Dealing with real-time attacks on user accounts

The common advice often depends on the victim's ability to effectively counter advanced cyber-threats. This is not a bullet-proof solution as victims of phishing attacks are no technical experts on mobile authentication.
A bullet-proof solution, is a hardware-based FIDO2 security key, which resist all adversary-in-the-middle and phishing attacks in real-time.  

Read More
Passwords weren’t built for today’s internet. Passkeys are.
Guest User Guest User

Passwords weren’t built for today’s internet. Passkeys are.

Your security depends not only on the strength of your password but also on every system that stores or transmits it. In a world of automated attacks, deepfakes, and massive breaches, that’s a fragile setup.
[..] with passkeys, your identity is tied to your device.
You can authenticate using a PIN that’s only locally stored, and the device handles the cryptographic handshake behind the scenes.

Read More