Microsoft announces that Windows 10 will support FIDO biometric authentication
Russell Brandom / The Verge :
Context & Ripple Effects
Microsoft's 2015 decision to build FIDO biometric authentication into Windows 10 turned out to be the first step of a decade-long walk away from the password. The company first carried biometrics down-market with fingerprint support coming to Windows 10 Mobile, then made the standards bet explicit by adding FIDO2 passwordless authentication to Windows Hello alongside Yubico's FIDO2 USB Security Key.
The endpoint visible in the related coverage is full standardization: Microsoft now supports [[a:935853|standards-based FIDO2 security keys that let Windows 10 users reach their Microsoft Account without a username or password]], and has put Windows Hello itself through formal FIDO2 certification for the May 2019 update. What began as a convenience feature is now a certified platform credential.
First-order effects
- Windows 10 users gain login methods built on an open standard rather than a Microsoft-proprietary scheme, so a biometric or hardware token works against any FIDO-compliant relying party, not just one vendor's account system.
Second-order effects
- Hardware-token makers like Yubico get a distribution channel at OS scale: once Windows natively speaks FIDO2, a commodity USB key becomes a mass-market product instead of a niche enterprise accessory.
Third-order effects
- With Microsoft certifying its own biometric stack against FIDO2, passwordless authentication shifts from per-site novelty to platform infrastructure — other OS vendors face pressure to adopt the same certified-standard route or be the ones still shipping passwords.
The trend: Operating-system authentication is migrating from vendor-specific passwords to certified FIDO2 credentials, with each OS release converting passwordless from opt-in feature to default expectation.