Google, Samsung, and 16 others receive FIDO certification for products and services designed to replace passwords
Russell Brandom / The Verge :
Context & Ripple Effects
FIDO certification in May 2015 lands two months after Microsoft committed Windows 10 to FIDO biometric authentication, making this the moment the standard moved from spec to shipping products across Google, Samsung, and sixteen smaller vendors.
The arc runs long: seven years later Apple, Google, and Microsoft jointly announced plans to adopt FIDO features, and by mid-2023 Google enabled passkeys on all accounts. The 2015 certifications are the first concrete evidence that the alliance could get hardware makers, not just standards bodies, behind password replacement.
First-order effects
- Google's and Samsung's certified products and services can now carry the FIDO mark, letting them ship biometric, cryptographic sign-in as a differentiator on Android devices and consumer services.
- The sixteen smaller certified companies gain entry into an emerging trusted-vendor pool, which is what websites and app developers need before they can accept FIDO credentials instead of passwords.
Second-order effects
- Non-certified rivals face pressure to pursue FIDO compliance or risk their products being locked out of passwordless flows as more sites adopt the standard.
- Samsung and Google deepen their existing partnership footprint — the same pair later collaborating on TizenOS-powered TVs with Google Photos — giving both an incentive to push FIDO support across shared device categories.
Third-order effects
- If the pattern holds, authentication consolidates around a handful of platform holders whose preauthenticated devices become the credential store — a structural shift from per-site passwords to platform-issued keys, later visible in Google's Titan Security Keys storing up to 250 unique passkeys.
- Standards alliances like FIDO effectively become gatekeepers: certification status determines which vendors participate in the passwordless ecosystem, giving the alliance regulatory-style power without regulation.
The trend: Passwordless authentication has moved from 2015-era standards certification toward platform defaults controlled by Google, Apple, and Microsoft, with FIDO certification deciding who gets to issue credentials.