FIDO Alliance and W3C announce WebAuthn, a new open standard for password-free logins, currently supported in Firefox, and to be supported in Chrome and Edge
One small step towards a world without phishing — Web browsers are building a new way for you to log in, announced today by the W3C and FIDO Alliance standards bodies.
Context & Ripple Effects
The FIDO Alliance and W3C are turning browser-based passwordless login into a formal standard: WebAuthn ships today with Firefox support live and Chrome and Edge committed. The announcement is the standards-body step in a line of coverage that runs from the W3C's later approval of WebAuthn as an official web standard to Google wiring FIDO2 hardware-key logins into its own account system.
What makes this one matter is who signed on: by 2022 the same standard underpins Apple, Google, and Microsoft's joint adoption of FIDO passwordless tech across fingerprint readers, face scanners, and phones — a rare case of three platform rivals converging on one authentication layer.
First-order effects
- Firefox users can immediately use WebAuthn for password-free logins, while Chrome and Edge users get it once those browsers ship support — site operators building against the spec gain a credential mechanism that works without passwords.
Second-order effects
- Google's later move to accept FIDO2 security keys for its accounts shows the demand side following: large identity providers have to add WebAuthn support or watch rivals offer phishing-resistant login their users prefer.
Third-order effects
- If the pattern holds — standards approval, then Google, then a three-platform pact — authentication consolidates around a single open credential layer, shifting the industry from per-site passwords toward the FIDO Alliance's portable, device-switching credential model.
The trend: Web authentication is migrating from per-site passwords to a shared open standard — WebAuthn — that browsers and platform vendors jointly implement.