• Solutions
    • Passwordless Authentication
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
© All rights reserved.
Nok Nok Nok Nok
  • Solutions
    • Passwordless Authentication
    • Passkeys
    • Secure Payments
    • Compliance
    • Professional Services
  • Industries
    • Government
    • E-Commerce
    • Financial Services
    • Mobile Network Operators
  • Products
    • Authentication Cloud
    • S3 Suite
    • Smart Analytics Module
    • Smart Sense Module
    • IoT SDK
  • Resources
    • Demo
    • Videos
    • White Papers
    • Testimonials
  • Company
    • About
    • Team
    • Partners
    • Clients
    • Events
    • News
    • Blog
    • Contact Us
    • Support Services
Nok Nok
Nok Nok News

Nok Nok News

18 Mar
3 Min read

Insurance Companies Are Charging Higher Premiums For Less Cyber-Intrusion Coverage

March 18, 2022 Nok Nok News Industry News 0 comments

Insurance companies around the USA are now following an alarming trend of increasing premiums on hacking and digital security breach coverage while providing less coverage when these issues occur. When it comes time to renew a policy for digital security, some companies are now facing as much as a 300% increase for budgeting in this contingency. A major reason for the increase is the rising number of successful attacks, forcing insurers to pay out to clients. Throughout the pandemic, as various organizations have moved work and data to local networks and even to cloud-based networks to facilitate data sharing, digital intrusions have increased. Ransomware and similar attacks have plagued many sectors, including construction, healthcare, government, and education that have failed to upgrade to more secure forms of protection like multifactor authentication.

More Measures Required Like Multifactor Authentication

Insurance companies themselves are becoming increasingly stringent when it comes to even considering giving coverage to a company for digital security. For example, many insurance companies won’t approve an application from a company that doesn’t use MFA, or multifactor authentication, a verification system that relies on more than just a person using only a single password to gain access to a network. Single password systems are incredibly vulnerable and far more prone to a successful intrusion than networks using MFA protocols.

Insurance companies are now also using their own scanning and digital reconnaissance technologies to “audit” the networks of potential clients and see how vulnerable they are. This has played a role in how insurers determine the monthly rates for the premiums a company must pay if they are serious about getting insured against cyber attacks.

Cyber Attacks Are Real And On The Rise

The days when only large companies or government agencies had to worry about hacking or other forms of digital intrusion are over. As more and more businesses of every size—and even private citizens—move more of their crucial data into the digital space, it becomes more lucrative for criminals.

Identity theft, where other individuals use personal identity details like credit cards and social insurance numbers, is rising. Ransomware, where network access and other critical functions are taken over and locked out until money is paid, is also hitting more companies. Network security is a real concern for any person or organization collecting and storing important, sensitive, or confidential data digitally. Legacy security systems based on single-passwords and personal information (knowledge-based access) is proving to be insufficient to protect against modern digital threats that are increasingly more sophisticated and automated. If you’re interested in upgrading your legacy security systems to modern FIDO-based multifactor authentication, Nok Nok has a variety of platform solutions and is trusted by the biggest financial institutions for protecting their customer’s identity and authentication.

Read more
16 Mar
3 Min read

Google Provides Digital Security Keys To Disrupt State-Level Hacking

March 16, 2022 Nok Nok News Industry News 0 comments

The world is now experiencing a time of conflict unlike anything seen in years, but because this is a modern-day, 21st-century clash, the war is not just being fought on a physical battlefield but also a digital one. As the invasion of Ukraine began official state hackers from both Russia and the West engaged in digital warfare, as did independent organizations such as “Anonymous,” a rogue hacking collective that has decided to stand against Russian cyber warfare.

Unfortunately, the worlds of military, corporate and civilian government data spaces are now considered fair game for state-level cyberattacks, funded and driven by government agencies. Now some companies are taking a stand.

Google Intervenes

Google, one of the premier technology companies globally for data management and analytics, is now providing security keys to groups and individuals to help protect them against cyberattack activity. They are distributing 10000 Titan security keys to individuals like journalists, whistleblowers, government officials, and others with sensitive or confidential data to encrypt and protect systems against intrusion and spying.

A Titan security key is an added level of encryption and access control. It is two devices, one a USB card shaped like a key, a Bluetooth device that functions similarly for wireless connections. This adds an extra level of multifactor authentication to an account. In addition to inputting a password to access data on, for example, a Gmail account, an account linked to a Titan security key would require the presence of the USB key plugged into the computer or a confirmed connection to the Bluetooth version for verification.

In other words, like with older multifactor authentication, methods that require a one-time code sent to a phone as an added layer of security, a Titan key system means that even if a password has been stolen through phishing or other means, the data can’t be accessed without a Titan security key to open the second “lock” on the data.

Multifactor Authentication Is The Best Defense

What Google and many other technology companies are discouraging is the use of only a single password to gain access to data and control of systems. A single password means that everything from identity theft, spying on confidential data, and outright seizure of control of systems is possible once that password is discovered.

Now that government agencies like Russia’s GRU are going after many systems and data, security is more important than ever.  If you’re still relying on a legacy password security technology and want to upgrade your network to modern identity and authentication security technology, (including the new global standard of key-pair biometrics), look at Nok Nok products for secure, password-free cyber authentication solutions. The largest global financial brands depend on Nok Nok’s modern auth platform for improving and protecting customer trust. 

Read more
16 Mar
4 Min read

Nok Nok Unveils Latest S3 Suite

March 16, 2022 Nok Nok News Press Release 0 comments

Nok Nok unveils the latest version of the S3 Authentication Suite – Version 8.0.1.

With this latest release, companies and organizations can now more easily operationalize modern identity and passwordless authentication in their system-level workflows, business processes and customer payment transactions. The enhancements to the Nok Nok S3 Authentication Suite are also designed to streamline large-scale operations in modern cloud environments and securely integrate with existing cryptographic infrastructure.

Key features and business benefits in this release include:

  • Enhanced Risk-Based Authentication: The S3 Suite now simplifies Registration and Authentication rules into a single ruleset. This allows customers to have full control over registration and authentication workflows based on predetermined business risk criteria to create very low friction customer journey experiences.
  • Federation Integration:  The S3 Suite now supports OpenID Connect as an integration mechanism allowing S3 to serve as an “authentication provider” that works with industry-leading identity providers (e.g., ForgeRock, Azure B2C) which allows Nok Nok customers to quickly integrate into existing identity and authentication systems.
  • Enhanced Transaction Confirmation Support: The S3 Suite will support payment transaction confirmation in Web Applications. Customers supporting PSD2-SCA workflows will be able to implement dynamic linking on both Mobile native and Web applications so that a fraudulent merchant or man-in-the-network can’t change the details of a FIDO-authenticated transaction to hijack and steal transaction revenue.
  • Integration With Existing Enterprise Cryptographic Infrastructure: Customers will be able to store sensitive digital system keys of our S3 server into standalone HSM (hardware security modules) or cloud-HSM hardware infrastructure to provide the ultimate business safeguards for storing and managing digital keys that control access to business servers and databases.
  • Pluggable Authentication for Backend Database Access: The S3 Suite servers will offer a pluggable connection framework that supports multiple architectural approaches to help our customers eliminate vulnerable database connections based on username and passwords from all of their existing system-level workflows and applications.
  • Support an External Backend “Secrets” Store: The S3 Server will support the ability to send push notifications and email-OTP messages through typically insecure, external gateways. To be secure, connecting and opening sessions to those external systems requires strong authentication.  With the new “external backend secrets store”, S3 offers the highest security in connecting with the systems of external MFA vendors.

“Through continued innovations that stay ahead of changing threat environments, Nok Nok continues to raise the bar above the modern authentication standards we helped to create. These new capabilities will offer greater integration flexibility for our customers that will enable them to integrate our S3 Suite with the use of their own APIs for handling encryption operations and also the use of external, hardware-based key vaults for storing sensitive information,” said Dr . Rolf Lindemann, Vice President of Products at Nok Nok.

Nok Nok’s S3 Authentication Suite was the first commercially deployed, highly scalable authentication suite built from the ground up leveraging the industry’s FIDO authentication protocols. With its modular architecture and container support, the Nok Nok S3 Suite has proven to run at internet scale, supporting mission-critical identity and modern authentication for tens of millions of users while protecting over 1B daily authentications around the globe.

About Nok Nok

Nok Nok is a pioneer in the FIDO standards and the trusted leader in next-generation identity and passwordless authentication solutions. The Nok Nok™ S3 Suite empowers companies to transform their customer experiences, transactions, business processes, and workflows by leveraging modern identity and passwordless authentication. The Nok Nok™ S3 Suite offers the most scalable and feature-rich passwordless solution that integrates into existing system-level workflows and legacy security infrastructure. Companies that implement the Nok Nok next-gen passwordless platform experience authentication success rates above 99%, onboarding conversion improvements of more than 10%, a 90% reduction in account recovery requests, and significantly reduced OpEx. Headquartered in Silicon Valley, California, the company has delivered unique inventions and innovations that are protected by a robust global patent portfolio. As a founder of the FIDO Alliance and an inventor of FIDO specifications, Nok Nok is the expert in deploying standards-based authentication, and its industry-leading customers and partners include Verizon, T-Mobile, Intuit, Cigna, Softbank, MUFG, NTT Docomo, Fujitsu Limited, Hitachi, Ericsson, MTRIX GmbH, NTT DATA, and OneSpan. For more information, visit www.noknok.com.

 

View the Official Press Release
Read more
16 Mar
4 Min read

Nok Nok Unveils Latest S3 Suite

March 16, 2022 Nok Nok News Press Release 0 comments

Nok Nok unveils the latest version of the S3 Authentication Suite – Version 8.0.1.

With this latest release, companies and organizations can now more easily operationalize modern identity and passwordless authentication in their system-level workflows, business processes and customer payment transactions. The enhancements to the Nok Nok S3 Authentication Suite are also designed to streamline large-scale operations in modern cloud environments and securely integrate with existing cryptographic infrastructure.

Key features and business benefits in this release include:

  • Enhanced Risk-Based Authentication: The S3 Suite now simplifies Registration and Authentication rules into a single ruleset. This allows customers to have full control over registration and authentication workflows based on predetermined business risk criteria to create very low friction customer journey experiences.
  • Federation Integration:  The S3 Suite now supports OpenID Connect as an integration mechanism allowing S3 to serve as an “authentication provider” that works with industry-leading identity providers (e.g., ForgeRock, Azure B2C) which allows Nok Nok customers to quickly integrate into existing identity and authentication systems.
  • Enhanced Transaction Confirmation Support: The S3 Suite will support payment transaction confirmation in Web Applications. Customers supporting PSD2-SCA workflows will be able to implement dynamic linking on both Mobile native and Web applications so that a fraudulent merchant or man-in-the-network can’t change the details of a FIDO-authenticated transaction to hijack and steal transaction revenue.
  • Integration With Existing Enterprise Cryptographic Infrastructure: Customers will be able to store sensitive digital system keys of our S3 server into standalone HSM (hardware security modules) or cloud-HSM hardware infrastructure to provide the ultimate business safeguards for storing and managing digital keys that control access to business servers and databases.
  • Pluggable Authentication for Backend Database Access: The S3 Suite servers will offer a pluggable connection framework that supports multiple architectural approaches to help our customers eliminate vulnerable database connections based on username and passwords from all of their existing system-level workflows and applications.
  • Support an External Backend “Secrets” Store: The S3 Server will support the ability to send push notifications and email-OTP messages through typically insecure, external gateways. To be secure, connecting and opening sessions to those external systems requires strong authentication.  With the new “external backend secrets store”, S3 offers the highest security in connecting with the systems of external MFA vendors.

“Through continued innovations that stay ahead of changing threat environments, Nok Nok continues to raise the bar above the modern authentication standards we helped to create. These new capabilities will offer greater integration flexibility for our customers that will enable them to integrate our S3 Suite with the use of their own APIs for handling encryption operations and also the use of external, hardware-based key vaults for storing sensitive information,” said Dr . Rolf Lindemann, Vice President of Products at Nok Nok.

Nok Nok’s S3 Authentication Suite was the first commercially deployed, highly scalable authentication suite built from the ground up leveraging the industry’s FIDO authentication protocols. With its modular architecture and container support, the Nok Nok S3 Suite has proven to run at internet scale, supporting mission-critical identity and modern authentication for tens of millions of users while protecting over 1B daily authentications around the globe.

About Nok Nok

Nok Nok is a pioneer in the FIDO standards and the trusted leader in next-generation identity and passwordless authentication solutions. The Nok Nok™ S3 Suite empowers companies to transform their customer experiences, transactions, business processes, and workflows by leveraging modern identity and passwordless authentication. The Nok Nok™ S3 Suite offers the most scalable and feature-rich passwordless solution that integrates into existing system-level workflows and legacy security infrastructure. Companies that implement the Nok Nok next-gen passwordless platform experience authentication success rates above 99%, onboarding conversion improvements of more than 10%, a 90% reduction in account recovery requests, and significantly reduced OpEx. Headquartered in Silicon Valley, California, the company has delivered unique inventions and innovations that are protected by a robust global patent portfolio. As a founder of the FIDO Alliance and an inventor of FIDO specifications, Nok Nok is the expert in deploying standards-based authentication, and its industry-leading customers and partners include Verizon, T-Mobile, Intuit, Cigna, Softbank, MUFG, NTT Docomo, Fujitsu Limited, Hitachi, Ericsson, MTRIX GmbH, NTT DATA, and OneSpan. For more information, visit www.noknok.com.

 

View the Official Press Release
Read more
07 Mar
3 Min read

A Nation’s Move To Modern Cyber Security

March 7, 2022 Nok Nok News Industry News 0 comments

Cyber attacks do not only target private individuals, but they can also represent increasingly sophisticated and persistent threats to national security. Billions of dollars are spent on legacy security annually, yet data breaches and theft are accelerating. Many institutions and organizations have suffered. That is why it is important to leverage modern security technologies and zero-trust architectures across sectors.

Becoming More Proactive

In its bid to address exposed areas of weakness in US digital infrastructure, the United States Federal Government updated its cyber security strategy.  In January 2022, President Biden signed Executive Order (EO) 14028 on Improving the Nation’s Cybersecurity. With this modern approach to cyber security, the US Federal Government boldly transitions from incremental improvements to legacy perimeter-based defenses – to significant investment in modern “zero-trust” architectures that never trust and always verify “anything and everything attempting to establish system and data access.”

Aiming for Safer Cyber Infrastructure

When multifactor authentication (MFA) was added to legacy knowledge-based-access (KBA) that is based on the storing and passing of passwords and other personal secrets, there was indeed, a measurable reduction in risk to digital systems and data compared to single factor authentication.

However, the attack strategies of bad actors (attack vectors) evolved such that today, these legacy KBA methods, even with MFA, no longer protect against sophisticated phishing attacks that easily fool account owners into providing account credentials to the attackers. Once a legitimate account is taken over (such as the case in the ransomware attack against Colonial Pipeline), it is very hard for any system to detect a bad actor before significant damage is done, data is stolen, or malicious code is embedded that creates security vulnerabilities at a later time (such as the case with the Solarwinds supply chain attack.)

In a very bold move and positive development for the modern identity and authentication industry, our nation’s new cyber security executive order recommends that federal agencies achieve zero trust security goals with strong, FIDO-based MFA by the end of Fiscal Year (FY) 2024, with plans for implementation due within 60 days.

Among other requirements for networks, devices, endpoints plus encryption for data and DNS traffic, the directive includes centralized enterprise-managed identities with phishing-resistant MFA to protect users from sophisticated attacks (including both PIV credentials and FIDO2 Web authentication (known as “WebAuthn”) created by the FIDO Alliance and published by the World Wide Web Consortium (W3C). The directive also includes enterprise-wide identity systems based on zero trust architecture that always verifies users before granting access.

Strong Defense for All

In a push for safer cyberspace infrastructure, the US Federal Government joins the thousands of enterprises that are leaving legacy KBA and perimeter-based security thinking behind in favor of modern and strong MFA identity and authentication.

As the world continues to see a massive proliferation in devices and network connectivity, technological advancements are required to address the growing challenges in fighting cyber threats and risks. Nok Nok Inc in partnership with the global FIDO Alliance they founded, is among those at the forefront of this fight.

The FIDO Alliance is an open industry association that develops and promotes authentication standards. At the same time, it also pushes for safer and more convenient cyber security measures for the end-user. Thus, making it a mission to reduce people’s insecure and over-reliance on legacy password and KBA-based system access. Learn about Nok Nok’s industry-leading FIDO platform for strong user and IoT authentication here.

Read more
04 Mar
3 Min read

Key-based Biometric Authentication: Addressing Fraud Through Modern Security

March 4, 2022 Nok Nok News Biometrics, E-Commerce 0 comments

Technology offers convenience. That cannot be denied. Recent years have proven how beneficial the Internet and smart devices can be in making various activities easier. A good example of this is online shopping. In the United States alone, more than 70% of residents have switched to online shopping in 2021 driven in part by changes in consumer purchasing behavior due to the Covid pandemic. 

Cyber Attacks: Fighting Risks

With the rise in the number of E-Commerce users come risks in security. Add to this the increase in electronic payment use for various transactions, including P2P payments.

Today’s new trend in Trust and Safety means institutions that have been strengthening cyber security for their own enterprise benefit, are now starting to focus on protecting end-users and their data. 

One way of doing this is by adopting modern authentication and security measures like FIDO-based biometric authentication. Generally, this type of user-centric authentication involves cryptographic keys and biometric methods including fingerprint use, voice authentication, and facial recognition, among others. In FIDO-based biometric authentication, user biometrics are under the control of the user and are never passed or stored by the enterprise.

Having modern authentication and security measures can prevent 80% of successful cyber breaches that according to Verizon’s 2021 annual security report, start with a man-in-the-middle or phishing attack, resulting in account take-overs, which are serious issues worldwide. 

In the U.S., online fraud attempts involving card payments increased by 23%. The Feedzai reported that during the second quarter of 2021, 93% of banking fraud occurs online and 83% of card fraud was done online. 

Purchase scams accounted for the top scam during the quarter based on volume. These happen when consumers are charged for products or services that they will not receive. 

Among other scams that are common during the period is SMS phishing or what some call smishing.

Taking the Right Step With Biometrics

Modernizing the security of identity verification for online transactions and interactions is also a must. The best way to do that is by implementing FIDO biometric and key-based authentication. With this modern authentication and security, it is harder for bad actors to get access to accounts and data.

This is especially crucial for financial institutions. Protecting cyberspace will also protect user data and assets.

That said, shifting into and implementing FIDO key-based identity and authentication can be a bit challenging for beginners. So, it may help to work with a reliable industry expert like Nok Nok that has already built a key-based identity and biometrics authentication platform trusted by some of the biggest banks, telcos and financial services brand in the world.

Nok Nok is a member of the FIDO Alliance and is an industry leader in the application of this modern security technology . Nok Nok also founded the association at the forefront of the fight against cyber threats and the over-reliance of people on passwords and other legacy knowledge-based authentication methods. In fact, the company offers multiple fast identity and passwordless authentication solutions like the incorporation of biometrics authentication including passwordless biometric authentication into consumer IoT devices.

You can check Nok Nok Products to find out more about multi-factor authentication and determine what is the best solution for your clients. 

Read more
02 Mar
4 Min read

Application of Modern Password Authentication: Examples From Nok Nok

March 2, 2022 Nok Nok News Industry News 0 comments

Billions of dollars are spent on legacy perimeter-based security annually, yet data breaches and theft continue to accelerate. These security risks are among the threats that institutions, especially those dealing with finance, need to address. Not only will solutions protect the organization itself, but they will also ensure the trust and safety of consumers – a top five 2022 priority among VP, C-suite and other enterprise executives.

Going Password Free

For many years, we have been relying on the use of passwords and knowledge-based-access (KBA) to verify user identity before granting system access. With its addition, while MFA has helped in protecting users against many types of attacks, the attack strategies of criminals evolved to find additional ways to take over accounts and conduct data breaches and identity theft.

Modern, phishing-resistant authentication (also referred to as “passwordless authentication”) is now a leading priority to improve security. Generally, it involves a consumer-centric approach to verify user identity without the need to capture, store and transmit passwords, personal secrets and other sensitive user data. This modern authentication approach involves cryptographic keypairs combined with one-time passwords (OTPs) and device-level biometrics that verify users on devices requesting access to digital services in a way that dramatically decreased user friction related to account setup and sign-in.

The advantages of going password-free can be experienced by both the institution and the users. As it offers dramatically reduced user-friction with defense-grade security, both the user experience and enterprise performance improve significantly. Enterprises implementing modern, phishing-resistant identity and authentication report authentication success rates of 99.5%, speed improvements in account signup and authentication of 50% or more and decreases in CSR calls and password resets of 60% or more. Both users and enterprises report dramatically improved consumer satisfaction in high value operating environments and payment transactions.

Nok Nok and Passwordless Authentication

Joining multiple members of the financial technology industry, Nok Nok participated in the recently conducted Authenticate 2021. Aside from being a participant, Nok Nok also served as a presenter.

During the presentation, attendees have seen some examples of real-world applications of password-free authentication. These are all based on Nok Nok’s customers’ experience.

  • Intuit TurboTax®: The partnership between Intuit and Nok Nok has addressed the former’s problem with a high level of friction during the creation of a new account. By leveraging the mobile App for passwordless Sign-Up, the company has seen a 10% increase in Sign-Up conversions. The Sign-Up time has also shown a 50% reduction.
  • T-Mobile: Forgotten passwords and account pins are among the problems many users experience. By incorporating FIDO-based biometrics and out-of-band push authentication, there has been at least a 65% reduction in account recovery requests within three months.
  • Fintech: Among the common problems causing friction to user experience is the complex login requirements, such as the use of passwords and SMS OTPs. Enhancing platform authenticators through FIDO passwordless authentication during web Sign-In, the Sign-In speed increased by 8x. Additionally, there was a 40% increase in users during the first month.
  • Major Bank: Financial institutions are also increasingly targeted by cyberattacks, especially for fraudulent activities. The use of modern FIDO biometrics and application pins for secure access via a mobile app has helped reduce fraud incidents. The app user reviews rating has also seen an improvement. Since one-time password resets are dramatically reduced, OPEX costs of decreased SMS OTP were reduced as well.
  • TEPCO Power Grid: Ensuring security is a must for the power grid. However, encouraging the use of complex passwords which are deemed “secure” slows down maintenance workers. To address this problem, Nok Nok and TEPCO leveraged modern web browser and device biometric authentication. Not only did this approach offer safe Sign-In experiences, but it also increased the speed and simplicity of account registration, account creation and sign-in as well.
Read more
28 Feb
3 Min read

Nok Nok Shares The Passwordless Journey: Here’s What You Need To Know

February 28, 2022 Nok Nok News Industry News 0 comments

Passwords have been used for many years to protect data and accounts. Despite being used for security purposes, using passwords is not always the best option. That is especially true when combatting cyber security threats. In fact, passwords can be seen as a weakness.

The Passwordless Authentication Path

Various risks come with the use of passwords. For example, users can forget about them. They are also easily compromised since many reuse passwords across different systems. Passwordless authentication is seen as a better alternative.

As the name suggests, password-free authentication includes the use of alternative authentication methods instead of relying on passwords. Common methods include the use of a secondary device or account for verification and biometric authentication.

Aside from reducing cyber security risks, going passwordless can help make reduce friction so that users will have a smoother experience. On the side of an institution, it helps reduce expenses. At the same time, it can help increase sales or the number of users.

Implementing Password-Free Authentication For Cyber Security

There are different ways of applying passwordless authentication. It is also more complex than one may think. Depending on what a company chooses, it may require having dedicated development resources for a long time.

Fortunately, working with a trusted service provider can help organizations skip some steps. In fact, with the help of a service provider, organizations can easily implement passwordless authentication for their users.

What Nok Nok Has Learned

The passwordless journey does not happen overnight. That is one of the main points Nok Nok has pointed out in its presentation at Authenticate 2021. The reasons for this include existing systems and processes being deeply rooted in security practices. It also takes a lot to develop behavior change, which is something necessary to fully adopt passwordless authentication. Additionally, the passwordless journey is typically included in a larger digital transformation.

Nok Nok also shared some of its experiences in applying password-free authentication in systems from different institutions. Based on the results of these partnerships, Nok Nok is proud to share that all companies have seen success.

Among the most notable statistics include the following:

  • 10% improvement in onboarding success
  • 50% reduction in onboarding time
  • 6% increase in sign in success
  • 78% increase in sign in speed

Going password-free comes with many benefits for both the institution and end-users. However, it is important to ensure proper implementation.

If you want to learn more about safer authentication techniques for better cyber security, contact us at Nok Nok.

Read more
22 Feb
2 Min read

MFA For Cybersecurity Gets Highlighted In Federal Zero Trust Strategy

February 22, 2022 Nok Nok News Industry News 0 comments

Cybersecurity is one of the pressing issues that the United States is facing. Threats affect the government, organizations, institutions, and even individuals.

The Identity Theft Resource Center (ITRC) said there were 1,291 data breaches publicly reported in the U.S. from January to September 2021, affecting about 281 million individuals. In comparison, this total is 17% more than the recorded breaches during the same period in 2020.

Government Efforts: The Federal Zero Trust Strategy

To address this problem, the government looks for ways to improve cybersecurity. On January 26, 2022, the Federal Zero Trust Strategy was released. The Office of Management and Budget (OMB) published the strategy as Memorandum M-22-09. Moving the U.S. Government Toward Zero Trust Cybersecurity Principles.

This move aims to promote a better security approach through government-wide efforts, setting a new baseline in terms of access controls. An important point to highlight is the prioritization of using phishing-resistant multi-factor authentication (MFA). Additionally, there is also a need to consolidate identity systems for improved protection and monitoring.

Understanding the Strategy

At the core of the strategy are two main focuses — the vision and actions on identity.

Generally, staff members of government agencies have to use enterprise-managed identities to get access to applications used for work. Phishing-resistant multi-factor authentication must be in place to protect said personnel against more sophisticated cyberattacks.

Three actions must be taken.

First, the agencies should have centralized management systems for users. 

Second, they should use strong MFA throughout the organization. Specifically, all agency staff members, contractors, and partners have to use phishing-resistant MFA. Meanwhile, public users should be given this option. Furthermore, it should not be required to use special characters for passwords or have regular password rotation.

Third, agencies should consider having at least one device-level signal when giving users authority to access resources. This signal is additional security alongside identity information about the authenticated user.

The FIDO Standard

Through the announcement of the strategy, the federal government also encouraged using FIDO2 standards. Thus, further recognizing the FIDO Alliance’s efforts to promote the use of phishing-resistant multi-factor authentication and reduce people’s over-reliance on passwords.

The FIDO2 is FIDO Alliance’s newest set of specifications. It includes Web Authentication (WebAuthn) specification and Client-to-Authenticator Protocol (CTAP). Learn more about the FIDO2 Project here.

Read more
15 Feb
2 Min read

E-Commerce Channels Get Better Security

February 15, 2022 Nok Nok News Cybersecurity, E-Commerce 0 comments

Security is among the top priorities and concerns of consumers around the world. That is especially true as we welcome more cashless transactions. Fortunately, many organizations have realized the importance of cyber security. For instance, EMVCo partnered with FIDO Alliance and W3C for fraud prevention.

Secure Transactions With Cyber Security

EMVCo, which is the organization that manages and develops EMV Specifications and programs to enable card-based payments, continuously works to ensure secure payment transactions. Addressing the challenges that come with global interoperability, the organization introduced an enhanced EMV 3-D Secure (3DS) Specifications. 

The latest version is called the EMV 3DS 2.3. It aims to improve the customer experience while strengthening the capabilities of acquirers, issuers, and merchants to fight fraud across various e-commerce channels and devices. 

EMV 3DS 2.3 At A Glance

The goal of adopting EMV 3DS 2.3 is to make the overall payment experience of customers better with a streamlined authentication process. At the same time, it offers more flexibility in implementing the EMV 3DS across channels and devices. Thus, helping issuers with the identification of fraudulent transactions.

One of the most important updates of this version focuses on cyber security. In its bid to further its efforts against fraud, EMVCo worked with World Wide Web Consortium (W3C) and FIDO Alliance. The collaboration resulted in the inclusion of Web Authentication (WebAuthn) and Secure Payment Confirmation (SPC) in the EMV 3DS flow. With these, issuers or merchants can better determine if a transaction is legitimate or not.

Here are other things you can expect:

  • Expect easier implementation of EMV 3DS on traditional and non-traditional e-commerce payment channels and/or devices due to the Split-SDK model that has multiple variants.
  • The consumer authentication process is seen to be faster as the updated version supports device binding, wherein the consumers’ devices remember their authentication details. 
  • The automated out-of-band transitions will allow consumers to seamlessly switch from a merchant application to a merchant application and vice versa. 
  • There will be additional data — transaction and EMV Payment Token — to help the issuers better identify transactions. Said data will also help simplify authentication in the future.

You can learn more about EMV 3DS Specifications on the organization’s website. You can also stay updated on new developments in cyber security by subscribing to Nok Nok.

Read more
  • 1…91011

Contact Us

Nok Nok, Inc.
2890 Zanker Rd #203
San Jose, CA 95134

(650) 433-1300

[email protected]

Get Google Maps Directions

Contact and Subscribe

* indicates required

Latest Posts

  • World Password Day: Time to Ditch Passwords for Good?
  • Verizon 2025 DBIR: Credential Attacks Still Dominate – A Nok Nok Perspective
  • Phillip Dunkelberger Recognized as a “Champion in Security” by Portal26 at RSA Conference 2025
  • Another Step Towards a Passwordless Future

Navigation

  • Subscribe
  • Careers
  • Resources
  • Support

Nok Nok Labs, Nok Nok, and NNL are all trademarks of Nok Nok Labs, Inc. © 2025 Nok Nok Labs, Inc.
FIDO is a trademark of the Fast IDentity Online, (FIDO), Alliance. All rights reserved.
Terms Of Use and Privacy Policy

 

Demo
Free Trial
Videos
Contact Us
Support

Contact Us: (650) 433-1300 • [email protected]

Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}
Manage Consent
To provide the best experiences, we use technologies like cookies to store and/or access device information. Consenting to these technologies will allow us to process data such as browsing behavior or unique IDs on this site. Not consenting or withdrawing consent, may adversely affect certain features and functions.
Functional Always active
The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
Preferences
The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
Statistics
The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
Marketing
The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
Manage options Manage services Manage {vendor_count} vendors Read more about these purposes
View preferences
{title} {title} {title}

Please complete this form to view and download this resource.

Submit to Download Forms

* indicates required

[mc4wp_form id=”18773″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18790″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18789″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18788″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18787″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18786″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18785″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18784″]

Please complete this form to view and download this resource.

[mc4wp_form id=”18783″]

MUFG-800×600

“Transactions using mobile devices are rapidly spreading and it is essential to support both usability and security. By combining Hitachi’s abundant system development capabilities and know-how in the financial system and security related fields, and Nok Nok’s globally deployed and proven FIDO certified products, we achieved this compatibility, which led to this adoption.”

– Mr. Nobuo Nagaarashi, General Manager, Financial Information Systems 1st Division, Hitachi, Ltd.

 

The M in MUFG stands for Mitsubishi, which is a combination of the words mitsu and hishi. Mitsu means three. Hishi means water chestnut, and the word denotes a rhombus or diamond shape.  In partnership with Hitachi, MUFG has enabled passwordless authentication solutions across many of the bank’s apps and services.

Coverage In The Paypers
Coverage In Finextra
intuit

“As an early adopter of FIDO, we’ve seen significant business benefits and are completely on board with continuing to leverage the latest FIDO innovations with our partner, Nok Nok.”

– Rakan Khalid, Group Product Manager, Identity.

 

Intuit has delivered passwordless authentication across mobile applications and devices using Nok Nok’s S3 Suite. The results have reduced customer friction in their Intuit application experience.

Read The Nok Nok Intuit Case Study
Watch the FIDO Alliance Webinar: The Right Mix
Watch Marcio Mello discuss Intuit’s Nok Nok implementation at Identiverse 2019:
docomo-800×600

“DOCOMO is a worldwide innovator in providing its millions of customers with simple and strong authentication backed by a standards-based approach.”

– Phillip Dunkelberger, President & CEO of Nok Nok Labs.

 

As one of Nok Nok’s earliest customers, NTT DOCOMO became the first carrier to offer a billing system that is enabled by FIDO, the first to offer a federated Identity system integrated FIDO, and was the first to offer a mobile device that authenticates via the iris biometric modality.

Coverage In Find Biometrics
Coverage In Telecompaper
bbva-800×600-2

“Traditionally, one of the biggest challenges of authentication systems has been to balance security with user experience. Due to the FIDO standard, we are confident that both elements work together seamlessly to provide customers with the highest security standards, along with a transparent and agile user experience.”

– Juan Francisco Losa, Global Technology & Information Security Officer.

Nok Nok partnered with banking leader, BBVA to improve the security and user experience of the bank’s mobile banking services through state-of-the-art biometric capabilities.

Coverage In American Banker
Coverage In Planet Biometrics
Softbank-800×600-1

“We can no longer rely on passwords for our financial or other sensitive transactions as they are weak, forgotten and easily hacked. We are very pleased with SoftBank’s decision to choose our standards-based authentication platform for their millions of customers.”

– Phillip Dunkelberger, President & CEO of Nok Nok Labs.

 

Millions of SoftBank’s mobile subscribers now have the ability to use biometrics for authentication through the mobile application “My SoftBank Plus”. With this implementation, SoftBank’s mobile users access data with the My SoftBank service using biometrics for a frictionless, simple and fast authentication experience.

Coverage In Mobile ID World
Coverage In Planet Biometrics
Coverage In The Paypers
Aflac-Japan-800×600-1

“Aflac is the first Japanese insurance provider to deploy a FIDO-certified solution, and we would like to continue collaborating with Nok Nok Labs to introduce it to banks, insurance industry and other industries.”

– Michihiko Ejiri, VP, Head of Portal Service Division, Service Technology Unit, Fujitsu Limited.

With the Nok Nok S3 Suite, Fujitsu has provided Aflac customers with strong authentication to their mobile claims payment application using any biometrics on their iOS and Android devices. The solution also provides Aflac and their customers with a scalable method to authenticate users that is interoperable with their existing security environments and reduces or eliminates the reliance on usernames and passwords.

Coverage In Find Biometrics
Coverage In Find Authority
lichtenstein-800×600-1

“For our customers, we only use the most secure products on the market that meet their requirements. Nok Nok perfectly aligns within our product portfolio and we are proud of the very trusted partnership.”

– Lukas Praml, CEO of YOUNIQX.

 

YOUNIQX Identity AG, the award-winning subsidiary of the Austrian State Printing House (OeSD) and Nok Nok partnered to deliver a electronic identity system (eID) for the citizens of the country of Liechtenstein.  This deployment represents the first time that Nok Nok’s FIDO platform has been used to deliver an eID.

FUN FACT
As of 2009 Liechtenstein’s per capita income was $139,100, the highest of any country in the world.

Learn How FIDO Supports EIDAS Regulation
Coverage In Mobile ID World
Coverage In The Paypers
Coverage In Biometric Update
Gallagher-800×600-1

“Nok Nok’s state-of-the-art, standards-based platform will deliver a tremendous user experience,”

– Steve Bell, Chief Technology Officer at Gallagher

When a horse called Joe took too much of a liking to using a car as a scratching post, owner Bill Gallagher Sr. devised a cunning electrical circuit that delivered a shock whenever the horse rocked the vehicle, and in doing so created a company.  Today, with passwordless authentication from Nok Nok, Gallagher is leading the IoT industry with innovative solutions that work in your office and in the outback.

Coverage In Biometric Update
Coverage In Mobile ID World
Coverage In Planet Biometrics
tmobile-800×600-1

“Our Forgot Password flows were running at about 65%. After we rolled out FIDO by Nok Nok, our forgot passwords dropped to 7%.”

Michael Engan, T-Mobile

 

Using the Nok Nok S3 Suite, T-Mobile has become a leader in carrier adoption of passwordless authentication. Their solutions have reduced forgotten passwords and dramatically improved customer satisfaction.

Watch Michael Engan from T-Mobile talk about their implementation of Nok Nok’s S3 Authentication Suite at Identiverse 2019.

  • 日本語