Connect with us

Hi, what are you looking for?

Apple

Tidas released to allow password ditching

Tidas is an iOS SDK that allows developers to offer the strongest user security protections — without the hassle of passwords — on any iPhone running iOS9.

Trail of Bits, a New York City-based information security company, has released Tidas, a first-of-its-kind security tool for app developers that boosts user privacy and minimizes developer liability—all by ditching passwords completely.

tidas

Tidas is an iOS SDK that allows developers to offer the strongest user security protections — without the hassle of passwords — on any iPhone running iOS9.

“Mobile apps usually have an awful user experience when it comes to security,” said Dan Guido, a security researcher and co-founder of Trail of Bits. “Trying to enter a complicated password on a mobile phone is difficult, and many users settle for weaker passwords to save time and frustration.”

Tidas is the first system to tap the native security features of Apple iOS9 — Touch ID and the Secure Enclave encryption chip — to identify users without a password. Apps built with the Tidas SDK require users to touch their phone’s Touch ID sensor to create an authentication token, much in the way Apple Pay does to secure payment transactions. The authentication token is based on a cryptographic key that never leaves the Secure Enclave. Apps use this token to verify the user’s identity and access backend services with strong authentication.

Advertisement. Scroll to continue reading.

Because Tidas operates in the Secure Enclave and neither collects nor stores any personal information, Trail of Bits and app developers have no access to sensitive data, such as passwords or Touch ID fingerprints, minimizing developer liability in the event of a data breach. “Even if a phone is jailbroken or infected with malware, no one can steal the keys from the Secure Enclave,” Guido said. “This is the strongest way to secure a transaction, whether it’s a password authentication or a purchase, and it’s time for app developers and users to benefit from that protection.”

Tidas is available on a free trial basis until March 31. Cloud and private enterprise versions of Tidas are available, allowing both consumer app developers as well as enterprises — especially those with high security needs, such as financial or healthcare institutions — to use the software.

Advertisement
Advertisement
Advertisement

Like Us On Facebook

You May Also Like

HEADLINES

"Given the Philippines' high exposure to cyber threats, it's important for both individuals and businesses to stay vigilant," said Adrian Hia, Managing Director for...

White Papers

When compared to 2023, Sophos saw a 51% increase in abusing “Living off the Land” binaries or LOLbins; since 2021, it’s increased by 83%.

HEADLINES

Someone illegally acquires or uses personal information such as bank account or credit card numbers of another person to obtain money, goods or services....

HEADLINES

To stay ahead of these challenges, organizations need to invest in AI-driven defenses, transition to quantum-safe encryption, and adopt a Zero Trust approach to...

HEADLINES

There was a 121% Year-on-Year (YoY) increase in identity fraud in 2024 across the region, with significant surges recorded in Singapore (207%), Thailand (206%)...

White Papers

The survey found that CXO’s feel less prepared than their global peers. Less than half or 48% in APAC said they felt completely prepared...

HEADLINES

On average, a single organization in the Philippines experiences 4,003 attacks per week, significantly higher than the APAC average of 2,870 attacks per week.

White Papers

Exploiting this vulnerability, cybercriminals craft deceptively authentic phishing emails that align with current trends, exploiting human emotions to invoke urgency and trick recipients into...

Advertisement