With Mozilla's release of Firefox 60 on Wednesday, web browsers will start letting you log into websites without a password -- an important change in authentication technology that could help curtail costly phishing attacks.
Firefox 60 supports technology called Web Authentication, or WebAuthn for short, that can be used to grant you access to websites with a physical authentication device like a YubiKey dongle, biometric identity proof using an Android phone's fingerprint reader or the iPhone's Face ID, and some other alternatives to passwords.
Passwords are a particular problem on the web. Fake websites can coax you to type in credentials that then can be used to steal money from your bank account or snoop your email -- a problem called phishing. Even if you pick hard-to-guess passwords, never reuse them on multiple sites and always remember them, passwords still aren't that strong a foundation for security these days. We're still a long way away from a post-password future, but WebAuthn is an important step, if nothing else, in making sites more secure.
"It might be that, in a few years time, a significant number of people have a passwordless experience with at least one site that they use regularly. That'll be exciting," Google security expert Adam Langley said in a March blog post.
One WebAuthn fan is data-sync service Dropbox.
"As a user, you'll enjoy much stronger sign in security on more browsers," Dropbox programmer Brad Girardeau said in a blog post Tuesday. "You can feel confident when signing in that it's really us, and we can be confident it's really you."
Mozilla boasts that Firefox is the first browser out of the gate to support WebAuthn, but it's coming to Google's Chrome -- the next version, due this month -- and Microsoft's Edge, too. That should improve web authentication compared to earlier attempts to support the technology.
WebAuthn is "significantly more capable" than earlier attempts to support physical authentication keys, Langley said. Happily, WebAuthn supports earlier authentication hardware, so people who have invested in the technology won't have to start from scratch.
Firefox 60 also introduces new sponsored links -- ads -- on the new-tab page. Only a test group of Firefox users in the US will see them to start as Mozilla refines the technology, but expect it to spread as the nonprofit seeks to diversify revenue sources besides Google and other search engines that pay Mozilla when Firefox sends our queries their way.
Mozilla tried ads on the new-tab page in 2014 but dumped the project because of problems coming up with ads that were a good match. This time, though, Firefox will offer sponsored links based on its own assessment of our interests as informed by its Pocket service, through which you can flag sites you find interesting.
Even if you're not seeing ads on the new-tab page, Firefox will show more personalized suggestions for websites there, Mozilla said.
Some other things we think you might find interesting
Our series explores the different variants of dementia from both a scientific and carers viewpoint. Professor Michael Hornberger explains in layman terms, what's happening in the brain to help our understanding of the disease. Fascinating and awful in equal measure.
We also hear from c