---
title: Twitter Hack in Bitcoin Scam Reveals Fundamental Security Flaw
description: Hackers took over the accounts of various Twitter celebrities to orchestrate a bitcoin scam. This revealed a fundamental security flaw.
image: https://blog.strongkey.com/hubfs/Twitter%20Hack%20Option%201-1.png
---

[![StrongKey Logo](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

INDUSTRY

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa50e587d1ab_cpu%20(1).svg) 

[Fintech Payments, card capture ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg)](https://www.strongkey.com/solutions/industry/fintech) [Enterprise Fully scalable customization ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg)](https://www.strongkey.com/solutions/industry/enterprise) [Manufacturing IIoT integration, key injection ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg)](https://www.strongkey.com/solutions/industry/manufacturing)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2d4787d1e0_check-square.svg)

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated; low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burden of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

Products

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

SOFTWARE

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa215487d1ca_activity.svg) 

[FIDO2 Passwordless Authentication Reduce password-related costs ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg)](https://www.strongkey.com/products/software/fido-strong-authentication) [Public Key Infrastructure Build new or update existing ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg)](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [Encryption & Tokenization For small and mid-sized applications ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg)](https://www.strongkey.com/products/software/tokenization-and-encryption) [Custom Solutions Work with us to find a solution ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cffdbccd1c7f01ee3fce_cicruit.svg)](https://www.strongkey.com/products/software/custom-solutions)

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa92287d205_truck.svg)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Development Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa554a87d2a0_chevron-down.svg)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy and future](https://www.strongkey.com/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) Partners and Resellers Who we do business with](https://blog.strongkey.com/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/careers)

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) 

[DEMOS ![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa61e187d118_arrow-left.svg)](https://www.strongkey.com/demos)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa118387d144_STR.Horizontal1_LightUSB_TM.png)](https://www.strongkey.com/)

[Home](https://www.strongkey.com/)

Solutions

COMPLIANCE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1de987d1e1_zap%20(1).svg) PSD2/SCA Integrated for low abandonment](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa6a5787d1a2_credit-card.svg) PCI DSS Reduce costs and burdens of audits](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf26e87d1ac_lock%20(1).svg) NACHA Easily secure deposit data](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) GDPR Application-level data protection](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf0ba87d1ba_users.svg) CCPA Consumer data privacy](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)

INDUSTRY

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026cfe6abf7e7861b604289_bank.svg) Fintech Payments, card capture](https://www.strongkey.com/solutions/industry/fintech) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf9e687d218_star.svg) Enterprise Fully scalable customization](https://www.strongkey.com/solutions/industry/enterprise) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6026d009d6756ce5aa5a0cf6_manufacturing.svg) Manufacturing IIoT integration, key injection](https://www.strongkey.com/solutions/industry/manufacturing)

Products

SOFTWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaea2f87d1d9_user-check.svg) FIDO Passwordless Authentication Reduce password-related costs](https://www.strongkey.com/products/software/fido-strong-authentication) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa991687d1d4_key.svg) Public Key Infrastructure Build new or update existing](https://www.strongkey.com/products/software/pki-key-and-certificate-management) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa477087d1d3_shield.svg) Encryption & Tokenization For enterprise applications](https://www.strongkey.com/products/software/tokenization-and-encryption)

HARDWARE

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa1afb87d1b4_server%20(1).svg) Hosted Solutions We do the heavy lifting](https://www.strongkey.com/products/hardware/hosted-solution) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aac83e87d1d1_hard-drive%20(1).svg) Tellaro T-Series Specifically for SMBs](https://www.strongkey.com/products/hardware/products-tellaro-t-midmarket-small-business-data-security) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa298687d1a1_database.svg) Tellaro E-Series Enterprise data protection](https://www.strongkey.com/products/hardware/products-tellaro-e-enterprise-data-security-solution)

Developer

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa65cf87d1db_codepen%20(2).svg) Open Source Collaboration Everyone wins when we share](https://www.strongkey.com/developer/developer) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaa41287d1e5_terminal.svg) Swagger API Docs Easy to use and learn](https://demo4.strongkey.com/getstarted/#/openapi) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa2b7687d1dc_log-in.svg) GitHub StrongKey FIDO Server Sample code, tutorials](https://github.com/StrongKey/fido2)

About

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aad93e87d1b7_home%20(1).svg) Company Our history, philosophy, and future](https://www.strongkey.com/about/company) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa600c87d207_tv.svg) Newsroom Latest news about StrongKey](https://blog.strongkey.com/newsroom) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa000d87d1b5_book-open.svg) Resources Access our content and documentation](https://blog.strongkey.com/resources) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aaf14f87d20c_mic.svg) Events Where you'll be able to meet us](https://www.strongkey.com/about/events) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa54be87d1ce_briefcase%20(1).svg) Careers Join us to improve data security for all](https://www.strongkey.com/about/careers) 

[Blog](https://blog.strongkey.com/blog) [CONTACT](https://www.strongkey.com/contact) [Demos](https://www.strongkey.com/demos)

[Dave Humphreys](https://blog.strongkey.com/blog/author/dave-humphreys) - Aug 04, 2020

# Twitter Hack in Bitcoin Scam Reveals Fundamental Security Flaw

- [Tweet](https://twitter.com/share)

[FIDO](https://blog.strongkey.com/blog/tag/fido)  [Breaches](https://blog.strongkey.com/blog/tag/breaches)

Back in July 2006 when Twitter, then known as Twtrr, was unleashed onto the unsuspecting public, the world was a simpler and gentler place. President Bush rolled out an anticipatory *in case* [Flu Pandemic Plan as a blueprint](https://www.usatoday.com/story/opinion/2020/04/06/coronavirus-donald-trump-ignores-2005-bush-pandemic-plan-column/2950848001/), but there was no actual pandemic. And it would be another three years before Bitcoin, the first decentralized crypto currency, made its debut.

The service, launched by the now-defunct Odeo, was simple, powerful, and innovative, but majorly insecure. As CEO Jack Dorsey proclaimed back in 2007, “One could change the world with one hundred and forty characters.” Not much has differed with regards to Twitter in the intervening time period, except the global bad actors now out-innovate the innovators, running rings around them whilst damaging companies and consumers alike.

A Coordinated Attack: Hackers Take over High-Profile Accounts

According to the [New York Times](https://www.nytimes.com/2020/07/15/technology/twitter-hack-bill-gates-elon-musk.html), on Wednesday afternoon, July 21st, some of the rich and famous tweeted similar altruistic messages: just forward me some Bitcoin and I, out of the goodness of my heart, will send back twice the amount. The scam has badly embarrassed the powers-that-be at Twitter, or so they say.

Twitter’s support folks reported the company was subjected to a coordinated social engineering attack targeting employees who had access to internal administration systems and tools. The hacked employee accounts were used to access and tweet from the accounts of targeted social media aristocracy and to compromise several cryptocurrency Twitter accounts used to reinforce the scam.

To keep the owners of the hacked accounts from being alerted that their passwords had been changed, the hackers disabled (or diverted) the two-factor authentication (2FA) account security that typically sends texts or emails when passwords are changed. Without the password change alerts, account owners had to rely on other means to notice that something was amiss with their accounts. Further, account owners completely lost the ability to access their Twitter accounts as they had no access to the hacker-reset passwords.

One of Twitter’s first actions was to change the email addresses for the affected accounts. With new (presumably isolated) email addresses for the affected accounts, hackers were no longer able to access individual accounts. If they tried to change the password, they weren’t able to use the email address to make or confirm additional password changes.

## How Could This Have Happened?

It is difficult to comment accurately on the administration authorization regime within Twitter, but on the face of things, despite having agreed to 10 years of security audits as part of a [2010 Federal Trade Commission settlement](https://www.nytimes.com/2020/07/15/technology/twitter-hack-bill-gates-elon-musk.html), internal policies appear far too lax for a company that holds accounts for people who actually can change the world with the wave of a wand of words. Based on media reports, it’s hard to understand exactly what happened. However, since employee accounts were compromised to gain access to internal admin tools, it’s not too much of a stretch to assume employee accounts were protected by passwords or shared-secret authentication.

As reports of data breaches have become common, our society seems to have become numb to them. It doesn’t need to be this way. Passwords are the leading cause of data breaches on the internet accounting for more than [80 percent of hacking-related breaches](https://blog.lastpass.com/2019/05/passwords-still-problem-according-2019-verizon-data-breach-investigations-report.html/). Passwords are an outdated means of accessing accounts or data. The sooner passwords and other forms of shared-secret authentication, such as one-time passwords (OTP), knowledge-based authentication (KBA), and SMS codes are eliminated, the safer we will be, and the hacking news coma will be relieved.

## Stronger Authentication Exists. Why Not Use It?

If the Twitter admin accounts had required a strong authentication method, this particular hack would have been a lot more difficult to pull off. There is some speculation that there was an ‘insider’ admin at Twitter involved; in this case using strong authentication for the admin user wouldn’t have helped prevent the hack. However, if the administrator policy had been designed to require a second admin (using strong authentication) before any 2FA was disabled for a user, that would have made it extremely difficult for the hacker.

The [FIDO Alliance](https://fidoalliance.org/), a nonprofit standards group of more than 200 companies from around the world, has been working for more than five years to eliminate passwords from enterprise and the internet. They have standardized [three protocols](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2) that have had dozens of implementations on the market for the past four years.

[Web Authentication (WebAuthn)](https://www.w3.org/TR/webauthn-1/), a core component of the Alliance’s FIDO2 set of specifications, is an API that allows websites to update their login pages to add FIDO-based authentication on supported browsers and platforms. FIDO2 enables users to leverage common devices to easily authenticate to online services in both mobile and desktop environments.

In 2017, the National Institute of Standards and Technology (NIST) published a draft [Special Publication 800-63-3](https://doi.org/10.6028/NIST.SP.800-63-3), Digital Identity Guidelines, naming FIDO-based solutions as the highest level of authentication technology assurance for federal use.

## The Passwordless Opportunity for a More Secure Future

IT professionals know that internal administration tools require the highest possible level of security controls. They may need to learn about the newest and most secure ways but importantly, what they really need is internal buy in from the top of their organizations.

Forward-seeking companies can easily roll out a better alternative for authenticating humans to devices. The vast majority of these authenticating devices need nothing more than the basic Universal Second Factor (U2F) protocol in passwordless mode to enable the registration of the first U2F key presented as the administrator's key to the device.

Twitter has been far-sighted enough to support FIDO authentication as an *option* for its users, yet it seems they haven’t used this security infrastructure to secure their internal systems. At a minimum—especially with their history of data breaches—they should require strong authentication for employee access. And it is time to start innovating again and take one important step further. To protect as many of its users as possible, Twitter should aim to have a vast majority of its user base—including all verified accounts—authenticate into their Twitter accounts by using FIDO2. If Twitter ‘mandated’ its customers to use FIDO2 it would be possible to design their platform to prevent the FIDO2 requirement being turned off for its users by an admin. Account recovery is a separate topic that we won’t discuss here.

What is Twitter waiting for? With the rapid maturation and support for WebAuthn, over [85 percent of today’s browsers](https://fidoalliance.org/expanded-support-for-fido-authentication-in-ios-and-macos/) now support FIDO2 Authentication—and FIDO2 works on both iOS and Android mobile devices.

The WebAuthn specification defines further use cases for public-key cryptography, which will continue to raise the bar for future hackers as the recommendations are implemented. [$1.3B was wiped off the market value of Twitter due to the attack](https://markets.businessinsider.com/news/stocks/twitter-market-value-losses-after-massive-hack-2020-7-1029402144); strong authentication could be implemented for a tiny fraction of that amount.

## About the Author

Dave Humphreys is a Regional VP of [StrongKey](https://strongkey.com/?utm_source=npi&utm_medium=SB327&utm_campaign=SB_327), a Cupertino, CA and Durham, NC company focused on securing data through key management, strong authentication, encryption, and digital signatures. Take a look at StrongKey’s FIDO2 information [here.](https://strongkey.com/fido2-fast-identity-online-v2/)

[![Cybersecurity can be hard, we get it. Click here to request a free security assessment.](https://no-cache.hubspot.com/cta/default/4723359/36fc7565-d889-4514-b5d0-f05165a346f9.png)](https://cta-redirect.hubspot.com/cta/redirect/4723359/36fc7565-d889-4514-b5d0-f05165a346f9)

### ALL TOPICS

- [FIDO (45)](https://blog.strongkey.com/blog/tag/fido)
- [Culture/Influence (31)](https://blog.strongkey.com/blog/tag/culture-influence)
- [Cybersecurity ROI (29)](https://blog.strongkey.com/blog/tag/cybersecurity-roi)
- [Breaches (16)](https://blog.strongkey.com/blog/tag/breaches)
- [Encryption/Tokenization (16)](https://blog.strongkey.com/blog/tag/encryption-tokenization)
- [Payments/E-Commerce (15)](https://blog.strongkey.com/blog/tag/payments-e-commerce)
- [Disruptive Defenses (14)](https://blog.strongkey.com/blog/tag/disruptive-defenses)
- [Key Management (11)](https://blog.strongkey.com/blog/tag/key-management)
- [PSD2 (11)](https://blog.strongkey.com/blog/tag/psd2)
- [GDPR and CCPA (8)](https://blog.strongkey.com/blog/tag/gdpr-and-ccpa)
- [SCA (8)](https://blog.strongkey.com/blog/tag/sca)
- [Events (7)](https://blog.strongkey.com/blog/tag/events)
- [Employee Spotlight (6)](https://blog.strongkey.com/blog/tag/employee-spotlight)
- [Ransomware (5)](https://blog.strongkey.com/blog/tag/ransomware)
- [COVID-19 (4)](https://blog.strongkey.com/blog/tag/covid-19)
- [PCI DSS (4)](https://blog.strongkey.com/blog/tag/pci-dss)
- [Products (4)](https://blog.strongkey.com/blog/tag/products)
- [Blockchain (3)](https://blog.strongkey.com/blog/tag/blockchain)
- [Healthcare (3)](https://blog.strongkey.com/blog/tag/healthcare)
- [Hybrid Cloud (RC3) (3)](https://blog.strongkey.com/blog/tag/hybrid-cloud-rc3)
- [IoT (3)](https://blog.strongkey.com/blog/tag/iot)
- [PKI (3)](https://blog.strongkey.com/blog/tag/pki)
- [Press Releases (2)](https://blog.strongkey.com/blog/tag/press-releases)
- [Citrix (1)](https://blog.strongkey.com/blog/tag/citrix)
- [Passkeys (1)](https://blog.strongkey.com/blog/tag/passkeys)

### Most Popular

<https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Key Management](https://blog.strongkey.com/blog/tag/key-management) [Passkeys](https://blog.strongkey.com/blog/tag/passkeys)

**[“Would you trust your bank with both keys to your ....](https://blog.strongkey.com/blog/would-you-trust-your-bank-with-both-keys-to-your-safe-deposit-box)**

<https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses)

**[An In-depth Guide to FIDO Protocols: U2F, UAF, and....](https://blog.strongkey.com/blog/guide-to-fido-protocols-u2f-uaf-webauthn-fido2)**

<https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how>

[Key Management](https://blog.strongkey.com/blog/tag/key-management) [Cybersecurity ROI](https://blog.strongkey.com/blog/tag/cybersecurity-roi)

**[Key Custodians: Who, What, Where, When, Why, and H....](https://blog.strongkey.com/blog/key-custodians-who-what-where-when-why-and-how)**

<https://blog.strongkey.com/blog/fido-101-strong-authentication>

[FIDO](https://blog.strongkey.com/blog/tag/fido) [Disruptive Defenses](https://blog.strongkey.com/blog/tag/disruptive-defenses) [Culture/Influence](https://blog.strongkey.com/blog/tag/culture-influence)

**[FIDO 101: Understanding FIDO Strong Authentication....](https://blog.strongkey.com/blog/fido-101-strong-authentication)**

### Archive

- [March 2026 (1)](https://blog.strongkey.com/newsroom/archive/2026/03)
- [June 2025 (1)](https://blog.strongkey.com/newsroom/archive/2025/06)
- [March 2022 (1)](https://blog.strongkey.com/newsroom/archive/2022/03)
- [December 2021 (1)](https://blog.strongkey.com/newsroom/archive/2021/12)
- [March 2021 (6)](https://blog.strongkey.com/newsroom/archive/2021/03)
- [December 2020 (4)](https://blog.strongkey.com/newsroom/archive/2020/12)
- [November 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/11)
- [October 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/10)
- [September 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/09)
- [August 2020 (3)](https://blog.strongkey.com/newsroom/archive/2020/08)
- [June 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/06)
- [April 2020 (2)](https://blog.strongkey.com/newsroom/archive/2020/04)
- [February 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/02)
- [January 2020 (1)](https://blog.strongkey.com/newsroom/archive/2020/01)
- [December 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/12)
- [September 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/09)
- [August 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/08)
- [July 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/07)
- [June 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/06)
- [May 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/05)
- [April 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/04)
- [March 2019 (1)](https://blog.strongkey.com/newsroom/archive/2019/03)
- [February 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/02)
- [January 2019 (3)](https://blog.strongkey.com/newsroom/archive/2019/01)
- [December 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/12)
- [November 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/11)
- [October 2018 (3)](https://blog.strongkey.com/newsroom/archive/2018/10)
- [September 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/09)
- [August 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/08)
- [July 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/07)
- [April 2018 (2)](https://blog.strongkey.com/newsroom/archive/2018/04)
- [January 2018 (1)](https://blog.strongkey.com/newsroom/archive/2018/01)
- [October 2017 (1)](https://blog.strongkey.com/newsroom/archive/2017/10)

![Strongkey - Logo](https://blog.strongkey.com/hubfs/Strongkey%20-%20Logo.png "Strongkey - Logo")

StrongKey provides solutions to companies looking to solve for PCI DSS, PSD2 Strong Customer Authentication, passwordless authentication with FIDO, data privacy, public key infrastructure and other security challenges.

Copyright 2022 StrongKey, Inc.

- [Privacy Policy](https://www.strongkey.com/about/privacy-policy)
- [Terms of Use](https://www.strongkey.com/about/terms-of-use)
- [Cookie Policy](https://www.strongkey.com/about/cookie-policy)

#### About

- [Company](https://www.strongkey.com/about/company)
- [Newsroom](https://blog.strongkey.com/newsroom)
- [Events](https://www.strongkey.com/about/events)
- [Careers](https://www.strongkey.com/about/careers)

#### Solutions

- [PCI DSS](https://www.strongkey.com/solutions/compliance/pci-dss-card-capture-services)
- [FIDO](https://www.strongkey.com/products/software/fido-strong-authentication)
- [PSD2 SCA](https://www.strongkey.com/solutions/compliance/psd2-strong-customer-authentication)
- [CCPA](https://www.strongkey.com/solutions/compliance/ccpa-california-consumer-protection-act)
- [GDPR](https://www.strongkey.com/solutions/compliance/gdpr-general-data-protection-2)
- [NACHA](https://www.strongkey.com/solutions/compliance/nacha-deposit-data-protection)

#### Resources

- [Library](https://blog.strongkey.com/resources)
- [CONTACT US](https://www.strongkey.com/contact)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526cad36f3a5e723525fba_GitHub_logo_white_10%25.png)](https://github.com/StrongKey) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa071787d2c3_Twitter.png)](https://twitter.com/strongkeyinc) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/5fbbeb5a2e59aa775287d2c0_Linkedin.png)](https://www.linkedin.com/company/strongkey)

[![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/60526bcf0df80d185f961b8d_youtube_white_icon.png)](https://www.youtube.com/channel/UCueU61oRt9G6MILRSHIfimA) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036be2bdf2d65e2d2fc906f_Instagram_5%25.png)](https://www.instagram.com/strongkeyinc/) [![](https://uploads-ssl.webflow.com/5fbbeb5a2e59aa544f87d0bb/6036bd8ef3da6a4bb2e24382_facebook_10%25.png)](https://www.facebook.com/strongkeyinc/)

#### Subscribe to Our Newsletter

Receive helpful information and the latest news from the world of cybersecurity