Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Los Angeles, California, United States
Sign in to view Andrew’s full profile
Andrew can introduce you to 10+ people at FIDO Alliance
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
5K followers
500+ connections
Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Andrew
Andrew can introduce you to 10+ people at FIDO Alliance
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
View mutual connections with Andrew
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Sign in to view Andrew’s full profile
or
New to LinkedIn? Join now
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
About
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Articles by Andrew
-
Thoughts on World Password Day
Thoughts on World Password Day
[this is a crosspost from my reflections made today on the FIDO Alliance blog] Yesterday, Google announced support for…
75
4 Comments -
Password Protecting our DemocracyNov 3, 2020
Password Protecting our Democracy
We’re on the cusp of the 2020 presidential election, and it feels like 2016 all over again -- only much worse. Between…
20
1 Comment -
Putting Passwords out to PastureJun 4, 2020
Putting Passwords out to Pasture
Passwords are not just the bane of every online account holder’s existence, they’re also the thorn in the side of every…
29
2 Comments
Activity
5K followers
-
Andrew Shikiar reposted thisAndrew Shikiar reposted thisAs #GDC26 kicks off built around the idea of turning collaboration into action, I want to highlight this recent success of collaborative effort: WebAuthn Level 3 reached W3C Recommendation status. Some may ask “Wait, wasn’t it a standard already?”, but this milestone matters a lot. WebAuthn and FIDO CTAP are the foundation of FIDO2 and, ultimately, passkeys. Having L3 now established as a stable, normative standard gives the ecosystem a clear reference point for implementation, conformance, procurement, and regulation — while formalizing many of the capabilities that have already been making passkeys work better in the real world. A lot of people contributed tirelessly to get us here. But the work doesn’t end here. I wrote a bit more about what this milestone means for the passkey ecosystem and what comes next on the FIDO Alliance blog: https://lnkd.in/gQCr-JZD #WebAuthn #Passkeys #FIDO #Standards #DigitalIdentity #Authentication #UsePasskeysWebAuthn Level 3 Is Now a W3C Recommendation | FIDO AllianceWebAuthn Level 3 Is Now a W3C Recommendation | FIDO Alliance
-
Andrew Shikiar posted thisI'm pleased to share two leadership announcements at the FIDO Alliance: 👉 Ronnie Manning joins us as Chief Marketing Officer. Ronnie spent years driving marketing and brand strategy at Yubico, where he was instrumental in building awareness for phishing-resistant authentication and passkeys well before they were mainstream. He brings that same depth of experience to FIDO as we tell the story of what comes next – digital credentials and agentic authentication. 👉 Diego Zavala moves into a full-time role as Director of Ecosystem Development, most notably leading our Digital Credentials program. Diego has been part of the FIDO team for the past year as Head of Special Projects, and previously drove passkey adoption as a Product Manager at Google. He now leads the business development, certification and enablement work that will make FIDO Wallet Certification the baseline that issuers, regulators and wallet providers build against – in addition to driving FIDO’s growing footprint in Latin America. FIDO is entering a new phase: Passkeys have reached mainstream adoption, and digital credentials and agentic authentication are the next frontier for how the world proves trust online. Ronnie will help us tell that story with the reach and clarity it necessitates; Diego will drive the ecosystem work that's already shaping how issuers, verifiers and wallet providers build trust in this next chapter. I’m thrilled to have them both on our management team and am looking forward to our work together. Please join me in welcoming them to these new roles - and be sure to come to Authenticate in October to meet with both in person!
-
Andrew Shikiar reposted thisIt's quite a feat to get 1 billion users to use passkeys, as WhatsApp did. This article has great actionable lessons that WhatsApp collected on that journey. Congratulations to the WhatsApp and Android teams! Mayank Manuja Niharika AroraAndrew Shikiar reposted thisWhatsApp upgraded to secure, seamless sign-in for 1B users with passkeys. 🔑 See how they used the Credential Manager API to: ✅ Slash login friction ✅ Add additional layers of security ✅ Unify authentication across Android Read more → https://goo.gle/4xcAAlz
-
Andrew Shikiar reposted thisAndrew Shikiar reposted thisWith identity becoming the highest targeted attack surfaces for bad actors, the time is now for organizations to move beyond debates about the future of authentication, and deploy a security upgrade that's available to them today. I’m looking forward to joining the HIP community in Nashville from 8-10 September for the Hybrid Identity Protection Conference, where my session “The Security Upgrade You Can Deploy Today” will take a practical look at how passkeys can help organizations move beyond phishable credentials and strengthen the identity layer without adding more friction for users. The FIDO Alliance community has spent years making the standards and technology viable for adoption. The next stage is helping organizations get the architecture, deployment strategy, and user experience right enough to make it work at scale. Let's explore at #HIPConf: https://lnkd.in/ggUH-vTR Hope to see you there. #UsePasskeys #IdentitySecurity #CyberSecurity #Authentication #Passkeys
-
Andrew Shikiar reposted thisAndrew Shikiar reposted thisI'm really looking forward to the Global Digital Collaboration 2026 conference in Geneva next week. GDC brings together the key stakeholders across governments, standards bodies, and open-source communities for the essential conversations that will shape the future of digital identity, digital credentials, and digital wallets. In that context, the discussions I’ll be leading at the conference along with FIDO Alliance colleagues all revolve around a theme I believe is becoming increasingly important: Trust as Infrastructure. In particular, I want to highlight these sessions on Day 2: 1) Heather Flanagan (W3C) and I will take the stage to frame this idea in our session about "Delivering the Digital Identity We Were Promised", which will explore the progress made, emerging risks, and work needed. We'll also be joined for a fireside chat by Paolo De Rosa, CTO EUDI Wallet. 2) I will be following that up alongside Elizabeth Garber (OpenID Foundation) by doing a panel on "Lessons from Around the World on Building Digital Identity that Citizens Trust" where we'll get globally diverse insights on cybersecurity, standards, governance, and public policy from the digital identity journeys of Brazil (Vinícius Silva), India (Barada Prasad Sabut), Japan (Tatsuji Shimoe), and Estonia (Joseph Carson). There are a number of other sessions we've put together with our FIDO Alliance members and partner organizations that tackle everything from digital identity and credentials to wallets, certification and agentic commerce, all aiming to grow the conversation around how we need to build the trust foundations that allow digital ecosystems to work securely across organizational and national boundaries. You can find a list of all these sessions and read more about the idea of Trust itself becoming infrastructure on my blog: https://lnkd.in/gTVVmDya Andrew Shikiar and I will also be joined by others from the FIDO Alliance team and membership on site to meet with folks and brief them on the work we're doing in advancing digital credentials, passkeys, and digital trust through our standards, enablement, and certification pillars. Hope to see many of you in Geneva for these important discussions! #GDC2026 #FIDOAlliance #TrustAsInfrastructure #DigitalCredentials #VerifiableCredentials #DigitalWallets #DigitalTrust #Collaboration #W3C #OIDF #EMVCo #ForAllByAll
-
Andrew Shikiar shared this👀 👀 !One billion people are now protected with passkeys on WhatsApp, plus more account security featuresOne billion people are now protected with passkeys on WhatsApp, plus more account security features
-
Andrew Shikiar reposted thisAndrew Shikiar reposted thisOne thing I think the identity industry gets wrong is framing passkeys and digital credentials as competing technologies. It is not passkeys or credentials. It is passkeys and credentials, because they solve different problems. A passkey answers: “Can this device prove it holds the cryptographic key registered to this account?” A digital credential answers: “What is true about this person, and who is willing to vouch for it?” Those are very different questions. Which is why a natural division of labor starts to emerge: Credentials at onboarding and verification. Passkeys at sign-in. When I create an account, there may be a legitimate reason for a service to know something about me. Am I over 18? Has a bank already verified my identity? Am I eligible for this service? A trusted digital credential can provide that information without forcing me to upload the same documents and go through the same verification process again. But once that account exists, I should not have to prove my real-world identity every time I log in. Most of the time, signing into an account should not require revealing who I am in the real world. I just need a strong, phishing-resistant way to authenticate. That is where passkeys fit extremely well. I also think recovery is an interesting part of this picture. You can build very strong authentication and then undermine the whole thing if recovery falls back to weaker mechanisms such as an emailed link or SMS code. A trusted credential could form part of a higher-assurance recovery process instead. And for higher-risk actions, the two can work together again. A passkey authenticates access to the account. Then a large payment, age-restricted purchase or regulated action might require an additional verified attribute appropriate to that specific transaction. What makes this particularly interesting is that the infrastructure is already starting to converge. The Digital Credentials API is creating a browser-mediated way for websites to request credentials from credential managers, including digital wallets. It builds on the same Credential Management API framework that WebAuthn extends. So I do not think the future looks like one technology replacing the other. It looks more like each one being used where it makes sense: Credentials to establish trusted facts. Passkeys to authenticate access. And both together when the situation requires stronger assurance.
-
Andrew Shikiar shared thisSenators Ron Wyden and Elizabeth Warren sent a letter to FINRA this week about ACATS fraud – criminals using stolen data to open a fraudulent brokerage account in your name, then quietly draining your real account into it. Their review of a dozen major U.S. firms found some banks won't let customers lock their own accounts, and some don't even alert you when your money moves. Their recommendations are straightforward: require transfer notifications, give customers the ability to lock their own accounts, and move toward phishing-resistant authentication – specifically, passkeys. Several major brokerages already support passkeys but don't require them, so the technology isn't the barrier – making it mandatory is. As evidence that mandates work, they point to Japan's Financial Services Agency, which required securities firms to mandate passkey-based authentication after a surge of account takeovers. The results back it up. Japan's FSA just reported that fraudulent trading tied to hijacked accounts fell for a fourth straight month in July, down to roughly ¥20 million and just one confirmed case – the lowest since the agency started tracking in January 2025. The U.S. financial industry tends to favor self-regulation over government mandates, which may end up being the case here as well. But either way, the playbook now exists as Japan has shown what happens when passkeys become the rule rather than the exception. https://lnkd.in/gkHZ29wmSeveral Big Brokerages Leave Customer Accounts Open to Theft, Senators SaySeveral Big Brokerages Leave Customer Accounts Open to Theft, Senators Say
-
Andrew Shikiar shared thisThere's a lot of buzz about this year's Global Digital Collaboration conference in Geneva -- and it's very well-earned. Kudos to Daniel Goldscheider, Ruth Puente and team for remarkable progress. At last year's event, I and other FIDO stakeholders used GDC to get industry feedback on our potential plans to help accelerate the digital identity ecosystem, starting with wallet certification. Fifteen months later, we've announced those plans with support from EMVCo, ISO, OIDF, and W3C, and made real progress building out the certification program - as we also initiate research and guidance on user experience. This year we've also launched initiatives in agentic authentication and agentic commerce. If you're interested in learning about any of the above, please reach out - we have a meeting room on-site where myself, Nishant Kaushik, Diego Zavala and leading FIDO contributors will be there to walk through the latest updates and insights.Andrew Shikiar shared thisMeet with FIDO’s CEO, Andrew Shikiar at the Global Digital Collaboration Conference 2026! Andrew will be scheduling 1-on-1 meetings to discuss how industry stakeholders can contribute to FIDO’s efforts in coordinating global efforts to help align and accelerate the digital credentials ecosystem – as well as updates on FIDO's expanding work in payments and Agentic AI. Don’t miss the opportunity to connect with Andrew and hear his perspective on where authentication and digital identity are headed. ➡️ Learn more https://luma.com/4du4wxqa Andrew Shikiar #GDC2026 #digitalcredentials #agenticAI #payments #authentication
-
Andrew Shikiar liked thisAndrew Shikiar liked thisISO/IEC 18013-X and 23220-X mDoc and Mobile Electronic Identity is now #free. Go to https://lnkd.in/g6nDhceH Congrats to OpenWallet Foundation, ISO - International Organization for Standardization, IEC (International Electrotechnical Commission) and the Sponsors to now provide an open standard free.
-
Andrew Shikiar liked thisSuper exciting to see Kevin Gao and the Descope team handling an important role here: many traditional identity providers and infrastructure still have gaps in their ability to shore up access for agentic systems, and this support helps not only fill those security gaps but also provide a more streamlined auth mechanism for users as well. Excited to work with y'all on the interop!Andrew Shikiar liked thisToday's a big day at Descope, and I'm super excited to share with everyone that Descope has released Cross App Access (XAA) support, for both acceptance/validation and issuance! Depending on who you are, this means two different things: 1. You're a B2B company building an MCP server. Your enterprise customers want their agents to reach your product through their own IdP. Descope validates the XAA token, whether it comes from Okta, Ping, their own instance of Descope, or something else. Their IT admin grants access once in their IdP, and none of their employees have to bother with per-user OAuth consent screens or separate credentials for your app to manage. 2. You're an enterprise governing your own internal agents. Your workforce IdP is Microsoft Entra or Google Workspace, and it doesn't issue XAA tokens. Descope issues them on your behalf. Entra or Google stay the source of truth for identity, and you get enterprise-managed agent support in Claude, VS Code, and other EMA-enabled clients right now. Thanks to Den Delimarsky and the rest of the Anthropic team for helping make sure Descope worked end to end with Claude. And to Prathmesh Patel and the rest of the MCPJam team for building a kick ass debugging tool to test the validator part with! Thanks also to everyone in the interoperability channels from Nick Steele from OpenAI, Atul Tulshibagwale from CrowdStrike, Aaron Parecki from Okta, and everyone else involved. A standard like this only matters if it works across vendors, and that takes people willing to test against each other's implementations rather than just ship their own. Here is the launch blog: https://lnkd.in/gznBMYMD And of course, I'm happy to walk through either use case with anyone who wants to see it live.
-
Andrew Shikiar liked thisAndrew Shikiar liked thisThe delegation from IDnow has arrived at #GDC2026! Happy to be at this great conference together with Leonie T. and Liudmyla (Mila) Rabchynska. Make sure to visit the sessions where we will be presenting: Using the EUDI Wallet for consumer banking and payments, September 3, 10.00-10.50 CEST, room Alpha. The backbone of the EUDIW ecosystem, September 3, 16.00-16.50 CEST, room Alpha. Trust infrastructure for the EUDI Wallet, September 3, 17.00-17.50 CEST, room Alpha. Else we will be happy to meet and greet with you during coffeebreaks, lunches and dinners!
-
Andrew Shikiar liked thisAndrew Shikiar liked thisCongratulations to the California DMV team on Most Innovative Use of Technology award at Government Technology Summit 2026 with the world class innovation of Instant Identity Card designed for disaster victims and unhoused Californians
-
Andrew Shikiar liked thisAndrew Shikiar liked thisWe’re proud to share that SIROS ID has been selected as a finalist for the Best Wallet Award 2026 in the Global Digital Trust Awards! SIROS ID is a fully open-source, community-developed wallet, so this is a great acknowledgement community's work. SIROS ID is a finalist alongside Google, France Identité, Unique Identification Authority of India (UIDAI) and the Swiss federal state's SWIYU Wallet. The winner will be announced at Global Digital Collaboration in Geneva. Public voting is now open until 2 September at 23:59 CET, and the community vote accounts for 50% of the final result. If you want to vote for SIROS in the Best Wallet Award please follow the link: https://lnkd.in/eZWA3Tkw
-
Andrew Shikiar liked thisAndrew Shikiar liked thisIt was so great being joined by 100+ customers and industry leaders in San Francisco last night to cheers the news about Socure's acquisition of Fravity AI, alongside a strategic growth investment at a $5.2 billion valuation led by Summit Partners. For me, the reasoning behind it is something I learned a long way from a boardroom. When I served on multiple combat deployments with the 75th Ranger Regiment, U.S. Army, we faced a decentralized and networked enemy with fewer people, less resources, and worse equipment yet they were still effective. They could see something, decide, and act before we finished routing a decision up the chain and back down. The answer was never more people. It was a shorter loop. Fraud is the same fight. Attack networks operate at machine speed. AI-driven attacks are up 8,000% in a year across our network of 3000+ customers. And 53% of organizations still spend an hour or more on a single alert. That is not a staffing gap. It's a decision velocity gap, and nobody hires their way across one. Fravity ships inside RiskOS as RiskOS_Agents. In existing deployments: resolution up to 5x faster, cost per case down 80%, false positives down as much as 70%. Routine alerts clear. Your best investigators work the ones that need judgment. Push the decision to the edge. That's the doctrine, and it's the only thing that works against a faster adversary. Welcome Kedar Samant, Rushik Upadhyay, and the entire Fravity team. Cheers!
Experience & Education
-
FIDO Alliance
***** ********* *******
-
**** ********
******* ******* * ********
-
*******
********* *******
View Andrew’s full experience
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
Welcome back
By clicking Continue to join or sign in, you agree to LinkedIn’s User Agreement, Privacy Policy, and Cookie Policy.
New to LinkedIn? Join now
Publications
-
Passwordless Authentication: The next breakthrough in secure digital transformation
World Economic Forum
See publicationCybercrime is set to cost the global economy $2.9 million every minute in 2020 and some 80% of these attacks are password-related. Knowledge-based authentication – whether with PINs, passwords, passphrases, or whatever we need to remember – is not only a major headache for users, it is costly to maintain. For larger businesses, it is estimated that nearly 50% of IT help desk costs are allocated to password resets, with average annual spend for companies now at over $1 million for staffing…
Cybercrime is set to cost the global economy $2.9 million every minute in 2020 and some 80% of these attacks are password-related. Knowledge-based authentication – whether with PINs, passwords, passphrases, or whatever we need to remember – is not only a major headache for users, it is costly to maintain. For larger businesses, it is estimated that nearly 50% of IT help desk costs are allocated to password resets, with average annual spend for companies now at over $1 million for staffing alone.
Passwordless authentication does not mean removing all security barriers to our digitalized society. It means harnessing technologies such as artificial intelligence and machine learning to save users time and save company-money.
This paper sheds light on the importance of authentication in digital transformation efforts, introduces a framework for future authentication systems and presents five key passwordless technologies available for use. -
BigML "Predictive Model of the Week" Blog Posts
See publicationVarious posts by myself and BigML colleagues leveraging open data to draw predictive insights and analyses.
Recommendations received
7 people have recommended Andrew
Join now to viewView Andrew’s full profile
-
See who you know in common
-
Get introduced
-
Contact Andrew directly
Other similar profiles
-
Jeffrey Schmitz
Jeffrey Schmitz
C level executive with 35+ year track record of contributing to high growth technology companies from venture backed startups to large public companies. Offers a unique perspective, having served as an Executive Leader in a variety of functions including General Manager, Chief Marketing Officer, and Chief People Officer across a wide span of industries including communications, retail, transportation and logistics, manufacturing, and healthcare.<br><br>Open to private or public board opportunities<br><br>Key Skills include:<br>• P&L Management<br>• Go to Market Strategy<br>• Mergers and Acquisitions<br>• CEO Succession
11K followersOkatie, SC -
Amanda St L Jobbins
Amanda St L Jobbins
Global technology executive | NED | Keynote speaker | Top 100 Marketer | Cranfield FTSE Top 100 Women in Business
9K followersUnited Kingdom
Explore more posts
-
Dr. Tyrone Moodley
Southernsoft Technologies • 6K followers
React2Shell Exploitation Escalates into Large-Scale Global Attacks, Forcing Emergency Mitigation The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has urged federal agencies to patch the recent React2Shell vulnerability by December 12, 2025, amid reports of widespread exploitation. The critical vulnerability, tracked as CVE-2025-55182 (CVSS score: 10.0), affects the React Server Components (RSC) Flight protocol. The underlying cause of the issue is an unsafe deserialization that allows an attacker to inject malicious logic that the server executes in a privileged context. It also affects other frameworks, including Next.js, Waku, Vite, React Router, and RedwoodSDK. "A single, specially crafted HTTP request is sufficient; there is no authentication requirement, user interaction, or elevated permissions involved," Cloudforce One, Cloudflare's threat intelligence team, said. "Once successful, the attacker can execute arbitrary, privileged JavaScript on the affected server." https://lnkd.in/e4N74-af
5
1 Comment -
Conor Coughlan
DNSFilter • 9K followers
(( Breaking News )) 🚨 Today, we shared how Armis worked with Copeland to address 10 newly discovered vulnerabilities impacting mission-critical equipment 🚨 Discovered by Armis Labs and collectively named “Frostbyte10���, these vulnerabilities were found in Copeland’s widely used E2 and E3 controllers. Deployed across many global enterprises, these devices are essential for managing HVAC, BMS and commercial refrigeration systems in industries including food retail, pharmaceuticals, and cold chain logistics. By prioritizing responsible disclosure, a transparent process, and early warnings to the community, together we turned a potential threat into an opportunity for stronger, safer systems. Our thanks to Copeland for the collaboration. Today's disclosure is a reminder of the risk embedded in legacy systems that were never designed with modern #CyberThreats in mind. 🔗 Read more in our blog: https://lnkd.in/eZiM6R44 #CPS #Collaboration #Vulnerabilities #OTSecurity #VulnerabilityManagement #CriticalInfrastructure
38
1 Comment -
Glen Stradwick
KiwiPoS • 51 followers
Keeping the momentum rolling for LOKRA Asset Solutions... AegisTrace is more than a tool tracker. We are building the infrastructure for public asset accountability. Consider the unattended laundromat. If a washing machine breaks at 10 PM on a Tuesday, the owner might not find out until they visit the site days later. With a LOKRA tag attached, the customer becomes the sensor. They scan a customized tag with a label that reads "Not working? Scan this tag!", report the fault and the owner is notified in seconds. This allows a small business to maintain a professional service standard without needing a physical presence on site at all times. Portable sanitation is another high stakes use case. Portaloos on construction sites or at major events require strict servicing schedules to remain compliant with health and safety standards. Any worker or attendee can scan the registry tag to request a cleaning or report damage. This provides the asset owner with a live map of where their attention is needed most and creates a verifiable log of when the request was made and when it was resolved. Viable usage even exists for life saving equipment like public access defibrillators. These units often sit in cabinets for weeks or even months without interaction. If a battery dies or the pads expire, the unit becomes useless in an emergency. By tagging these assets, anyone can scan the QR code to verify that the maintenance is up to date. The public record shows a "last maintained" field and allows the user to alert the recorded contact if the unit appears tampered with. This moves the responsibility from a hidden spreadsheet to a public safety ledger. If a unit has not been serviced within a calibrated timeframe, the owner or delegated service agent will receive a reminder both by email and in their portal. This is the power of a forensic digital twin. It turns static objects into active nodes in a governance network. The engine is live and the hardware is ready. We are currently funding our first industrial production run on Kickstarter. Join the standard for physical asset governance today. Campaign Link: http://kck.st/4bXMfOa #AssetSecurity #DigitalTracking #AssetSafety #ChainOfCustody #BurdenOfProof #LOKRA #AegisTrace
1
-
Timothy Cradle
Cradle Crown Holdings ·… • 338 followers
Execution governance isn’t new. Access control, IAM, policy engines, and runtime enforcement have existed for decades. What may be shifting is the framing. Instead of treating governance as documentation or post-incident review, what happens if we treat it as a structural execution invariant? Mandate declared. Scope bound. Refusal by default. Allow/deny recorded as a first-class artifact. This is part of an ongoing research effort exploring execution-layer governance models in bounded environments. I’ll share a minimal runtime demonstration of this approach in the coming days.
1
2 Comments
Explore top content on LinkedIn
Find curated posts and insights for relevant topics all in one place.
View top content