惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

Google DeepMind News
Google DeepMind News
人人都是产品经理
人人都是产品经理
S
Securelist
P
Proofpoint News Feed
H
Help Net Security
S
Schneier on Security
T
Tenable Blog
C
Cisco Blogs
S
Security @ Cisco Blogs
博客园 - 司徒正美
博客园 - 叶小钗
Cisco Talos Blog
Cisco Talos Blog
Google DeepMind News
Google DeepMind News
C
Cybersecurity and Infrastructure Security Agency CISA
Google Online Security Blog
Google Online Security Blog
Exploit-DB.com RSS Feed
Exploit-DB.com RSS Feed
Hacker News: Ask HN
Hacker News: Ask HN
NISL@THU
NISL@THU
云风的 BLOG
云风的 BLOG
V
Vulnerabilities – Threatpost
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
W
WeLiveSecurity
www.infosecurity-magazine.com
www.infosecurity-magazine.com
Jina AI
Jina AI
腾讯CDC
WordPress大学
WordPress大学
Simon Willison's Weblog
Simon Willison's Weblog
Vercel News
Vercel News
小众软件
小众软件
N
Netflix TechBlog - Medium
有赞技术团队
有赞技术团队
AWS News Blog
AWS News Blog
雷峰网
雷峰网
Forbes - Security
Forbes - Security
The Hacker News
The Hacker News
博客园 - 聂微东
F
Full Disclosure
量子位
Scott Helme
Scott Helme
宝玉的分享
宝玉的分享
A
About on SuperTechFans
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
Schneier on Security
Schneier on Security
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
K
Kaspersky official blog
AI
AI
SecWiki News
SecWiki News
Webroot Blog
Webroot Blog
Martin Fowler
Martin Fowler

Yubico

RIP SMS: Microsoft transitioning to passkeys as default authentication method for Entra ID OpenAI mandates hardware-backed passkeys for Trusted Access Cyber members to log into ChatGPT accounts Works with YubiKey Spotlight: Translating YubiKey logistics into enterprise cyber resilience with EgoMind’s Appterix Google Play Services adds support for NFC-enabled FIDO2 security keys: How Yubico makes Android passkey authentication seamless Post-quantum cryptography is now a federal mandate: Here’s what it means and what your agency should do now Salesforce enforces MFA for all employee logins: Here’s what you need to know Secure it Forward Spotlight: Cyber defenders as a force for resilience New Executive Order on AI: Identity as a critical foundation for trusted AI YubiKey 5 FIPS Series and YubiHSM 2 FIPS are now FIPS 140-3 validated: What it means for high assurance security Secure It Forward Spotlight: Securing independent journalism with Radio Free Europe / Radio Liberty The passkey spectrum: Importance of user choice in digital security journeys OpenAI’s Advanced Account Security program: Top 5 things Codex users need to know New to OpenAI’s Advanced Account Security program? Here’s how to add your YubiKey to ChatGPT accounts Leading Yubico forward: Q1 reflections and securing the AI frontier Building a safer AI journey: How to add your YubiKey to ChatGPT accounts OpenAI partners with Yubico: What it means for the future of AI-based workflows and the role of the human Works with YubiKey Spotlight: Securing the AI frontier and high-assurance infrastructure Yubico’s commitment to securing the future of digital identities: Reflecting on RSAC 2026 YubiKey as a Service expands to Ping Identity with pre-configured security keys Securing agentic AI: Why automation still needs human oversight Yubico officially lands in Singapore: Opening our third global headquarters Welcome to YubiNation Partners: Reimagining the Future of Channel Partnership to Secure Identity at Scale Yubico’s Clifton Slater recognized as a CRN 2026 Channel Chief Leading Yubico into the Future: 2025 Reflections and Our 2026 Roadmap Fireside chat: Meet Yubico’s new acting CEO, Jerrod Chong Yubico will introduce secure and privacy capable passkey enabled digital signatures in upcoming 5.8 firmware The 265% ROI of phishing resistance with Yubico: Why modern enterprises are ditching legacy MFA for YubiKeys
Beyond the login: Top 3 things developers need to know about YubiKey 5.8
Mario Bodemann · 2026-07-21 · via Yubico

With today’s launch of the YubiKey 5.8, we’re excited to continue efforts toward shifting passkeys from a mechanism for trusted authentication into a standard for verifiable, digital authorization. For organizations and developers, YubiKey 5.8 now expands the role of identity from simply verifying who a user is to authorizing what they can do with verified human intent. YubiKey 5.8 is now shipping across all major YubiKey product lineups starting today, except the FIPS Series and CCN Series (currently undergoing final re-certification).

Hardware-backed passkeys have transformed how the industry approaches identity verification, offering an unprecedented line of defense against modern phishing vectors. Whether signing documents, approving agent-driven actions, confirming medical treatments, or authorizing critical workflows, YubiKey 5.8 enables high-assurance digital actions anchored in hardware-backed passkey trust.

Here, we’ll detail the top three things developers need to know about the YubiKey 5.8 so that you can begin building passkey-native apps today. Don’t miss our webinar today, July 21 at 9am PT, “Beyond the Login: Securing Trusted Actions and AI Workflows with Passkeys” – register here or watch on-demand.

1. Hardware-backed digital signatures through preview APIs

Historically, implementing high-assurance digital signatures required spinning up complex, expensive backend Hardware Security Modules (HSMs) or custom Public Key Infrastructures (PKIs). YubiKey 5.8 introduces full support for FIDO CTAP 2.3 alongside a developer preview for emerging WebAuthn signing extension – allowing developers to request cryptographic digital signatures from a hardware security key using the open-standard WebAuthn extension patterns you already use for your login workflows. 

This directly opens up a an exciting new area of use cases, including:

  • Agentic AI safeguards: Binding an automated AI workflow’s high-risk decisions (like altering production database schemas) to a mandatory human-in-the-loop physical touch.
  • Decentralized identity: Serve as the secure root-of-trust for digital identity wallets, verifiable credentials, and Secure Payment Confirmation (SPC).
2. Privacy-preserving cryptography (ARKG preview)

We know that user privacy is a non-negotiable architectural requirement for next-generation apps. A common roadblock with digital signing tracking is that public keys can accidentally be used by third-party verifiers to collude and track users across separate digital sessions.

To solve this, YubiKey 5.8 introduces a developer preview of Asynchronous Remote Key Generation (ARKG) extension. ARKG allows the security key to dynamically generate unique, public keys for distinct workflows. Verifiers can cryptographically confirm the validity of the signature and the hardware origin without ever being able to link or track the user across separate platform interactions. This makes it possible to support emerging initiatives such as digital wallets and payments.  

3. Streamlined UX and frictionless credential discovery

Hardware-backed passkeys are incredibly secure, but historically they’ve had a visibility problem in the browser compared to native software credentials. YubiKey 5.8 implements the latest CTAP 2.3 UX enhancements, including Persistent PIN/User Verification Auth Token (PPUAT) protocol feature. This mechanism allows applications to discover discoverable credentials stored on the hardware key smoothly and intuitively.

For the end user, this translates to a streamlined, autofill-like passkey experience inside native apps. Users can leverage system autofill dropdowns to select their security key credentials instantly, significantly minimizing redundant, repetitive PIN prompt bottlenecks throughout a multi-application workspace session.

Working together to secure and build for AI-era workflows

Yubico is committed to empowering the developers and engineers with the best security tools, and receiving critical feedback from the community. To kickstart development, Yubico will be hosting the YubiKey 5.8 Virtual Hackathon on August 5, 2026.

Accepted developers receive a YubiKey 5C NFC with custom laser-marked “HACKATHON 5.8” to prototype experimental code across trusted AI workflows, digital wallets, secure payments, and more. Join our developer community to learn more about future hackathons and engage with the Yubico Developer Relations team here.

For more information on YubiKey 5.8 visit the press release or the official YubiKey 5.8 page here. You can also check out our quickstart guides and open-source packages over at the Yubico Developer Portal.