Why phishing defeats many sign-in methods
A phishing attack tricks a user. The user then types a secret into a fake site. The attacker replays the secret on the real site.
Many methods still use a shared secret. This gap makes a phishing attack possible.
- OTP codes: a user can type them into a fake site.
- Push approvals: a user can approve a fake prompt.
- SMS codes: an attacker can intercept or redirect them.
- Passwords: an attacker can steal and reuse them.
How SenseCrypt resists phishing
SenseCrypt is a passwordless identity provider (IdP). It asks for no password and no shared code at sign-in. So a phishing page has nothing to capture or replay. The proof is a live face plus a device-bound signature.
A user signs in by face. Face matching runs on-device. The sign-in binds to the device. This binding makes the sign-in phishing-resistant.
- No password to steal or phish
- No shared code to read and replay
- A live face and a device-bound signature prove the user
- The sign-in binds to the user device
How the face login stays strong
A face login must reject a fake face. SenseCrypt uses liveness detection for this task. Its liveness detection holds iBeta ISO 30107-3 certification. This certification covers Level 1 and Level 2.
SenseCrypt also protects the face itself. It uses patent-pending face tokenization. A face becomes a single-use face token. SenseCrypt stores no biometric data on the server.
- Liveness detection rejects a photo, a video, or a mask.
- iBeta ISO 30107-3 certification covers Level 1 and Level 2.
- Face tokenization turns a face into a single-use face token.
- SenseCrypt stores no biometric data on the server.
The outcome
Phishing-resistant authentication closes a common attack path. An attacker has no secret to steal or replay.
A user signs in fast by face. Your apps gain a strong, simple sign-in. Your team lowers the risk from phishing.
- No shared secret for an attacker to steal
- A fast, simple sign-in for the user
- A strong defense for every connected app
- Clear audit logs for each sign-in
Who it fits
Phishing-resistant authentication fits any team that faces phishing. It suits customer identity (CIAM), workforce SSO, and B2B SaaS SSO.
SenseCrypt costs one dollar per user per month, flat. A 30-day free trial needs no card.
- Customer identity (CIAM) for external users
- Workforce single sign-on (SSO) for staff
- B2B SaaS SSO for business customers
Frequently asked questions
What is phishing-resistant authentication?
Phishing-resistant authentication is a sign-in method that a phishing attack cannot defeat. It uses no shared secret. So there is no code for an attacker to steal.
Is OTP phishing-resistant?
No. A user can type a one-time password (OTP) into a fake site. An attacker can then replay it. A SenseCrypt sign-in uses no OTP.
How does SenseCrypt resist phishing?
A SenseCrypt sign-in asks for no password and no shared code. A user signs in by face on-device. The sign-in binds to the device.
Does SenseCrypt hold a security certification?
Yes. Its liveness detection holds iBeta ISO 30107-3 certification. This certification covers Level 1 and Level 2.
Related