Phishing-Resistant Authentication
PCIComplianceHubLast updated
Authentication that cannot be defeated by tricking a user into handing over a credential or approving a prompt, because the factor is cryptographically bound to the legitimate site or device. FIDO2 security keys, passkeys and certificate-based authentication are phishing-resistant. SMS codes, one-time passwords and push approvals are not, because a user can be induced to relay or approve them. PCI DSS Requirement 8.5.1 requires multi-factor authentication systems to resist replay attacks, and PCI SSC guidance points to phishing-resistant factors as the stronger option.
In PCI DSS v4.0.1. 8.5.1