Andrew Shikiar
- Leads the FIDO Alliance, the consortium behind FIDO2 and passkeys
- Drove the cross-platform passkey launch with Apple, Google, and Microsoft
- Previously led market development for Liberty Alliance and other consortia
Bio
Andrew Shikiar is executive director and CEO of the FIDO Alliance, the consortium whose specifications became WebAuthn and FIDO2 and, in consumer form, passkeys. He previously led market development for the Tizen Association, LiMo Foundation, and the Liberty Alliance Project.
Profile built from public consortium and press records.
Where their work shows up
The specification was the easy half. Passkeys only mattered once Apple, Google, and Microsoft agreed to sync them across their platforms and use the same name for them, and that is consortium work: getting competitors to ship a compatible thing on a compatible timeline. It is the clearest recent example of why industry bodies exist. See implementing passkeys in the enterprise, the best phishing-resistant MFA ranking, and the Authenticate conference.
Related on Start with Identity
- Blog94 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-univ
- BlogAmazon says 175 million customers now sign in with passkeys
Amazon reports more than 175 million customers have enabled passkeys, signing in six times faster, with passkeys now the default on mobile for anyone who has se
- BlogBlack Hat USA 2026 recap: passkeys get broken (twice), and AI agents get an identity perimeter
Our identity takeaways from Black Hat USA 2026: two independent passkey implementation attacks, a wave of AI agent identity and governance launches, an open sou
- GlossaryPasskey
A passkey is a WebAuthn public-key credential that replaces a password. Possession of the authenticator plus a user verification step proves identity, with no s
- GlossaryPhishing-Resistant MFA
Multi-factor methods that cannot be relayed or replayed by a phishing site, principally FIDO2 security keys and passkeys. Recommended by NIST and CISA over OTP
- GlossaryWebAuthn
A W3C standard browser API for public-key authentication. WebAuthn is the protocol used by passkeys and FIDO2 security keys. The relying party server stores the