Dreamforce 2016 – FIDO U2F YubiKey Log In to Salesforce

October 4, 2016 3 minute read
Salesforce logo with YubiKey registration screen

Momentum is the motion of a moving body, measured as a product of its mass and velocity. Today, we see the mass and velocity of the world’s largest cloud ecosystem get behind FIDO Universal 2nd Factor (U2F) strong authentication.

At this week’s Dreamforce 2016, conference attendees will get the first look at new native support of U2F in the Salesforce Winter ’17 release. Once enabled by an organization’s Salesforce administrator, end users can authenticate with any YubiKey that supports U2F to securely log in to their Salesforce accounts with superior security and unmatched simplicity. Furthermore, that same YubiKey can be used to authenticate to the ever-growing list of services that support U2F.

After a Salesforce user registers their YubiKey with their account, they log on as usual with their username and password. But before they are granted access, they are prompted to insert their YubiKey into their computer’s USB port and touch the device’s button. This  completes a strong authentication based on public key cryptography, that thwarts phishing and man-in-the-middle attacks that plague other solutions such as one-time codes sent via SMS.

Users can register both a YubiKey and the Salesforce Phone App with their Salesforce account so they always have a backup authenticator. If their phone is dead a user can use their YubiKey. Or if they don’t have their YubiKey, they can use the phone app.

To learn more about U2F, YubiKey, and the Salesforce integration, sign up to attend a joint webinar hosted by Yubico and Salesforce on Oct. 20 (sign up here!). Together, we will demonstrate how easy it is to activate U2F on the Salesforce platform. We will also dive into the growing importance of the FIDO Alliance protocol, and discuss the cost savings achieved with YubiKey as a second factor for authentication.

Salesforce’s U2F integration comes on the heels of more than a dozen online services that have made support for U2F beginning with Google, Github, Dropbox, and most recently Okta, Gitlab, Dashlane, and Bitbucket. As we read daily about new password and data breaches, companies are moving to strong, open authentication built on U2F. Google tracked the authentication habits of 50,000 employees using U2F within the company over a two-year period. The results showed that compared against Google’s own authenticator phone app, U2F was faster, more secure, and reduced support costs by thousands of hours per year.

We hope to see you in San Francisco. Stop by our Dreamforce Booth #345 in Moscone South Hall. We are demoing the YubiKey with Salesforce Winter ’17, along with other slick U2F-based services.

Share this article:

Recommended content

Accounting for the human element: A security tool that nobody wants to use is destined for the trash heap

To continue our effort to peel back the layers on the journey to passwordless, Yubico talked with former Navy intelligence officer and University of Tulsa professor, Sal Aurigemma, about his research in the behavioral information security field. Professor Aurigemma focuses on end-user experiences and adoption rates of authentication technologies. He regularly runs field experiments with ...

Cloud vs. On-Prem: Why opting for on-prem can cost you your next data breach

Most CISOs and IT teams spend their time asking themselves “when”, not “if”, they will be the next company to suffer a data breach. And rightfully so. The frequency of data breaches is skyrocketing, with no sign of slowing down.  To help quantify the problem, recent research from Canalys shows that there were more records ...

Find us at Oktane21 and discover how Okta and the YubiKey bridge enterprises to passwordless

Okta’s premier identity conference, Oktane21, is taking place virtually on April 6-8, and Yubico is once again a proud sponsor. This year, Yubico will highlight our continued partnership with Okta and showcase the YubiKey as the key to trust.  Okta Adaptive MFA and the phishing-resistant YubiKey allow organizations to quickly and securely deploy strong multi-factor ...

Yubico announces general availability of next-generation Android and iOS SDKs

Yubico is committed to enabling YubiKey integrations for all of our technology partners and enterprise customers with the least amount of friction and time-to-market as possible. With this goal in mind, we are very excited to announce the public general availability of our Android and iOS SDKs that went into public beta in December last ...