By NHI Mgmt Group Editorial TeamBased on 1Kosmos: “1Kosmos, CodeCluster, and Arculus Partner to Reduce Fraud” (March 27, 2023)

TL;DR: Passwordless authentication using a secure card and mobile device removes exposed passwords from the login path, reducing account takeover and shared-secret risk, according to 1Kosmos. The broader lesson is that identity programmes should treat phishing-resistant, card-present verification as a control pattern, not just a user experience improvement.


At a glance

What this is: This is a discussion of passwordless, card-based authentication that binds a verified user to a secure payment card and uses a tap on a mobile device to complete login.

Why it matters: It matters because IAM teams evaluating phishing-resistant authentication need controls that remove reusable secrets, reduce account takeover risk, and fit real user workflows.


Context

Passwordless authentication replaces shared secrets with a stronger factor that is harder to steal, reuse, or phish. In this case, the focus is a card-present flow where a mobile device and secure card complete the login or approval step after identity enrollment.

For IAM programmes, the governance question is not whether the user experience is simpler. It is whether the authentication method materially reduces account takeover risk by removing passwords from the access path and binding the credential to the person in possession of the card.

The article frames the card tap as a practical way to reduce fraud in environments where stolen usernames and passwords remain a common entry point. That makes this a human identity control pattern, not just a consumer convenience feature.


Key questions

Q: What breaks when users still depend on passwords for frequent logins and resets?

A: When passwords remain the primary access method, the most obvious breakdown is repeated user friction. People forget credentials, reset them, and spend extra time on account setup and recovery. That pattern also increases support burden and makes authentication feel like a recurring task rather than a quick control, which is why passwordless designs are often adopted first for high-friction user journeys.

Q: Why do phishing-resistant methods reduce account takeover risk?

A: Phishing-resistant methods reduce takeover risk because they rely on cryptographic proof instead of reusable secrets or user-entered codes. A fake login page cannot steal a private key or replay a device-bound signature, so the attacker loses the simplest path from deception to impersonation.

Q: How can IAM teams tell whether a passwordless programme is actually working?

A: Look for completion rates, exception volumes, support calls, and the frequency of policy bypass behaviour. A healthy programme should reduce friction without increasing workaround activity. If users still need IT to issue or reissue credentials routinely, the operating model is not mature enough.

Q: When does card-based authentication make more sense than shared-secret login?

A: It makes sense when the main threat is account takeover through credential theft and when the user population can support possession-based verification. High-risk roles, regulated workflows, and remote access paths usually benefit first.


Technical breakdown

How card-present authentication replaces reusable passwords

Card-present authentication shifts the login ceremony away from shared secrets and toward possession of a cryptographic or device-bound factor. The user does not type a password that can be phished, logged, or reused. Instead, the mobile app receives approval when the secure card is tapped, which ties the event to a physical credential in the user's control. Identity enrollment matters because the card must be bound to a verified identity before authentication can be trusted. This is why the control is stronger than a simple password reset or OTP flow: the attacker needs both a valid enrolment path and the physical factor at runtime.

Practical implication: Treat card-present authentication as an access control design, not a user convenience layer.

Why passwordless flows reduce account takeover exposure

Account takeover succeeds when an attacker can replay or steal something that the system accepts as proof of identity. Passwords are especially exposed because they are reusable, transferable, and often captured through phishing, malware, or credential stuffing. A passwordless flow reduces that risk by eliminating the shared secret from the login path and narrowing the value of intercepted credentials. It does not remove the need for identity proofing or lifecycle governance, but it does lower the probability that a stolen string alone will unlock an account. The security gain comes from removing the most portable attacker asset, not from making authentication merely more modern.

Practical implication: Prioritise passwordless where the main threat is credential theft and reuse.

How identity enrollment supports high-assurance authentication

Identity enrollment is the step that establishes who the credential belongs to before authentication begins. In this flow, the vendor describes matching a user's face to government credentials and verifying credential integrity before issuing or binding the card-based authenticator. That matters because passwordless systems still fail if enrolment is weak, disputed, or easily spoofed. The assurance target is not just login security, but enrolment integrity plus authentication strength. In IAM terms, this is where identity proofing, credential binding, and authentication assurance meet. Without that front-end trust, even a strong factor can be anchored to the wrong person.

Practical implication: Review enrolment assurance before treating any passwordless factor as phishing-resistant.


Threat narrative

Attacker objective: The attacker aims to impersonate a legitimate user and gain unauthorized access without needing the physical card or mobile approval step.

  1. Entry occurs when an attacker obtains usernames and passwords through phishing, logging, theft, or other credential compromise.
  2. Escalation follows when those reusable secrets are accepted by the target system and used to impersonate the user.
  3. Impact occurs as the attacker completes account takeover, enabling fraudulent access or abuse of the victim account.

NHI Mgmt Group analysis

Shared-secret authentication remains the weakest link in many human identity programmes: Passwords are still portable, phishable, and replayable, which makes account takeover a credential problem before it becomes a security operations problem. A tap-based, card-present flow removes the reusable secret from the path and changes the attacker equation. The implication for IAM teams is that authentication design should be judged by how much credential portability it leaves behind.

Identity assurance does not start at login, it starts at enrolment: The article's workflow depends on matching the user to government credentials and verifying credential integrity before the card is accepted as an authenticator. That means weak proofing at enrolment can undermine even strong passwordless controls. Practitioners should treat enrolment governance as part of the authentication control plane, not as a separate administrative step.

Phishing resistance is only durable when the factor is bound to the person and the device or card they physically possess: This card-present model reduces the chance that a stolen username and password can be reused elsewhere. It does not eliminate governance needs around issuance, revocation, or loss handling, but it changes the dominant failure mode from secret theft to possession control. For identity teams, that is a materially better baseline than shared-secret login.

Passwordless is an access pattern, not a cosmetic upgrade: The operational value here is not convenience alone, but the removal of a high-reuse credential class from the environment. That makes authentication policy, enrolment checks, and device or card binding part of the same governance decision. Teams should evaluate passwordless programmes by the reduction in recoverable attack paths, not by adoption optics.

Card-based authentication sharpens the boundary between human IAM and NHI governance: Humans still need enrolment assurance, possession factors, and recovery workflows that reflect personhood, while machine identities need lifecycle and secret governance. The important lesson is that identity security improves when each actor type is authenticated through controls that match its actual behaviour. Practitioners should avoid one-size-fits-all authentication design.

From our research library:

What this signals

Passwordless controls only change risk when they remove the reusable secret: IAM teams should not treat a nicer login flow as a governance outcome. The meaningful shift is that authentication no longer depends on a password that can be copied, replayed, or harvested.

Identity proofing and authentication must be governed together: If enrolment is weak, a strong factor can still be issued to the wrong person. That makes proofing, card binding, and recovery part of the same operating model rather than separate tasks.


For practitioners

  • Prioritise passwordless for high-risk user populations Use card-based or other phishing-resistant authentication first for administrators, finance users, and remote access paths where account takeover has outsized impact.
  • Bind enrolment to verified identity proofing Require strong identity proofing before issuing or linking a physical authenticator so the card is anchored to the right person from day one.
  • Design for lost-card and recovery governance Define how access is suspended, reissued, or re-verified when a card is lost, replaced, or suspected of compromise, and test that flow before rollout.
  • Measure reduction in reusable-secret exposure Track how many users still rely on passwords, OTP fallback, or shared secrets after deployment so the programme proves real risk reduction rather than cosmetic change.

Key takeaways

  • Passwords remain a high-risk authentication mechanism because they can be stolen, replayed, and used for account takeover.
  • The article's core evidence is a card-tap flow that ties authentication to possession and verified enrolment instead of a reusable secret.
  • IAM teams should treat passwordless adoption as a governance decision that depends on proofing, recovery, and fallback control.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

MITRE ATT&CK addresses the attack and risk surface, while NIST SP 800-63, NIST CSF 2.0 and OWASP ASVS set the governance and control requirements practitioners need to meet.

FrameworkControl / ReferenceRelevance
NIST SP 800-63SP 800-63B — AuthenticationThe article is about stronger human authentication that reduces reliance on passwords.
SP 800-63A — Enrollment and Identity ProofingThe flow depends on verifying identity before binding the card authenticator.
Recommendation — Adopt phishing-resistant authentication methods and reduce dependence on reusable secrets. Strengthen identity proofing before issuing or binding passwordless authenticators.
NIST CSF 2.0PR.AA-05 — Access Permissions, Entitlements and AuthorizationsThe control outcome is better authenticated access decisions for human identities.
Recommendation — Align authentication policy with access decisions that minimize account takeover risk.
OWASP ASVSV6 — AuthenticationThe post concerns authentication assurance and replacement of password-based login.
Recommendation — Use strong authentication requirements that remove reusable secrets from the login path.
MITRE ATT&CKTA0006 — Credential AccessThe article's threat model is credential theft leading to account takeover.
Recommendation — Map password theft and replay risk to credential access and prioritise phishing-resistant controls.

Key terms

  • Passwordless Authentication: An authentication approach that removes passwords and uses a device-bound cryptographic key plus local user verification. It reduces phishing and replay risk, but it only improves assurance when enrollment, recovery, and revocation are tightly governed.
  • Identity Enrollment: The process of proving who a person is before issuing or binding an authentication factor or account to them. It is a governance control as much as a technical step, because weak proofing can make a secure login method validate the wrong person more reliably.
  • Phishing-Resistant Authentication: Phishing-resistant authentication proves identity without relying on a user to approve a prompt or reveal a reusable secret. It typically binds access to a device, key, or cryptographic proof that an attacker cannot easily reuse or coerce. This approach reduces reliance on human judgment at login time.
  • Card-Present Authentication: A login or approval flow that requires a physical card to be present at the time of authentication. The control shifts security from knowledge of a secret to possession of a governed authenticator, which changes the attacker's path from remote theft to harder physical compromise.

Deepen your knowledge

NHI governance, agentic AI identity, and machine identity lifecycle are core topics in our NHI Foundation Level course, the industry's only accredited NHI security programme. If you are building or maturing an IAM programme, it is worth exploring.
NHIMG Editorial Note
Published by the NHIMG editorial team on June 23, 2026.
Updated on October 11, 2026.
NHI Mgmt Group, the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org