Slide 1

Slide 1 text

Securing Your WordPress Site with Modern Authentication and Beyond [email protected] (2023/11/18) WordCamp Hong Kong 2023

Slide 2

Slide 2 text

No content

Slide 3

Slide 3 text

You Need More Security Than You Think

Slide 4

Slide 4 text

Default Wordpress User Management

Slide 5

Slide 5 text

Single Sign-On Everything in One-Click Passwordless login B2B Authentication Multi-Factor Authentication Breached Password Detection Zero trust architecture

Slide 6

Slide 6 text

Auth Demo And Setup Demo

Slide 7

Slide 7 text

Bad conversion rate for sign up Do you know… according to Andrew Chen (Growth Uber, a16z): 1. 78% of users forgot their password and had to reset it 2. User forgot if they’ve sign up, the confusion reduce sign up conversions Switch to Email + Magic Link, and update the UI to optimize, takes weeks. Optimize Signup Conversion 78% of users forgot their password and had to reset it

Slide 8

Slide 8 text

Security for Scale Audit Logs, Brute force Protection, SMS Rate Limits 2FA Introducing two-factor authentication for security policies Re-Auth for Critical Transactions Integrations Integrate signup with analytics, CDP, drip campaigns 1 2 3 4 Essential Enhancements Additional layer of security

Slide 9

Slide 9 text

Integrate with OIDC client 🤖 ● Effectively 2 Authentications ● Authgear cannot control session/auth state between user and the ODIC client

Slide 10

Slide 10 text

Integrate with OIDC client 🤖 ● Effectively 2 Authentications ● Authgear cannot control session/auth state between user and the ODIC client Authenticated Authenticated

Slide 11

Slide 11 text

FIDO, FIDO2, Webauth, Passkeys FIDO Alliance ("Fast IDentity Online")

Slide 12

Slide 12 text

Thank You! ● Contact ○ [email protected] ● Authgear References ○ https://www.authgear.com/ ○ https://github.com/authgear