Home / Companies / Ory / Blog / Post Details
Content Deep Dive

The case for device binding: what it actually protects

Blog post from Ory

Post Details
Company
Ory
Date Published
Author
Lani Leuthvilay
Word Count
977
Company Posts That Month
4
Language
English
Hacker News Points
-
Post removed?
No
Summary

Device binding, or device authentication, uses public-key cryptography and hardware-backed keys to restrict account access to one specific verified phone, addressing account takeover risks that passwords, SMS codes, tokens, and often synchronized passkeys cannot fully prevent. During enrollment, a device generates a non-exportable private key in Apple Secure Enclave or Android Keystore hardware, while platform attestation verifies that the key belongs to a genuine, uncompromised physical device; later logins require the enrolled device to sign a server challenge after biometric or PIN verification. Unlike passkeys, which are designed to synchronize across a user’s devices for convenience, device binding is intended for businesses such as banks and fintechs that require access to remain limited to an approved device. It can serve either as a second factor for sensitive actions or as a passwordless first factor, with Ory’s app PIN offering an alternative for users without or unwilling to use biometrics while protecting against offline guessing through rate limits and key destruction after repeated failures. Ory’s implementation supports iOS and Android native applications and meets NIST AAL2 requirements, with potential future support for AAL3 when keys use dedicated security hardware.

Trends Found in this Post

No tracked trend matches for this post yet.

Use This Data

Use this post, company, and trend context to find content marketing opportunities, perform competitive analysis, or address product feature gaps via the Plushcap MCP server or the Plushcap API.