Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

  • Septimaeus@infosec.pub
    link
    fedilink
    English
    arrow-up
    5
    arrow-down
    3
    ·
    6 hours ago

    The passkey options I’ve come across so far are as close to push-button as I can imagine.

    Do you mean from the developer perspective, like the complexity of the API/workflow?

    • asmoranomar@lemmy.world
      link
      fedilink
      English
      arrow-up
      2
      ·
      50 minutes ago

      Perhaps he means the process of setting it up. Or when it doesn’t work. Or when passkeys are lost. Or using another device. A lot of people’s complaints about passkeys aren’t really about when it works.

      It’s valid I think, but also some people forget passwords can have similar experiences. For one, there seems to be this idea that if you lose your passkey you get locked out of your account forever. The recovery process should be no different than losing your password.