Passkeys are built on the FIDO2 standard (CTAP2 + WebAuthn standards). They remove the shared secret, stop phishing at the source, and make credential-stuffing useless.

But adoption is still low, and interoperability between Apple, Google, and Microsoft isn’t seamless.

I broke down how passkeys work, their strengths, and what’s still missing

you are viewing a single comment's thread
view the rest of the comments
[–] 98 points 10 months ago (1 child)

This is the only accurate take in the whole thread.

Passkeys solve "well, can't be fished" by introducing 2 new problems and never resolving super prevalent session hijacking. Even as a basic cost-benefit analysis, it's a net loss to literally everyone.

  • source
  • parent
  • hideshow 1 child comment
  • [–] 3 points 10 months ago

    That’s what I worried, and then especially to computers that age out of updates (2 older MacBooks).

    We end up having to reauthenticate on some other device at some point anyway and that means there’s still going to be a weak point.

    Like with 2 auth sim jacking.

  • source
  • parent