Passwords are fundamentally broken, even with 2FA. Learn how passkeys provide true phishing resistance by design, eliminating server-side credential theft.
#1about 2 minutes
The fundamental security flaws of traditional passwords
Passwords suffer from issues like weakness, reuse across multiple accounts, and predictability, leading to widespread security vulnerabilities.
#2about 2 minutes
Why mandatory password rotation policies often fail
Forcing users to change passwords frequently leads to predictable patterns and weaker credentials, undermining the intended security benefits.
#3about 5 minutes
Risks from password managers and server-side storage
Even with strong passwords, security is compromised by vulnerabilities in password managers and poor server-side practices like weak hashing.
#4about 3 minutes
How phishing attacks can bypass two-factor authentication
Malicious actors can intercept one-time passwords to defeat common two-factor authentication, making physical security keys a stronger alternative.
#5about 3 minutes
Introducing passkeys for secure passwordless authentication
Passkeys leverage the FIDO2 and WebAuthn standards with public-key cryptography to provide a more secure and user-friendly login experience.
#6about 4 minutes
How to register and sign in using passkeys
The user workflow involves creating a passkey tied to a device's lock mechanism and then using that same mechanism for subsequent logins.
#7about 4 minutes
Using cross-device authentication for phishing resistance
Logging into a new device with a phone's passkey uses a QR code and Bluetooth for proximity detection, effectively preventing remote phishing attacks.
#8about 2 minutes
Strategies for managing passkeys across multiple devices
Users can manage their passkeys across different devices using built-in OS credential managers, third-party password managers, or physical hardware keys.
#9about 3 minutes
Current adoption and developer implementation challenges
While major platforms are adopting passkeys, implementation is complex for developers due to detailed specifications and a lack of reliable AI-generated code.
#10about 1 minute
The future outlook for passkey authentication
Although widespread adoption will take time, passkeys represent the most affordable and secure future for digital authentication.
Related jobs
Jobs that call for the skills explored in this talk.
Why Developers are So Excited About PretextPretext is a new JavaScript and TypeScript library from Cheng Lou - previously a React core developer - that crossed 7,000 GitHub stars in three days to get the entire tech world talking recently.
The demos that spread were visually striking: dragon...
Chris Heilmann
The top 200 passwords of 2024 can be cracked in less than a secondPasswords are a pain and with biometric logins, passkeys and other two factor authentication methods should be a thing of the past. In reality, though, a lot of systems still use username and password as the only security measure and users choose al...
The Overflow: 5 Security and Privacy Tools for DevelopersWe’re back again with another edition of the Overflow, where we share some of the best tools we’ve found from around the web that we just couldn’t cram into the already jam-packed editions of the Dev Digest.
So let’s take a look at five security and ...
From learning to earning
Jobs that call for the skills explored in this talk.