Clemens Hübner
Passwordless future: WebAuthn and Passkeys in practice
#1about 3 minutes
The fundamental problems with password-based authentication
Passwords are hard for users to manage and insecure for developers to store, making them vulnerable to phishing and theft.
#2about 1 minute
Shifting to modern possession and biometric factors
The future of authentication moves away from what you know (passwords) to what you have (possession) and what you are (biometrics).
#3about 2 minutes
An overview of the WebAuthn JavaScript API
WebAuthn is a W3C standard and JavaScript API that enables passwordless authentication in web apps using modern cryptography.
#4about 2 minutes
Live demo of passwordless registration and login
A practical demonstration shows how a user can register and log in to a web application using a physical security key instead of a password.
#5about 4 minutes
How WebAuthn's registration and authentication ceremonies work
WebAuthn uses a registration ceremony to create a public-private key pair and an authentication ceremony to verify identity with a challenge-response process.
#6about 3 minutes
Understanding the history and browser support for WebAuthn
WebAuthn has been a W3C standard since 2019 and is now supported by over 95% of modern browsers across all major platforms.
#7about 3 minutes
Introducing Passkeys to solve WebAuthn's usability issues
Early WebAuthn adoption was slow due to usability challenges like managing physical keys and syncing credentials across multiple devices.
#8about 4 minutes
How Passkeys improve the user experience
Passkeys are WebAuthn credentials integrated into platform ecosystems like Apple ID and Google accounts, enabling seamless syncing and cross-device usage via QR codes.
#9about 3 minutes
The impact of Passkeys on passwordless adoption
The introduction of Passkeys by major platforms has significantly accelerated the adoption of passwordless authentication by improving usability and providing user education.
#10about 7 minutes
Answering key questions about Passkeys and WebAuthn
Common questions are addressed regarding credential recovery, phishing resistance, future-proofing against quantum computing, and usability for non-technical users.
Related jobs
Jobs that call for the skills explored in this talk.
Architekt für Cloud Security - AWS (w|m|d)

zeb consulting
Frankfurt am Main, Germany
Remote
Junior
Intermediate
Senior
Featured Partners
Related Videos
Going Beyond Passwords: The Future of User Authentication
Gift Egwuenu
Passwordless Web 1.5
Paweł Łukaszuk
Security in modern Web Applications - OWASP to the rescue!
Jakub Andrzejewski
Unleashing the Power of Developers: Why Cybersecurity is the Missing Piece?!?
Tino Sokic
Let’s write an exploit using AI
Julian Totzek-Hallhuber
Accelerating Authentication Architecture: Taking Passwordless to the Next Level
Yedidya Schwartz
No More Post-its: Boost your login security with APIs
Alvaro Navarro
Programming secure C#/.NET Applications: Dos & Don'ts
Sebastian Leuer
From learning to earning
Jobs that call for the skills explored in this talk.
Senior Software Engineer - AI Authentication (Auth for GenAI)
Okta for Developers
Barcelona, Spain
API
NoSQL
MongoDB
Node.js
JavaScript
+3
Staff Security Research Engineer
Proofpoint
Municipality of Madrid, Spain
Remote
Python
Document Object Model (DOM)
Identity & Access Consultant (m/w/d) - mit Fokus auf Okta & Auth0
Skaylink GmbH
Leipzig, Germany
Remote
Azure
Microsoft Access
Microsoft Office
Microsoft Active Directory
Senior Backend Engineer, Authentication and Authorization
Pleo
Municipality of Madrid, Spain
Remote
€80-85K
API
Java
Kotlin
+2




