Clemens Hübner
Passwordless future: WebAuthn and Passkeys in practice
#1about 3 minutes
The fundamental problems with password-based authentication
Passwords are hard for users to manage and insecure for developers to store, making them vulnerable to phishing and theft.
#2about 1 minute
Shifting to modern possession and biometric factors
The future of authentication moves away from what you know (passwords) to what you have (possession) and what you are (biometrics).
#3about 2 minutes
An overview of the WebAuthn JavaScript API
WebAuthn is a W3C standard and JavaScript API that enables passwordless authentication in web apps using modern cryptography.
#4about 2 minutes
Live demo of passwordless registration and login
A practical demonstration shows how a user can register and log in to a web application using a physical security key instead of a password.
#5about 4 minutes
How WebAuthn's registration and authentication ceremonies work
WebAuthn uses a registration ceremony to create a public-private key pair and an authentication ceremony to verify identity with a challenge-response process.
#6about 3 minutes
Understanding the history and browser support for WebAuthn
WebAuthn has been a W3C standard since 2019 and is now supported by over 95% of modern browsers across all major platforms.
#7about 3 minutes
Introducing Passkeys to solve WebAuthn's usability issues
Early WebAuthn adoption was slow due to usability challenges like managing physical keys and syncing credentials across multiple devices.
#8about 4 minutes
How Passkeys improve the user experience
Passkeys are WebAuthn credentials integrated into platform ecosystems like Apple ID and Google accounts, enabling seamless syncing and cross-device usage via QR codes.
#9about 3 minutes
The impact of Passkeys on passwordless adoption
The introduction of Passkeys by major platforms has significantly accelerated the adoption of passwordless authentication by improving usability and providing user education.
#10about 7 minutes
Answering key questions about Passkeys and WebAuthn
Common questions are addressed regarding credential recovery, phishing resistance, future-proofing against quantum computing, and usability for non-technical users.
Related jobs
Jobs that call for the skills explored in this talk.
Java Softwareentwickler Kartenautorisierung (m/w/d)
Finanz Informatik
Frankfurt am Main, Germany
Intermediate
Matching moments
17:18 MIN
Understanding the next generation of authentication with passkeys
Going Beyond Passwords: The Future of User Authentication
13:11 MIN
Introducing passkeys for secure passwordless authentication
Passwordless Web 1.5
01:01 MIN
Understanding passwordless authentication technologies
Accelerating Authentication Architecture: Taking Passwordless to the Next Level
00:29 MIN
Exploring the user experience flaws in web authentication
SSO with Ethereum and Next JS
24:03 MIN
Following accessibility guidelines for authentication flows
The Cake Is a Lie... And So Is Your Login’s Accessibility
00:21 MIN
Understanding the vulnerabilities of password-based authentication
No More Post-its: Boost your login security with APIs
29:19 MIN
The future outlook for passkey authentication
Passwordless Web 1.5
26:25 MIN
Current adoption and developer implementation challenges
Passwordless Web 1.5
Featured Partners
Related Videos
Going Beyond Passwords: The Future of User Authentication
Gift Egwuenu
Passwordless Web 1.5
Paweł Łukaszuk
Accelerating Authentication Architecture: Taking Passwordless to the Next Level
Yedidya Schwartz
No More Post-its: Boost your login security with APIs
Alvaro Navarro
Programming secure C#/.NET Applications: Dos & Don'ts
Sebastian Leuer
Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems
Adam Larter
Skynet wants your Passwords! The Role of AI in Automating Social Engineering
Wolfgang Ettlinger & Alexander Hurbean
Delegating the chores of authenticating users to Keycloak
Alexander Schwartz
From learning to earning
Jobs that call for the skills explored in this talk.

Key and Crypto Engineer
Deutsche Bank

Automotive Security Pentester - Connected Car
proofnet GmbH


Vault & PKI Test Automation Engineer / Security QA Engineer
Westhouse Consulting GmbH
Go
API
Java
Bash
Python
+4

IT-Security Engineer Awarness Training and Security Roadmap
Paris Lodron-Universität Salzburg
Powershell
Windows Server
Microsoft Office
Scripting (Bash/Python/Go/Ruby)



Berater Cybersecurity Strategy
Webseite EY Deutschland

Anwendungsentwickler IT-Security / Kryptographie
Finanz Informatik GmbH & Co. KG
Remote
Intermediate
GIT
Java
Eclipse
Jenkins