World Congress 2026 Europe • Jul 9, 2026 • Session details

Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls

Martina Kraus

Are passkeys truly phishing-resistant? Discover how flawed configurations undermine WebAuthn and learn to integrate secure identity providers without building everything from scratch.

Pause
Mute Enter Fullscreen
#1 about 5 min

Why traditional multi-factor authentication fails against modern phishing

Proxy-based attacks can easily intercept time-based one-time passwords to bypass traditional multi-factor authentication.

#2 about 4 min

How passkey architecture provides built-in phishing resistance

Passkeys tie credentials directly to origin domains and utilize cryptographic signatures to eliminate interceptable secrets.

#3 about 6 min

Enabling and managing passkey authentication using Keycloak domains

Developers can register and handle hardware-bound or cross-platform passkeys directly through identity providers like Keycloak.

#4 about 3 min

Configuring the relying party identifier to prevent subdomain takeovers

Restricting the authentication domain prevents attackers from exploiting dangling subdomains to compromise broad passkey scopes.

#5 about 2 min

Enforcing local user verification to prevent physical proximity attacks

Requiring strict biometric unlock steps blocks unauthorized authentication attempts from a nearby connected mobile device.

#6 about 6 min

Evaluating authenticator attestation and utilizing the metadata service

Verifying manufacturer certificates against a global database ensures that only trusted authenticator models are accepted.

#7 about 3 min

Phasing out passwords and managing passkey account recovery

Transitioning users entirely away from passwords requires secure fallback mechanisms like magic links for lost hardware devices.

#8 about 5 min

Key integration takeaways and leveraging managed authentication services

Utilizing established identity providers prevents critical implementation flaws while supporting modern cryptographic standards and hardware constraints.

Matching moments

3:04 min

Defending against phishing with hardware passkeys

Christoph Menzel Christoph Menzel · World Congress 2026 Europe

3:17 min

Platform integration and synchronization using passkeys

Clemens Hübner Clemens Hübner · World Congress 2023

4:13 min

Hardware keys and mitigating persistent password vulnerabilities

Chris Heilmann Chris Heilmann +2 · LIVE

4:32 min

Shifting organizational security toward phishing-resistant authentication standards

Christoph Menzel Christoph Menzel · World Congress 2026 Europe

1:22 min

Securing application access with WebAuthn and physical FIDO keys

Gift Egwuenu · World Congress 2023

2:21 min

Improving usability around secure private key custody

John Woods John Woods · World Congress 2024