World Congress 2026 Europe Jul 9, 2026 Session details

Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls

Martina Kraus

Are passkeys truly phishing-resistant? Discover how flawed configurations undermine WebAuthn and learn to integrate secure identity providers without building everything from scratch.

Pause
Mute Enter Fullscreen
#1 about 5 min

Why traditional multi-factor authentication fails against modern phishing

Proxy-based attacks can easily intercept time-based one-time passwords to bypass traditional multi-factor authentication.

#2 about 4 min

How passkey architecture provides built-in phishing resistance

Passkeys tie credentials directly to origin domains and utilize cryptographic signatures to eliminate interceptable secrets.

#3 about 6 min

Enabling and managing passkey authentication using Keycloak domains

Developers can register and handle hardware-bound or cross-platform passkeys directly through identity providers like Keycloak.

#4 about 3 min

Configuring the relying party identifier to prevent subdomain takeovers

Restricting the authentication domain prevents attackers from exploiting dangling subdomains to compromise broad passkey scopes.

#5 about 2 min

Enforcing local user verification to prevent physical proximity attacks

Requiring strict biometric unlock steps blocks unauthorized authentication attempts from a nearby connected mobile device.

#6 about 6 min

Evaluating authenticator attestation and utilizing the metadata service

Verifying manufacturer certificates against a global database ensures that only trusted authenticator models are accepted.

#7 about 3 min

Phasing out passwords and managing passkey account recovery

Transitioning users entirely away from passwords requires secure fallback mechanisms like magic links for lost hardware devices.

#8 about 5 min

Key integration takeaways and leveraging managed authentication services

Utilizing established identity providers prevents critical implementation flaws while supporting modern cryptographic standards and hardware constraints.

Matching moments

3:04 min

Defending against phishing with hardware passkeys

Christoph Menzel Christoph Menzel · WWC Europe 2026

3:17 min

Platform integration and synchronization using passkeys

Clemens Hübner Clemens Hübner · WWC 2023

4:13 min

Hardware keys and mitigating persistent password vulnerabilities

Chris Heilmann +2 · LIVE

4:32 min

Shifting organizational security toward phishing-resistant authentication standards

Christoph Menzel Christoph Menzel · WWC Europe 2026

1:22 min

Securing application access with WebAuthn and physical FIDO keys

Gift Egwuenu · WWC 2023

2:21 min

Improving usability around secure private key custody

John Woods John Woods · WWC 2024

Upcoming sessions on this topic

Open session

World Congress 2026 North America

Secure-by-Inclusion: Preventing Accessibility Barriers from Becoming Security Vulnerabilities

Radostina (Ina) Tsvetkova

Norwegian Directorate of Labour and Welfare (NAV), Senior Advisor in Digital Accessibility and Inclusive Design

Radostina (Ina) Tsvetkova
Open session

World Congress 2026 North America

Securing AI Agent Infrastructure: Identity, Attestation, and Trust at Scale

Abdel Fane

Founder of OpenA2A

Abdel Fane
Open session

World Congress 2026 North America

SecurePrompt: Building a Pre-Flight Security Layer for Agentic AI

Ravi Sastry Kadali

AI/ML Engineer at General Motors

Ravi Sastry Kadali
Open session

World Congress 2026 North America

Responsible AI Architecture with Zero Trust Agents

Ashok Prakash

Staff ML Engineer at Apple

Ashok Prakash
Open session

World Congress 2026 North America

Designing APIs That Survive AI Agents at Scale

Phani Pendurthi

Mastercard, Principal Software Engineer

Phani Pendurthi
Open session

World Congress 2026 North America

It passed auth, then production caught fire

Alex Olivier

Co-founder & CPO @ Cerbos | OpenID AuthZEN Co-chair

Alex Olivier