> Markdown version of [/videos/1216-passwordless-web-1-5?t=1662](https://www.wearedevelopers.com/videos/1216-passwordless-web-1-5?t=1662). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Passwordless Web 1.5 Traditional authentication is broken, but deploying Passkeys isn't just a simple NPM import. Master the complex WebAuthn specification to build virtually perfect, phishing-resistant logins for your applications. - **Speakers:** Paweł Łukaszuk - **Event:** WeAreDevelopers LIVE - **Published:** September 25, 2024 - **Duration:** 30:21 - **URL:** https://www.wearedevelopers.com/videos/1216-passwordless-web-1-5 ## Summary Traditional password authentication is broken, relying on outdated analog concepts in a digital security world. Users struggle to balance immense credential volume with security, often resorting to predictable patterns or relying on password managers that introduce single points of failure. Even worse, mandatory password resets—a practice largely advised against by Microsoft and modern security standards—only encourage weak, iterative passwords. Furthermore, standard two-factor authentication (2FA) via one-time passwords remains highly vulnerable to real-time proxy phishing attacks, as seen in major corporate breaches. To combat these systemic vulnerabilities, the industry is transitioning toward "Passwordless Web 1.5" through the adoption of Passkeys. Built on the foundational FIDO2 and WebAuthn standards, Passkeys leverage asymmetric cryptography to eliminate shared secrets. A private key remains locked within a device's secure hardware (like a TPM or Secure Enclave), while only the public key resides on the server. By requiring local biometric or PIN unlocking, Passkeys provide a frictionless user experience while fundamentally binding authentication to the exact domain being accessed. This automatic domain-binding mechanism, coupled with Bluetooth proximity detection for cross-device logins, entirely removes the human element from URL verification and creates virtually perfect phishing resistance. While Passkeys are now supported by major platforms and third-party password managers, achieving widespread adoption remains a long-term architectural challenge. Implementing Passkeys is not as simple as importing an NPM package; it requires developers to deeply understand a complex, 200-page specification and handle intricate credential management logic. Because the technology and its implementation patterns are relatively new, relying on generative AI tools for coding assistance often yields incorrect or insecure results. Despite the steep developer learning curve and an anticipated enterprise transition period spanning several years, Passkeys currently represent the most universally affordable, secure, and user-friendly mechanism to permanently replace legacy credentials. **Keywords:** passkeys implementation, passwordless authentication, FIDO2 standard, WebAuthn protocol, asymmetric cryptography in web, credential phishing resistance, real-time 2FA bypass, cross-device authentication, bluetooth proximity detection, domain binding security, trusted platform module TPM, secure enclave credentials, mandatory password reset policies, hardware security keys, web security architecture framework ## Chapters 1. **Common issues with creating and remembering diverse passwords** (00:03) — The challenges of generating, memorizing, and reusing traditional combinations across numerous internet accounts. 1. **Counterproductive effects of mandatory password rotation policies** (02:54) — User behaviors and security compromises that occur when businesses force frequent password changes. 1. **Evaluating password managers and physical credential tracking methods** (05:18) — The practical realities and security trade-offs of storing hundreds of personal and business logins. 1. **Exposing user credentials through massive server data breaches** (08:01) — How weak hashing algorithms and logging errors lead to billions of compromised user combinations. 1. **The vulnerability of two-factor authentication to live phishing attacks** (10:04) — How malicious actors bypass code checks and the hardware cost constraints of preventing proxies. 1. **Introducing passkeys and the web authentication protocol components** (13:11) — The hardware and software puzzle pieces needed to adopt asymmetric cryptography for digital verification. 1. **Registering and logging in with primary device passkeys** (16:15) — The seamless user workflow for connecting profiles to local hardware using standard screen locks. 1. **Implementing cross-device authentication and proximity phishing resistance** (20:06) — Connecting computing environments to mobile credentials securely via encrypted bluetooth signals and domain checks. 1. **Synchronizing digital keys across ecosystems and hardware limitations** (24:01) — Exploring storage options spanning integrated cloud accounts, dedicated vaults, and constrained physical tokens. 1. **Engineering challenges and complexities of implementing web authentication** (27:42) — The extensive manual coding and protocol testing developers need to integrate strict security benchmarks. ## Related Moments - [Platform integration and synchronization using passkeys](https://www.wearedevelopers.com/videos/810-passwordless-future-webauthn-and-passkeys-in-practice) (from "Passwordless future: WebAuthn and Passkeys in practice") - [Overcoming barriers to passwordless authentication adoption](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) (from "MFA? Game over! Watch your protection collapse – live") - [Hardware keys and mitigating persistent password vulnerabilities](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") - [Demonstration of passwordless registration and login](https://www.wearedevelopers.com/videos/810-passwordless-future-webauthn-and-passkeys-in-practice) (from "Passwordless future: WebAuthn and Passkeys in practice") - [Replacing traditional website logins with biometric web passkeys](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) (from "Going Beyond Passwords: The Future of User Authentication") - [How passkey architecture provides built-in phishing resistance](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) (from "Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls") ## Related Articles - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [Dev Digest 115 password beefstew is not Strog/|n0FF](https://www.wearedevelopers.com/magazine/429-dev-digest-115-password-beefstew-is-not-strog-n0ff) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 167: Open Source AI, Passwordless Microsoft and Vibe Coding](https://www.wearedevelopers.com/magazine/586-dev-digest-167-open-source-ai-passwordless-microsoft-and-vibe-coding) ## Related Jobs - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Cyber Security Architect](https://www.wearedevelopers.com/jobs/ext/1210090-cyber-security-architect) at **BWI GmbH** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Engineer, Offensive Security Organization](https://www.wearedevelopers.com/jobs/ext/1992296-engineer-offensive-security-organization) at **Twilio**