> Markdown version of [/videos/810-passwordless-future-webauthn-and-passkeys-in-practice?t=1071](https://www.wearedevelopers.com/videos/810-passwordless-future-webauthn-and-passkeys-in-practice?t=1071). Every page supports `.md` or `Accept: text/markdown`. Links point to the HTML versions so they work for humans too. Agent guide: [/agents.md](https://www.wearedevelopers.com/agents.md). --- # Passwordless future: WebAuthn and Passkeys in practice Traditional passwords and SMS 2FA are failing modern security standards. Master the navigator.credentials API to implement passkeys and deliver frictionless, phishing-resistant logins across all devices. - **Speakers:** [Clemens Hübner](https://www.wearedevelopers.com/@clemens-hubner) - **Event:** World Congress 2023 - **Published:** November 10, 2023 - **Duration:** 32:32 - **URL:** https://www.wearedevelopers.com/videos/810-passwordless-future-webauthn-and-passkeys-in-practice ## Summary Authentication has long relied on inherently fragile passwords that are vulnerable to guessing, improper storage, and sophisticated phishing attacks. Even traditional two-factor authentication (2FA) mechanisms like SMS and TOTP fail to stop modern phishing campaigns. The shift toward a passwordless future leverages WebAuthn, a W3C standard routing through browser JavaScript APIs, which transitions security from "something you know" to "something you have" or "something you are." By utilizing public key cryptography and a challenge-response model, WebAuthn ensures that sensitive secrets never leave the user's device and implicitly scopes credentials to specific domains, effectively neutralizing credential-stealing attacks. While WebAuthn laid the technical groundwork, early adoption was hindered by steep learning curves and the physical portability limits of hardware keys. Passkeys have revolutionized the ecosystem by wrapping WebAuthn credentials in platform-native usability. Driven by platforms like Apple, Google, and Microsoft, passkeys sync private keys across devices via cloud keychains and enable cross-ecosystem logins using QR codes backed by Bluetooth proximity checks. For developers, integrating passwordless logins involves using the `navigator.credentials` API to handle registration and authentication ceremonies natively within the browser. While the API abstracts much of the cryptographic heavy lifting, engineering teams must still design logical account recovery flows to handle lost personal devices. With nearly universal browser support, developers have a clear mandate to adopt passkeys, substantially reducing credential friction while elevating application security to next-generation standards. **Keywords:** passwordless authentication, webauthn standard, passkeys integration, public key cryptography, phishing resistance, challenge-response protocol, hardware security keys, biometric authentication, cross-device syncing, navigator credentials api, account recovery flows, two-factor authentication vulnerabilities ## Chapters 1. **Shortcomings of passwords and secondary authentication factors** (00:03) — Traditional memorized secrets and basic two-factor methods remain highly susceptible to phishing. 1. **Exploring possession and biometric authentication factors** (03:26) — Hardware tokens and biometric data provide stronger authentication by removing memorization burdens. 1. **Introduction to the WebAuthn JavaScript API architecture** (05:08) — WebAuthn acts as a standardized browser interface to securely handle challenge-response cryptography without transmitting secrets. 1. **Demonstration of passwordless registration and login** (07:04) — A practical implementation showcases how users interact with hardware keys during the registration and authentication flow. 1. **Understanding WebAuthn registration and authentication ceremonies** (08:57) — The underlying protocol relies on public key cryptography to generate credentials and verify digital signatures. 1. **Browser support timeline and early usability challenges** (13:08) — Despite widespread technical support, initial adoption struggled due to hardware portability limits and user education barriers. 1. **Platform integration and synchronization using passkeys** (17:51) — Major tech ecosystems rebrand webauthn credentials as synchronized passkeys to solve device constraints. 1. **Implementing cross-device login via QR codes** (21:09) — A hybrid mechanism allows secure authentication across device boundaries via proximity and local communication channels. 1. **Accelerating adoption through developer resources and user education** (22:24) — Implementing modern passwordless solutions requires careful planning around ecosystem constraints and guiding users through new workflows. 1. **Handling lost authenticators and future cryptographic standards** (25:47) — Fallback workflows for lost physical tokens rely on traditional email verification protocols while waiting for quantum-resistant updates. 1. **Establishing secure recovery factors without password fallbacks** (28:38) — Registering multiple hardware tokens or ecosystem passkeys prevents complete account lockout during device loss. 1. **Phishing protection and proximity checks for cross-device authentication** (29:50) — WebAuthn strictly binds credentials to originating domains to thwart traditional phishing and man-in-the-middle attacks. ## Related Moments - [Overcoming barriers to passwordless authentication adoption](https://www.wearedevelopers.com/videos/100322-mfa-game-over-watch-your-protection-collapse-live) (from "MFA? Game over! Watch your protection collapse – live") - [Hardware keys and mitigating persistent password vulnerabilities](https://www.wearedevelopers.com/videos/1331-wearedevelopers-live-chrome-for-sale-comet-the-upcoming-perplexity-browser-stealing-and-leaking) (from "WeAreDevelopers LIVE - Chrome for Sale? Comet - the upcoming perplexity browser Stealing and leaking") - [Replacing traditional website logins with biometric web passkeys](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) (from "Going Beyond Passwords: The Future of User Authentication") - [Introducing passkeys and the web authentication protocol components](https://www.wearedevelopers.com/videos/1216-passwordless-web-1-5) (from "Passwordless Web 1.5") - [Securing application access with WebAuthn and physical FIDO keys](https://www.wearedevelopers.com/videos/714-going-beyond-passwords-the-future-of-user-authentication) (from "Going Beyond Passwords: The Future of User Authentication") - [Phasing out passwords and managing passkey account recovery](https://www.wearedevelopers.com/videos/100156-passkeys-truly-phishing-resistant-implementation-and-pitfalls) (from "Passkeys: Truly Phishing-Resistant? Implementation and Pitfalls") ## Related Articles - [The top 200 passwords of 2024 can be cracked in less than a second](https://www.wearedevelopers.com/magazine/502-the-top-200-passwords-of-2024-can-be-cracked-in-less-than-a-second) - [Native Web Apps: Are We There Yet?](https://www.wearedevelopers.com/magazine/83-native-web-apps-are-we-there-yet) - [Dev Digest 138 - Are you secure about this?](https://www.wearedevelopers.com/magazine/486-dev-digest-138-are-you-secure-about-this) - [Dev Digest 115 password beefstew is not Strog/|n0FF](https://www.wearedevelopers.com/magazine/429-dev-digest-115-password-beefstew-is-not-strog-n0ff) ## Related Jobs - [Principal Software Engineer, Identity](https://www.wearedevelopers.com/jobs/ext/1469181-principal-software-engineer-identity) at **GitHub** - [Cyber Security Architect](https://www.wearedevelopers.com/jobs/ext/1210090-cyber-security-architect) at **BWI GmbH** - [Staff Developer Advocate, GitHub Security Lab](https://www.wearedevelopers.com/jobs/ext/1921051-staff-developer-advocate-github-security-lab) at **GitHub** - [Penetration Tester / Red team Specialist](https://www.wearedevelopers.com/jobs/ext/293774-penetration-tester-red-team-specialist) at **Raiffeisen Bank International AG** - [Security Architect - AI](https://www.wearedevelopers.com/jobs/ext/1581899-security-architect-ai) at **ZEISS Group** - [Security Solution Architekt - Schwerpunkt Access Management & Zero Trust](https://www.wearedevelopers.com/jobs/ext/91930-security-solution-architekt-schwerpunkt-access-management-zero-trust) at **BWI GmbH**