World Congress 2023 • Nov 10, 2023

Passwordless future: WebAuthn and Passkeys in practice

Clemens Hübner

Traditional passwords and SMS 2FA are failing modern security standards. Master the navigator.credentials API to implement passkeys and deliver frictionless, phishing-resistant logins across all devices.

Pause
Mute Enter Fullscreen
#1 about 4 min

Shortcomings of passwords and secondary authentication factors

Traditional memorized secrets and basic two-factor methods remain highly susceptible to phishing.

#2 about 2 min

Exploring possession and biometric authentication factors

Hardware tokens and biometric data provide stronger authentication by removing memorization burdens.

#3 about 2 min

Introduction to the WebAuthn JavaScript API architecture

WebAuthn acts as a standardized browser interface to securely handle challenge-response cryptography without transmitting secrets.

#4 about 2 min

Demonstration of passwordless registration and login

A practical implementation showcases how users interact with hardware keys during the registration and authentication flow.

#5 about 5 min

Understanding WebAuthn registration and authentication ceremonies

The underlying protocol relies on public key cryptography to generate credentials and verify digital signatures.

#6 about 5 min

Browser support timeline and early usability challenges

Despite widespread technical support, initial adoption struggled due to hardware portability limits and user education barriers.

#7 about 4 min

Platform integration and synchronization using passkeys

Major tech ecosystems rebrand webauthn credentials as synchronized passkeys to solve device constraints.

#8 about 2 min

Implementing cross-device login via QR codes

A hybrid mechanism allows secure authentication across device boundaries via proximity and local communication channels.

#9 about 4 min

Accelerating adoption through developer resources and user education

Implementing modern passwordless solutions requires careful planning around ecosystem constraints and guiding users through new workflows.

#10 about 3 min

Handling lost authenticators and future cryptographic standards

Fallback workflows for lost physical tokens rely on traditional email verification protocols while waiting for quantum-resistant updates.

#11 about 2 min

Establishing secure recovery factors without password fallbacks

Registering multiple hardware tokens or ecosystem passkeys prevents complete account lockout during device loss.

#12 about 3 min

Phishing protection and proximity checks for cross-device authentication

WebAuthn strictly binds credentials to originating domains to thwart traditional phishing and man-in-the-middle attacks.

Matching moments

1:53 min

Overcoming barriers to passwordless authentication adoption

Christoph Menzel Christoph Menzel · World Congress 2026 Europe

4:13 min

Hardware keys and mitigating persistent password vulnerabilities

Chris Heilmann Chris Heilmann +2 · LIVE

2:09 min

Replacing traditional website logins with biometric web passkeys

Gift Egwuenu · World Congress 2023

3:04 min

Introducing passkeys and the web authentication protocol components

Paweł Łukaszuk · LIVE

1:22 min

Securing application access with WebAuthn and physical FIDO keys

Gift Egwuenu · World Congress 2023

2:20 min

Phasing out passwords and managing passkey account recovery

Martina Kraus Martina Kraus · World Congress 2026 Europe