Clemens Hübner
Passwordless future: WebAuthn and Passkeys in practice
#1about 3 minutes
The fundamental problems with password-based authentication
Passwords are hard for users to manage and insecure for developers to store, making them vulnerable to phishing and theft.
#2about 1 minute
Shifting to modern possession and biometric factors
The future of authentication moves away from what you know (passwords) to what you have (possession) and what you are (biometrics).
#3about 2 minutes
An overview of the WebAuthn JavaScript API
WebAuthn is a W3C standard and JavaScript API that enables passwordless authentication in web apps using modern cryptography.
#4about 2 minutes
Live demo of passwordless registration and login
A practical demonstration shows how a user can register and log in to a web application using a physical security key instead of a password.
#5about 4 minutes
How WebAuthn's registration and authentication ceremonies work
WebAuthn uses a registration ceremony to create a public-private key pair and an authentication ceremony to verify identity with a challenge-response process.
#6about 3 minutes
Understanding the history and browser support for WebAuthn
WebAuthn has been a W3C standard since 2019 and is now supported by over 95% of modern browsers across all major platforms.
#7about 3 minutes
Introducing Passkeys to solve WebAuthn's usability issues
Early WebAuthn adoption was slow due to usability challenges like managing physical keys and syncing credentials across multiple devices.
#8about 4 minutes
How Passkeys improve the user experience
Passkeys are WebAuthn credentials integrated into platform ecosystems like Apple ID and Google accounts, enabling seamless syncing and cross-device usage via QR codes.
#9about 3 minutes
The impact of Passkeys on passwordless adoption
The introduction of Passkeys by major platforms has significantly accelerated the adoption of passwordless authentication by improving usability and providing user education.
#10about 7 minutes
Answering key questions about Passkeys and WebAuthn
Common questions are addressed regarding credential recovery, phishing resistance, future-proofing against quantum computing, and usability for non-technical users.
Related jobs
Jobs that call for the skills explored in this talk.
Java Softwareentwickler Kartenautorisierung (m/w/d)
Finanz Informatik
Frankfurt am Main, Germany
Intermediate
Matching moments
17:18 MIN
Understanding the next generation of authentication with passkeys
Going Beyond Passwords: The Future of User Authentication
13:11 MIN
Introducing passkeys for secure passwordless authentication
Passwordless Web 1.5
01:01 MIN
Understanding passwordless authentication technologies
Accelerating Authentication Architecture: Taking Passwordless to the Next Level
00:29 MIN
Exploring the user experience flaws in web authentication
SSO with Ethereum and Next JS
24:03 MIN
Following accessibility guidelines for authentication flows
The Cake Is a Lie... And So Is Your Login’s Accessibility
00:21 MIN
Understanding the vulnerabilities of password-based authentication
No More Post-its: Boost your login security with APIs
29:19 MIN
The future outlook for passkey authentication
Passwordless Web 1.5
26:25 MIN
Current adoption and developer implementation challenges
Passwordless Web 1.5
Featured Partners
Related Videos
Going Beyond Passwords: The Future of User Authentication
Gift Egwuenu
Passwordless Web 1.5
Paweł Łukaszuk
Accelerating Authentication Architecture: Taking Passwordless to the Next Level
Yedidya Schwartz
No More Post-its: Boost your login security with APIs
Alvaro Navarro
Programming secure C#/.NET Applications: Dos & Don'ts
Sebastian Leuer
Break the Chain: Decentralized solutions for today’s Web2.0 privacy problems
Adam Larter
Skynet wants your Passwords! The Role of AI in Automating Social Engineering
Wolfgang Ettlinger & Alexander Hurbean
Delegating the chores of authenticating users to Keycloak
Alexander Schwartz
From learning to earning
Jobs that call for the skills explored in this talk.


Vault & PKI Test Automation Engineer / Security QA Engineer
Westhouse Consulting GmbH
Go
API
Java
Bash
Python
+4

IT-Security Engineer Awarness Training and Security Roadmap
Paris Lodron-Universität Salzburg
Powershell
Windows Server
Microsoft Office
Scripting (Bash/Python/Go/Ruby)

Berater Cybersecurity Strategy
Webseite EY Deutschland

Informatiker Identity & Access Management/ IAM / Access / MFA
WWK Allgemeine Versicherung AG
Remote
Microsoft Access

Anwendungsentwickler IT-Security / Kryptographie
Finanz Informatik GmbH & Co. KG
Remote
Intermediate
GIT
Java
Eclipse
Jenkins


