< Back to all clusters
[TECHNOLOGY] · 5 sources

started · updated

Passkeys emerge as secure alternative to traditional passwords

Digital authentication is undergoing a significant shift as passkeys begin to replace traditional passwords. While passwords remain widely used for accessing email, social media, and banking, they are increasingly vulnerable to threats such as phishing, brute force attacks, and credential stuffing.

Passkeys utilize asymmetric cryptography, involving a public key stored on a server and a private key kept securely on a user's device. This method allows users to authenticate via biometrics, PINs, or facial recognition without transmitting a secret password. Because passkeys are tied to specific domains, they offer robust protection against phishing, as they cannot be used on fraudulent websites.

Security experts highlight two primary models for passkey management: synchronized passkeys, which allow credentials to move across multiple devices for user convenience, and device-bound passkeys, which remain physically attached to a single authenticator for higher security in professional environments. Despite these advancements, risks remain, including phishing campaigns that exploit human trust through fake emails and phone calls to bypass security measures.

Entities

Credit Agricole · FIDO · FIDO Alliance · Windows Hello