started · updated
Passkey authentication faces new security threats and market shifts
New research has identified at least 39 documented methods and exploitation scenarios that can compromise passkey authentication and the surrounding infrastructure. While the underlying FIDO2 cryptography may remain intact, attackers are targeting various layers of the authentication ceremony, including web applications, browsers, operating systems, and cloud synchronization services. Identified techniques include assertion phishing, browser hooking, and user verification manipulation.
In the commercial sector, password manager companies are navigating shifting pricing models and security architectures. 1Password maintains a significant enterprise presence with 180,000 businesses, focusing on passkey usability and its 2SKD dual-layer protection system. Meanwhile, Bitwarden has reached 15 million users and 80,000 businesses, recently raising its Premium tier price to $19.80 annually. Proton Pass continues to compete in the free-tier market by offering email aliases and passkey synchronization.
Entities
1Password · Bitwarden · Proton Pass · SpecterOps · W3C