Passkeys
Passkeys replace passwords with cryptographic key pairs, effectively protecting logins against phishing.
Passkeys are credentials that replace a password with a cryptographic key pair. They are bound to the respective website and are therefore resistant to phishing.
How it works
When setting up a passkey, the device generates a key pair. The public key is stored by the service. The private key remains protected on the device or in a password manager. To sign in, the person authenticates using a fingerprint, face, or PIN. The device then signs a challenge from the service with its private key. Since the passkey is bound to the real domain, it will not work on a fraudulent website. Passkeys are based on the FIDO2 and WebAuthn standards.
For example, an employee clicks a link to a deceptive login page. They no longer have a password, only a passkey. The browser does not offer the passkey on the fake domain. The attacker gets neither credentials nor a session token.
What to look out for
- Plan a process for lost or new devices. The recovery process is often the weakest link.
- Distinguish between synchronised passkeys and device-bound security keys. Device-bound keys are often a better choice for administrators.
- Check which of your applications already support passkeys.
- Remove weaker authentication methods once passkeys are implemented.
Why it matters
Many attacks start with stolen credentials, even with MFA. Passkeys largely close this avenue. In addition, there is no longer a password that can be reused or published in a data leak.
Limitations
Passkeys only protect the authentication step itself. Attackers can still hijack sessions on an already compromised device, for example through malware. A weak helpdesk or account recovery process can also undermine the protection offered by passkeys.
Switzerland and regulation
The National Cyber Security Centre (NCSC) recommends phishing-resistant methods for protecting accounts. Cyber insurance providers and supervisory authorities increasingly expect strong authentication. This is especially true for privileged accounts.
How we implement it
In the SOC, we monitor the registration of new authentication methods. We are happy to discuss architecture questions as part of our Security Consulting.