Passwords suck. Can passkeys replace them?
Summary
Discusses the potential of passkeys to replace passwords as a more secure authentication method.
Similar Articles
Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
This Unit 42 research discloses three novel attacks against passwordless authentication using Google's synced passkey ecosystem, showing how malware can take over passkey-protected accounts, bypass user verification, and extract private keys.
XSS Is Deadly for Passkeys: The Hidden Risk of Attestation None
The article explains how a single XSS vulnerability can defeat the phishing-resistance of passkeys when attestation is set to 'none', allowing attackers to register their own passkeys and achieve persistent account takeover. It calls for attention to this overlooked threat and suggests defenses.
Switching Password Managers in 2026
The article explains how password managers can now exchange data across platforms using passkeys, featuring a demo of exporting from 1Password to Apple Passwords on iOS.
Passkeys were invented by engineers with zero understanding of consumer brain
The author criticizes the rollout of passkeys, arguing that they were designed by engineers who don't understand how ordinary consumers think, and expresses confusion even as a tech company founder.
New Pass-ta-key attack reveals all the things we didn't know about passkeys
A new attack called Pass-ta-key shows that passkeys stored in Google Password Manager on Windows can be extracted by malware, revealing that passkeys are generally stored locally rather than in TPM hardware. The article clarifies that this is not a novel attack and that the Windows platform is the main exception.