Upgrade to Pro — share decks privately, control downloads, hide ads and more …

What the fuck are passkeys and why are they eve...

What the fuck are passkeys and why are they everywhere now?

It seems like every time you login to a website nowadays, it asks you to create a passkey. If you’re like me, you initially assumed this was some sort of scam. But now that it’s everywhere, you’re beginning to wonder what it’s all about and why every website is pushing it constantly.

This talk will cover the basics of what a passkey is, how they came to be, and what you should do about them now that they’re here.

Avatar for Daniel Lew

Daniel Lew

May 02, 2026

More Decks by Daniel Lew

Other Decks in Technology

Transcript

  1. What the fuck are passkeys and why are they everywhere

    now https://www. fl ickr.com/photos/xrrr/3892883749 Dan Lew @ Minnebar20
  2. Proposal 2013 2026? Level 3 Standard Apple Passkeys 2022 2019

    Level 1 Standard Level 2 Standard 2021
  3. Neo 🧑 Trinity 👩 Neo’s private key Trinity, help! Trinity,

    Help! BE459576 786039E8 Neo’s public key Sign
  4. Neo 🧑 Trinity 👩 Neo’s private key Trinity, help! Trinity,

    Help! BE459576 786039E8 Neo’s public key Verify Sign
  5. Neo 🧑 Trinity 👩 Neo’s private key Trinity, help! Trinity,

    Help! BE459576 786039E8 Trinity, help! Neo’s public key Verify Sign
  6. Trinity 👩 Trinity, help! Trinity, Help! BE459576 786039E8 Trinity, help!

    Verify Sign You 🫵 Your private key Your public key
  7. Trinity, help! Trinity, Help! BE459576 786039E8 Trinity, help! Verify Sign

    You 🫵 Your private key Your public key Server 🌐
  8. Verify Sign You 🫵 Your private key Your public key

    Server 🌐 It’s me! It’s me! BE459576 786039E8 It’s me!
  9. ♻ Password reuse 🔓 Weak passwords 🔐 Strong passkeys ❄

    Unique passkeys Data breaches 🚨 🎣 Phishing
  10. ♻ Password reuse Data breaches 🚨 🔓 Weak passwords 🔐

    Strong passkeys ❄ Unique passkeys 🥱 Breach safe 🎣 Phishing
  11. ♻ Password reuse 🎣 Phishing Data breaches 🚨 🔓 Weak

    passwords 🔐 Strong passkeys ❄ Unique passkeys 🥱 Breach safe 🪝 Domain locked
  12. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication
  13. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication FALSE
  14. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) FALSE
  15. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) FALSE FALSE
  16. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa FALSE FALSE
  17. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa FALSE FALSE TRUE
  18. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts FALSE FALSE TRUE
  19. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts FALSE FALSE TRUE FALSE
  20. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts • You need the device that created the passkey to use it FALSE FALSE TRUE FALSE
  21. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts • You need the device that created the passkey to use it FALSE FALSE TRUE FALSE IT DEPENDS
  22. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts • You need the device that created the passkey to use it • You’re locked into a vendor’s credential manager (Apple, Google, etc.) FALSE FALSE TRUE FALSE IT DEPENDS
  23. Trivia Time! True or false… • Your biometrics are sent

    to servers during passkey authentication • Passkeys are 2FA (like SMS or TOTP) • You can use an iOS passkey on an Android phone or vice versa • Losing your phone means losing access to passkey accounts • You need the device that created the passkey to use it • You’re locked into a vendor’s credential manager (Apple, Google, etc.) FALSE FALSE TRUE FALSE IT DEPENDS FALSE
  24. Inconsistencies Website or
 app 📱 Operating
 system ⚙ Browser 🌎

    Credential
 manager 🗄 Personal vs.
 work account 🏢
  25. Inconsistencies Website or
 app 📱 Operating
 system ⚙ Browser 🌎

    Credential
 manager 🗄 Personal vs.
 work account 🏢 Software vs.
 hardware authenticator 🗝
  26. Horror Stories One passkey
 at a time ☝ One passkey


    *ever* 🖕 Links passkey
 to cookie 🍪
  27. Horror Stories One passkey
 at a time ☝ One passkey


    *ever* 🖕 Links passkey
 to cookie 🍪 Can’t initiate
 passkey fl ow 🛑
  28. Horror Stories One passkey
 at a time ☝ One passkey


    *ever* 🖕 Links passkey
 to cookie 🍪 Can’t initiate
 passkey fl ow 🛑 Can’t fi nd
 passkey ❓
  29. Horror Stories One passkey
 at a time ☝ One passkey


    *ever* 🖕 Links passkey
 to cookie 🍪 Can’t initiate
 passkey fl ow 🛑 Can’t fi nd
 passkey ❓ Just plain
 broken! ☹
  30. ♻ Password reuse 🎣 Phishing Data breaches 🚨 🔓 Weak

    passwords 🔐 Strong passkeys ❄ Unique passkeys 🥱 Breach safe 🪝 Domain locked
  31. Passkey hopes & dreams… 🤝 Understood
 and trusted ⚖ Stable

    and
 consistent 💎 Rough edges
 polished