Перейти к содержимому

Why Hackers Can’t Phish Your Passkey

How Technology Actually Works

0:00 / 0:00

Why Hackers Can’t Phish Your Passkey

17 просмотров · 6 дней назад
How Technology Actually Works
11 подписчиков
17 просмотров · 6 дней назад
A hacker can steal your password. They can trick you into entering an MFA code. So why is a passkey different? In this video, we break down what actually happens when you sign in with a passkey — and why a convincing phishing website can’t simply steal it like a password. You’ll see how: • Passkeys use public-key cryptography • Private and public keys work together • WebAuthn connects your browser to the authenticator • FIDO2 and CTAP fit into the authentication process • Your passkey is tied to the website it was created for • A fake website can be recognized as the wrong origin • The authenticator can refuse to sign the request • Synced and device-bound passkeys differ • Passkeys fit into Microsoft’s move toward phishing-resistant authentication The key difference is simple: Passwords are secrets you can be tricked into revealing. Passkeys use cryptographic proof instead. And that changes what phishing can do. We’ll go step-by-step through the technology behind passkeys, from the moment a website sends a challenge to the moment your authenticator proves that you’re allowed to sign in. Sources & further reading: Microsoft Security Microsoft Learn W3C WebAuthn FIDO Alliance #Cybersecurity #Passkeys #Phishing #FIDO2 #WebAuthn #Technology