Why Hackers Can’t Phish Your Passkey
How Technology Actually Works
0:00 / 0:00
Why Hackers Can’t Phish Your Passkey
17 просмотров · 6 дней назад
How Technology Actually Works
11 подписчиков
17 просмотров · 6 дней назад
A hacker can steal your password.
They can trick you into entering an MFA code.
So why is a passkey different?
In this video, we break down what actually happens when you sign in with a passkey — and why a convincing phishing website can’t simply steal it like a password.
You’ll see how:
• Passkeys use public-key cryptography
• Private and public keys work together
• WebAuthn connects your browser to the authenticator
• FIDO2 and CTAP fit into the authentication process
• Your passkey is tied to the website it was created for
• A fake website can be recognized as the wrong origin
• The authenticator can refuse to sign the request
• Synced and device-bound passkeys differ
• Passkeys fit into Microsoft’s move toward phishing-resistant authentication
The key difference is simple:
Passwords are secrets you can be tricked into revealing.
Passkeys use cryptographic proof instead.
And that changes what phishing can do.
We’ll go step-by-step through the technology behind passkeys, from the moment a website sends a challenge to the moment your authenticator proves that you’re allowed to sign in.
Sources & further reading:
Microsoft Security
Microsoft Learn
W3C WebAuthn
FIDO Alliance
#Cybersecurity #Passkeys #Phishing #FIDO2 #WebAuthn #Technology