establishing end-to-end ecrypted communication channel
sign in
require platform support
bound (embedded_ authenticators): biometricts and PINs, and external (roaming) authenticators: FIDO security keys, mobile devices, wearables
keys sync (icloud, google, 1password)
don’t need username
bluetooth should be enabled
CTAP1 (2FA only) and CTAP2 (passwordless and 2FA)
Passkey could be used as FIDO1 device with existente sites with no code change
Passkey has a device info boud to auth request, the same passkey + device info could identify that the login is from new device and trigger conditional 2FA
Share passkey
Advantages for business
faster login
lower bounce rate
Disadvantages
learning curve (your role in it)
user account restore and reset (aooth could help)
not widely supported (aooth could help)
rely on your phone security (your iCloud password), which is yubikey
because passkey is saved in your iCloud, anuyone could buy an iPhone and login to all your passkeys
passkeys should be supported on your phone
don’t have advanced features as password mangers: share passwor4ds, password delegation, auth groups
Apple adds sharing with AirDrop, but not centalised
managed environments
ensure passkeys only syunc to managed devices
stroe passkeys created for work in icloud keyachanein og manged accounts
proof the passkey has been created in managed device
managed passkeys could not been shared
Mac OS Venture and iOS 16 only
Want to print your doc? This is not the way.
Try clicking the ··· in the right corner or using a keyboard shortcut (