
How passkeys work: WebAuthn, phishing and why you can't move them
How passkeys work: one key pair per site, a signed challenge, and an origin the browser writes. Why that stops phishing, and why it locks you in.
Tag archive

How passkeys work: one key pair per site, a signed challenge, and an origin the browser writes. Why that stops phishing, and why it locks you in.
Tim Cappalli co-edits the WebAuthn specification. On February 27 he published a post titled "Please,...

A code-first guide to adding WebAuthn passkey registration and login to a NestJS and PostgreSQL API: the schema, the service, the controller, and the compliance and hardening details most tutorials skip.

Passkeys are replacing passwords. Cognito’s Hosted UI supports them out of the box. But Cognito also...
A password is a secret two parties have to keep at the same time: you, and every server you ever...
Ein Passwort ist ein Geheimnis, das zwei Parteien gleichzeitig aufbewahren müssen: Sie selbst und...

WebAuthn's own demo code creates a credential the browser can't find on its own — so your passkey button quietly turns into a fancier security key instead of an actual passwordless sign-in. One option fixes it.
Introduction: The Security Gap in JavaScript Screen Locks Existing JavaScript screen lock...
Passkeys in India (2026): add WebAuthn login to iOS and Android apps Summary. Visa Payment...
Passkeys eliminate password vulnerabilities through cryptographic authentication. Learn why major tech companies are ditching passwords for good.
The WebAuthn PRF extension turns a passkey into an encryption keystore. How pknotes derives keys from a Face ID tap, and what that can't protect.

Originally published at norvik.tech Introduction Explore the implications of...