Recent academic research has revealed new insights into the security considerations surrounding FIDO2 authentication and synced passkeys, highlighting both the strengths and potential vulnerabilities of current authentication systems. The analysis comes at a time when major technology companies are increasingly adopting passkey technology, with Microsoft reporting login times three times faster than traditional passwords.

Formal methods analysis of the FIDO2 standard has revealed potential weaknesses in the underlying protocols that warrant attention from security professionals. The research particularly focuses on the implementation of synced passkeys, which enable cross-device access through passkey providers. These findings support recent expert warnings about interoperability concerns in FIDO2 implementations.


More

Vox: A world without passwords is in sight

Thanks to passkeys, you may not need to remember a password ever again. Apple thinks…

Read More →

Android Authority: Passkeys make switching to Android more challenging, but not for long

The FIDO Alliance is aware of passkey lock-in, and it’s actively working to address that:…

Read More →

ZDNet: Passkeys take yet another big step towards killing off passwords

One of the drawbacks to passkeys is that currently there’s no way to import or…

Read More →