Join our Newsletter — 33% off our NHI Course

Why do liveness checks matter in passwordless authentication?

Liveness checks make it harder to use photos, videos, masks or replayed samples as substitute biometrics. They do not prove the whole identity by themselves, but they materially reduce spoofing risk when biometrics are used for enrolment or step-up access. Without them, a strong factor can still authenticate a weak or false identity claim.

Why liveness checks change the security value of biometrics

Liveness checks add a verification layer that tries to distinguish a live person from a replayed, imitated, or generated presentation. In passwordless flows, that matters because biometrics are often used to reduce friction, not to become a complete identity proofing system. If the input can be spoofed, the control stops being a strong factor and becomes a weaker signal.

They are most important where biometrics are used for enrolment, device binding, or step-up access, because those are the moments when a spoofed sample can contaminate the trust chain. A face scan or voice sample that passes without liveness may still belong to the wrong person, or to no live person at all.

That is why strong passwordless systems treat liveness as part of the assurance package, not as a cosmetic add-on. The relevant baseline is NIST SP 800-63 Digital Identity Guidelines, which ties authenticator strength and biometric use to explicit assurance expectations.

What liveness checks do, and what they do not do

A liveness check reduces the chance that an attacker can authenticate with something captured from the real user, such as a photo, screen replay, deepfake video, mask, or synthetic sample. It may also force a better attack path, such as compromising the actual device or operating system rather than merely presenting a copy of the biometric trait.

It does not prove legal identity, employee status, account ownership, or long-term trust. It only raises the cost of impersonation at the point where the biometric is accepted. That distinction matters because biometric checks are often paired with passkeys, device possession, or account recovery flows, and each of those has different failure modes.

For teams rolling out passwordless sign-in, the practical question is whether the biometric is being used as a convenience factor on a trusted device, or as a primary gate for a high-value action. The strongest internal guidance on that distinction is in the Passwordless and Passkeys Guide, which covers how passkeys, FIDO2, and phishing-resistant authentication fit together in real deployments.

Where liveness failures become operationally expensive

The biggest risk is false acceptance at the wrong stage. If an enrolment flow accepts a spoofed face or voice sample, the system can bind a genuine credential to the wrong claimant and carry that error forward into future authentication events. If step-up access accepts a replayed sample, an attacker may escalate into a sensitive action even after initial sign-in protections have done their job.

This is why many real incidents involve not a broken password, but a broken trust assumption around the factor used after the password is gone. Biometric spoofing is especially dangerous when recovery, onboarding, or help-desk assisted resets rely on the same signal. The broader pattern is well illustrated in NHIMG’s MFA Guide, which shows how attackers bypass strong factors by attacking the process around them.

Liveness also affects user experience and failure rates. Too much friction increases fallback to weaker paths; too little rigor increases spoofing exposure. In practice, the control has to be tuned to the transaction value, the threat model, and the recovery design around it.

Risk and Threat Considerations

Biometric spoofing is attractive because it can defeat the appearance of strong authentication without first stealing the user’s password. Once a fake sample is accepted, the attacker may gain access through normal trust paths, and the failure is often hard to distinguish from a legitimate user session.

Failure mechanism: A presentation attack or replay sample passes the biometric matcher because the system does not sufficiently detect signs of liveness, device context, or injection. That can bind an account to the wrong person during enrolment or unlock step-up access during a session.

Impact: The result can be account takeover, fraudulent enrolment, weakened recovery assurance, or unauthorized actions that appear to come from a valid user. In high-value systems, the damage is amplified because the false trust persists after the initial bypass.

Standards & Framework Alignment

This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.

OWASP Non-Human Identity Top 10 addresses the attack and risk surface, while NIST SP 800-63, CIS Controls v8 and NIST SP 800-53 Rev 5 set the governance and control requirements practitioners need to meet.

Framework Control / Reference Relevance
NIST SP 800-63 Digital Identity Guidelines Biometric liveness and passwordless assurance are governed by authenticator and identity assurance guidance.
Recommendation — Align biometric use with assurance expectations and require phishing-resistant authenticators for sensitive access.
OWASP Non-Human Identity Top 10 NHI-04 — Insecure Authentication Liveness is part of preventing biometric authentication from accepting spoofed presentations.
NHI-05 — Overprivileged NHI If biometric step-up unlocks too much access, a single bypass has outsized impact.
NHI-01 — Improper Offboarding Passwordless recovery and enrolment paths can be abused after account lifecycle changes or compromised access.
Recommendation — Require anti-spoofing checks wherever biometrics help establish or step up authentication. Limit what a biometric step-up can authorize and keep high-risk actions behind stronger controls. Tie enrolment and recovery eligibility to current account state and revoke stale trust paths promptly.
CIS Controls v8 CIS-5 — Account Management Biometric authentication only works safely when accounts, recovery paths, and access rights are tightly governed.
Recommendation — Review account and recovery pathways so spoofed biometric access cannot persist unnoticed.
NIST SP 800-53 Rev 5 IA-9 — Identification and Authentication (Service and System Accounts) Passwordless systems often depend on non-human and device-backed authenticators that still need strong authentication assurance.
Recommendation — Authenticate device-backed services and authenticators with mechanisms that resist replay and impersonation.

Practitioner Guidance

What to verify: Check whether liveness is enforced at enrolment, re-authentication, and recovery, not just at initial sign-in. If biometrics are only used on managed devices, verify that the device trust signal and the biometric assurance level are aligned.

Decision rule: If a successful biometric unlock can authorize a sensitive transaction, treat liveness as a required control and pair it with phishing-resistant authentication and strong recovery restrictions. If the biometric only unlocks a local device but not the account, the assurance bar can be narrower.

Common mistake: Assuming “passwordless” automatically means “safer” without checking whether the fallback path, enrolment path, or account recovery path is weaker than the password flow it replaced.

Practitioner takeaway: Liveness checks matter most when they protect the trust boundary where a biometric becomes an authenticator; if that boundary is weak, the biometric can still validate the wrong claimant.