Join our Newsletter — 33% off our NHI Course

Passkeys and phishing-resistant authentication: are your controls ready?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: Passkeys are presented as a phishing-resistant alternative to passwords and OTPs, with up to 93% login success rates versus about 63% for traditional methods, according to OneSpan. The governance question is no longer whether passkeys work, but how to introduce them alongside existing authentication without creating inconsistent assurance across users and channels.

Editorial analysis by NHI Mgmt Group, based on content published by OneSpan: “Strengthen authentication with passkeys”.

By the numbers:

  • Passkeys deliver up to 93% login success rates versus about 63% for traditional methods, according to OneSpan.

Key questions

Q: How should security teams roll out passkeys without disrupting existing authentication flows?

A: Start with applications where phishing risk and user friction are both high, then introduce passkeys alongside current methods while you preserve enrolment, recovery, and audit continuity.

Q: Why do passkeys reduce phishing risk compared with passwords?

A: Passkeys are bound to the original website and use cryptographic proof instead of a reusable secret.

Q: What are the signs that a passkey rollout is creating inconsistent assurance?

A: Look for uneven adoption across user groups, repeated fallback to passwords or OTPs, and different recovery journeys for the same access tier.

Practitioner guidance

  • Define passkey eligibility by user and transaction risk Map which populations can use passkeys for routine sign-in and which access paths still require stronger step-up controls for sensitive actions.
  • Preserve password and OTP fallback governance during rollout Keep authentication policy consistent while passkeys are introduced alongside existing methods so assurance does not fragment across channels.
  • Differentiate synced and device-bound passkeys in policy Use separate assurance rules for portable passkeys and tightly bound authenticators, especially for privileged or high-risk workflows.

Bottom line: Passkeys change the authentication problem by removing reusable secrets from the primary sign-in flow.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 2 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21346
 

Passkeys remove the shared-secret attack surface that passwords and OTPs create. That changes the identity control conversation from protecting a reusable secret to governing possession and device-bound cryptographic proof. The practical consequence is that phishing resistance becomes a property of the authenticator flow, not a user behaviour problem.

A question worth separating out:

Q: How should security teams decide where to use syncable passkeys versus device-bound keys?

A: Use syncable passkeys where usability and scale matter most, but keep device-bound keys for privileged access, regulated workflows, and any application where the organisation must preserve a stronger device-to-credential binding. The decision should be based on assurance requirements, not user preference alone. If the workflow tolerates credential portability, syncable passkeys are reasonable. If it does not, hardware binding should stay mandatory.

👉 Read our full editorial: Passkeys strengthen phishing-resistant authentication without passwords


This post was modified 2 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.