Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

Passkeys and phishing resistance: what IAM teams still need to fix


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 12324
Topic starter  

TL;DR: Passkeys replace reusable passwords with phishing-resistant cryptographic credentials, but Bitwarden argues that recovery paths, shared access, service accounts, and legacy sign-ins still leave organizations exposed. The shift makes authentication stronger, yet also exposes the broader identity stack that conventional login-focused security often ignores.

NHIMG editorial — based on content published by Bitwarden: phishing-resistant passkeys and the transition beyond passwords

Questions worth separating out

Q: How should security teams roll out passkeys without breaking account recovery?

A: Start with low-risk journeys, then define recovery as a controlled identity workflow rather than a convenience feature.

Q: Why do passkeys not eliminate the need for secrets management?

A: Because most organisations still rely on service accounts, API keys, shared credentials, and application integrations that do not use passkeys.

Q: What do security teams get wrong about passwordless authentication?

A: The most common mistake is treating passwordless as a user-experience upgrade instead of an identity control change.

Practitioner guidance

  • Map every fallback access path Document recovery codes, backup devices, shared credentials, and break-glass accounts alongside primary passkey sign-in.
  • Inventory non-human credentials Include service accounts, API keys, SaaS tokens, and integrations in the same identity inventory used for human users.
  • Bind recovery to governance Set approval, verification, and logging requirements for account restoration so that credential recovery is not easier to abuse than the primary authentication flow.

What's in the full article

Bitwarden's full blog post covers the operational detail this post intentionally leaves for the source:

  • How its vault model handles passkey storage, sync, and end-to-end encryption across trusted devices.
  • Practical transition guidance for keeping passwords, recovery codes, shared access, and secrets in scope during passwordless rollout.
  • Examples of how organisations can manage non-human access alongside passkeys without losing visibility into legacy credentials.
  • Product-level detail on how phishing protections and breach alerts fit into day-to-day credential hygiene.

👉 Read Bitwarden's guidance on passkeys, secrets, and passwordless transition →

Passkeys and phishing resistance: what IAM teams still need to fix?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 2 months ago
Posts: 11878
 

Passkeys improve authentication, but they do not solve identity governance. The industry keeps framing passwordless adoption as the destination, when it is really only one control layer. Recovery flows, shared credentials, and non-human access still determine whether identity is actually governed. The practitioner conclusion is simple: passwordless reduces phishing exposure, but governance only starts when the rest of the credential estate is visible.

A few things that frame the scale:

  • The average estimated time to remediate a leaked secret is 27 days, despite 75% of organisations expressing strong confidence in their secrets management capabilities, according to the State of Secrets in AppSec.
  • Only 44% of developers are reported to follow security best practices for secrets management, which helps explain why passwordless rollouts do not eliminate the broader credential problem.

A question worth separating out:

Q: How do organisations know whether passkey adoption is actually reducing risk?

A: Track the share of accounts that are passkey-enrolled, the proportion of sign-ins still using passwords, and the number of recovery events that bypass the primary factor. If password use remains high or recovery is frequent, the programme is still in transition rather than truly passwordless.

👉 Read our full editorial: Phishing-resistant passkeys expose the limits of password-era IAM



   
ReplyQuote
Share: