Meta tags:
description= You’ve probably seen that little prompt that says “Sign in with Face ID” or “Use a passkey” instead... Tagged with security, api, webdev, discuss.;
keywords= security, api, webdev, discuss, software, coding, development, engineering, inclusive, community;
Headings (most frequently used words):
the, what, more, passkeys, explained, simply, dev, community, problem, with, passwords, exactly, is, passkey, why, it, secure, under, hood, webauthn, and, fido2, if, lose, my, phone, how, to, use, them, today, conclusion, top, comments, 34, from, thomas, bonnet,
Text of the page (most frequently used words):
the (98), like (55), and (50), comment (50), you (37), your (27), link (22), passkeys (22), for (21), dev (20), that (20), #thomas (20), this (20), with (19), key (19), #password (19), bonnet (18), hide (18), copy (18), jul (18), joined (17), follow (17), menu (17), passkey (17), reply (16), button (16), dropdown (16), expand (16), collapse (16), likes (15), may (13), but (12), google (12), work (11), create (10), account (10), 2026 (10), location (10), via (10), one (10), more (9), comments (9), have (9), security (9), device (9), which (9), server (9), web (8), pronouns (8), developer (8), recovery (8), com (8), webauthn (8), share (7), software (7), use (7), consultant (7), him (7), france (7), mainly (7), everything (7), here (7), user (7), site (7), public (7), phishing (7), how (6), 2017 (6), iam (6), ariovis (6), french (6), touches (6), volunteer (6), admin (6), mod (6), learn (6), nuxt (6), moment (6), databases (6), addict (6), cappuccino (6), music (6), all (6), system (6), apple (6), secure (6), they (6), even (6), same (6), log (5), will (5), been (5), never (5), secret (5), than (5), building (5), also (5), private (5), question (5), was (5), what (5), sync (5), them (5), just (5), domain (5), nothing (5), can (5), phone (5), new (5), website (5), community (4), other (4), source (4), personal (4), webdev (4), well (4), hidden (4), post (4), report (4), some (4), only (4), thanks (4), instead (4), has (4), when (4), authentication (4), cryptography (4), not (4), fido2 (4), voltagegpu (4), years (4), microsoft (4), using (4), answer (4), access (4), add (4), based (4), end (4), windows (4), signature (4), challenge (4), fullscreen (4), mode (4), credentials (4), their (3), open (3), code (3), about (3), education (3), manage (3), apps (3), abuse (3), are (3), want (3), still (3), sign (3), cheesidibbl (3), jamesroy (3), thank (3), writing (3), stratagems (3), asymmetric (3), model (3), point (3), xulingfeng (3), while (3), credential (3), across (3), users (3), traditional (3), publiflow (3), real (3), default (3), exactly (3), bound (3), created (3), architect (3), engineering (3), dirk (3), mattig (3), service (3), great (3), two (3), reuse (3), time (3), neithergalax (3), part (3), passwords (3), because (3), support (3), multiple (3), jun (3), founder (3), lolo (3), remember (3), rza (3), asadov (3), side (3), mia (3), keller (3), weak (3), verification (3), network (3), mustafa (3), erbay (3), store (3), name (3), steal (3), icloud (3), standard (3), resistant (3), pair (3), browser (3), 2fa (3), manager (3), uint8array (3), w3c (3), place (2), where (2), conduct (2), database (2), accounts (2), discuss (2), keep (2), blog (2), astro (2), few (2), improving (2), seo (2), javascript (2), further (2), confirm (2), visible (2), view (2), find (2), full (2), now (2), solid (2), breakdown (2), series (2), shared (2), entirely (2), making (2), better (2), flow (2), email (2), implementing (2), cross (2), flows (2), handles (2), relies (2), underlying (2), implementation (2), any (2), fallback (2), synced (2), mfa (2), local (2), good (2), cryptographically (2), aug (2), recommended (2), should (2), think (2), per (2), explanation (2), biggest (2), related (2), many (2), technical (2), around (2), isn (2), technology (2), apiarium (2), save (2), data (2), must (2), devices (2), türkiye (2), project (2), let (2), next (2), yes (2), limited (2), its (2), back (2), usually (2), social (2), protonpass (2), article (2), behind (2), fingerprint (2), physical (2), backup (2), design (2), travel (2), over (2), keychain (2), won (2), face (2), hello (2), settings (2), already (2), offer (2), paypal (2), under (2), lose (2), yubikey (2), synchronization (2), written (2), principle (2), generates (2), biometrics (2), sends (2), exit (2), enter (2), required (2), userverification (2), provided (2), publickey (2), navigator (2), await (2), const (2), type (2), spec (2), api (2), fake (2), leaked (2), breach (2), tied (2), transmitted (2), every (2), ever (2), stored (2), chip (2), verizon (2), problem (2), explained (2), simply (2), search (2), coders, stay, date, grow, careers, made, love, 2016, ruby, rails, built, powers, inclusive, communities, forem, terms, privacy, policy, mlh, shop, free, postgres, contact, showcase, organization, advertise, help, tracks, videos, challenges, home, space, development, career, own, css, tutorial, tips, beginners, productivity, progressive, pwas, pwabuilder, pwa, from, actions, consider, blocking, person, reporting, child, sure, become, permalink, logged, visitors, author, out, discussion, read, really, understood, nice, looking, way, frame, narrative, context, ongoing, stories, replace, fits, expected, gold, too, his, xulingfengcn, gmail, testing, storyteller, ancient, chinese, military, tactics, meet, modern, meltdowns, 15yr, test, framework, surprisingly, tricky, dealing, recently, noticed, beautifully, syncing, ecosystem, heavily, vendor, found, reliable, strategies, enterprise, environments, might, machines, seems, transition, period, going, require, supporting, both, quite, working, systems, appreciate, simplify, removing, reliance, managers, storage, interesting, see, finally, gaining, traction, especially, combined, hardware, backed, keys, enclaves, projects, involving, look, securely, offload, cryptographic, operations, gpu, align, kind, architecture, oct, 2025, sealed, gpus, confidential, introduction, said, achieved, phd, mathematics, agent, tamer, coding, hobby, profession, corporate, sme, sector, transitioning, approach, rely, ecosystems, managing, independently, questions, compared, strong, setup, advantage, reducing, human, risks, neither, chasing, hype, nor, titles, exploring, galax, curiosity, consistency, world, commit, curious, people, actually, shipped, production, hard, don, redesign, authenticators, hurdle, anymore, adoption, madrid, infra, layer, providers, predictable, credits, smart, routing, picks, text, image, voice, transcription, proton, pass, almost, ago, developed, widely, onboarding, getting, anyway, least, losses, 2024, meetvap, azerbaijan, national, oil, academy, antalya, decades, financial, payments, cybersecurity, product, ownership, international, team, leadership, considering, wondering, strategy, pattern, loses, freelance, stack, clean, scalable, sharing, journey, collaborate, totally, thing, story, practice, overall, often, process, falls, sms, attackers, target, path, itself, designed, level, devops, builder, bursa, infrastructure, burncpu, mustafaerbay, dismiss, preview, submit, templates, quickly, faqs, snippets, template, trusted, subscribe, top, affiliate, means, receive, commission, decide, through, additional, cost, helps, cover, hosting, fees, aren, represent, complete, shift, offers, option, significantly, faster, current, recoverable, loss, does, conclusion, somewhere, useful, different, platforms, encrypted, need, operating, ask, touch, passcode, click, typical, workflow, services, github, amazon, gone, step, today, regain, restored, doesn, works, compatible, advice, put, eggs, basket, although, there, android, chrome, encrypts, ios, macos, stumps, everyone, topic, resonates, entire, single, failure, applies, since, 2022, added, hassles, after, theft, unlocking, verify, libraries, node, most, simplewebauthn, get, assertion, existing, authenticatorselection, es256, alg, pubkeycredparams, displayname, example, mysupersite, super, creating, client, looks, diagram, registration, technically, broader, promoted, fido, alliance, whose, members, include, yubico, browsers, expose, hood, performs, unlike, impossible, intercept, faith, explains, very, paypa1, linked, unlocked, memorized, managed, stores, useless, attacker, event, exact, vulnerable, unique, reusable, sites, login, why, secrets, black, white, phish, random, number, signs, verifies, match, authenticated, hand, sent, leaves, iphone, mac, directly, usb, such, tpm, enclave, computer, token, ssh, generated, connect, fundamental, vulnerability, remains, could, accidentally, investigations, perfectly, mimics, without, realizing, minor, issue, reminds, year, stolen, remain, among, leading, causes, hacking, worldwide, alongside, vulnerabilities, dbir, hacked, who, everywhere, tired, coming, ideally, hashed, points, best, probably, seen, little, prompt, says, field, warn, originally, published, thomasbnt, posted, mastodon, facebook, linkedin, copied, clipboard, pick, gem, boost, jump, fire, raised, hands, exploding, head, unicorn, reaction, close, powered, algolia, navigation, skip, content,
Text of the page (random words):
secure chip the secure enclave on iphone mac the tpm on windows or directly on the chip of a usb key such as a yubikey the public key on the other hand is sent to the website and stored on the server to log in the site sends you a challenge a random number your device signs it with the private key and the site verifies the signature using the public key if they match you re authenticated no secrets ever travel over the network only a signature it s written in black and white in the w3c webauthn spec nothing to steal nothing to phish why it s more secure password passkey shared secret transmitted with every login nothing is transmitted just a signature reusable across multiple sites unique per site tied to the domain vulnerable to phishing resistant to phishing tied to the exact domain can be leaked in the event of a server breach the server stores only the public key which is useless to an attacker must be memorized or managed via a manager unlocked via biometrics or a local code the key point a passkey is linked to the domain on which it was created if you go to paypa1 com instead of paypal com your device won t even offer the passkey it s the browser os that performs this verification not you google explains it very well unlike a password a passkey is cryptographically bound to the site for which it was created so it s impossible to intercept or reuse on a fake site they re resistant to phishing by design not because of the user s good faith under the hood webauthn and fido2 technically passkeys are based on the webauthn w3c standard which is part of the broader fido2 standard promoted by the fido alliance whose members include google apple microsoft and yubico it is this api that browsers expose via javascript to create and use credentials diagram of the registration flow based on the w3c webauthn spec creating a client side passkey looks like this const credential await navigator credentials create publickey challenge new uint8array 32 provided by the server rp name my super site id mysupersite com user id new uint8array 16 name thomas example com displayname thomas pubkeycredparams alg 7 type public key es256 authenticatorselection userverification required enter fullscreen mode exit fullscreen mode and to log in with an existing passkey const assertion await navigator credentials get publickey challenge new uint8array 32 provided by the server userverification required enter fullscreen mode exit fullscreen mode the server generates the challenge the browser handles all the biometrics and unlocking and sends you back a signature to verify on the server side libraries like simplewebauthn server in node js do most of the verification work what if i lose my phone this is the question that stumps everyone and if this topic resonates with you i ve already written an entire article on the hassles of 2fa after a phone theft the same single point of failure principle applies to passkeys since 2022 apple google and microsoft have added passkey synchronization on ios macos they sync via your icloud keychain on android chrome they sync via your google account using google password manager which encrypts everything end to end on windows via windows hello although cross device synchronization is even more limited there than with apple or google so if you lose your phone but regain access to your icloud or google account on a new device your passkeys will be restored as well you can also use a physical security key yubikey as a backup which doesn t sync but works on any compatible device exactly the same advice as for traditional 2fa never put all your eggs in one basket how to use them today more and more services already offer them google apple github microsoft paypal amazon x google has even gone a step further by making passkeys the default for personal accounts you ll usually find them in your account s security settings under access key or passkey the typical workflow go to the service s security settings click add an access key or create a passkey your browser or operating system will ask you to confirm using face id touch id windows hello or your phone s passcode that s it the next time you log in you won t need a password if you want to manage your passkeys somewhere other than your os s keychain useful if you re on multiple different platforms protonpass can also create and store them end to end encrypted in the same place as your passwords conclusion question answer what is it based on asymmetric cryptography private public key pair does the password travel over the network no never resistant to phishing yes by design domain bound technical standard webauthn fido2 device loss recoverable via icloud google sync or physical backup key passkeys aren t just a password hidden behind a fingerprint they represent a complete shift in the model nothing to remember nothing to steal if a service offers you the option to create one go for it it s significantly more secure and faster than your current password the protonpass link in this article is an affiliate link which means i may receive a commission if you decide to sign up through this link at no additional cost to you this helps me cover hosting and domain name fees thank you for your support top comments 34 subscribe personal trusted user create template templates let you quickly answer faqs or store snippets for re use submit preview dismiss collapse expand mustafa erbay mustafa erbay mustafa erbay follow system architect with 20 years in infrastructure building burncpu com an open source social network personal blog mustafaerbay com tr en tr location bursa türkiye work system architect devops open source builder joined may 9 2026 jul 28 dropdown menu copy link hide great explanation one thing i d add is that passkeys are only one part of the authentication story in practice the overall security of an account is often limited by its account recovery process if recovery falls back to weak email or sms verification attackers will usually target that path instead of the passkey itself authentication and recovery should be designed with the same level of security like comment like comment 7 likes like comment button reply collapse expand thomas bonnet thomas bonnet thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 jul 28 dropdown menu copy link hide yes totally like comment like comment 3 likes like comment button reply collapse expand mia keller mia keller mia keller follow freelance full stack developer building clean scalable web apps and sharing my dev journey let s collaborate on your next project joined jun 29 2026 jul 28 dropdown menu copy link hide great breakdown i ve been considering implementing passkeys for a side project but i keep wondering about account recovery what s your recommended strategy or fallback pattern when a user loses access to all their synced devices like comment like comment 3 likes like comment button reply collapse expand rza asadov rza asadov rza asadov follow more than two decades across software engineering financial technology payments cybersecurity product ownership and international team leadership location türkiye antalya education azerbaijan national oil academy pronouns he work founder as meetvap com joined jun 26 2024 jul 29 dropdown menu copy link hide some time ago developed system using passkeys widely and answer to your question is some secret question answer on onboarding and getting other data related to user via support anyway at least user must remember password also even if losses passkey devices at all like comment like comment 3 likes like comment button reply collapse expand thomas bonnet thomas bonnet thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 jul 28 dropdown menu copy link hide for me i use proton pass to save almost all my passkeys like comment like comment 3 likes like comment button reply collapse expand lolo lolo lolo follow building the infra layer around ai providers one key predictable credits smart routing picks the model for you text image voice transcription founder apiarium location madrid work founder apiarium joined jun 17 2026 jul 28 dropdown menu copy link hide i think the biggest hurdle now isn t the technology anymore it s adoption webauthn has been solid for years but many apps still default to passwords because they don t want to redesign recovery flows or support multiple authenticators curious how many people here have actually shipped passkeys in production was the technical implementation the hard part or was it the ux around recovery like comment like comment 2 likes like comment button reply collapse expand neithergalax neithergalax neithergalax follow neither chasing hype nor titles just exploring the os galax with curiosity consistency and real world building one commit at a time joined may 17 2026 aug 5 dropdown menu copy link hide great explanation of passkeys i have two questions compared with a strong password mfa setup is the biggest advantage of passkeys mainly the underlying cryptography or reducing human related risks like phishing and credential reuse also for users transitioning to passkeys what is the recommended approach should users rely on ecosystems like google apple microsoft to manage and sync them or think about managing passkeys independently per service like comment like comment 2 likes like comment button reply collapse expand dirk mattig dirk mattig dirk mattig follow it consultant software architect agent tamer 40 years of coding as a hobby 25 years of software engineering as a profession corporate sme public sector education phd in mathematics joined may 18 2026 aug 5 dropdown menu copy link hide good introduction thank you one question you said that a passkey is cryptographically bound to the site for which it was created how exactly is that achieved like comment like comment 2 likes like comment button reply collapse expand voltagegpu voltagegpu voltagegpu follow sealed gpus private ai confidential by default location france joined oct 11 2025 jul 28 dropdown menu copy link hide as a developer working with secure systems i appreciate how passkeys simplify authentication while improving security by removing reliance on password managers or local storage it s interesting to see fido2 webauthn finally gaining real traction especially when combined with hardware backed keys or secure enclaves on projects involving voltagegpu we also look at how to securely offload cryptographic operations to the gpu and passkeys align well with that kind of architecture like comment like comment 2 likes like comment button reply collapse expand publiflow publiflow publiflow follow joined jul 13 2026 jul 30 dropdown menu copy link hide implementing passkeys has been surprisingly tricky when dealing with cross device authentication flows i recently noticed that while webauthn handles the cryptography beautifully syncing the credential across a user s ecosystem still relies heavily on the underlying os vendor s implementation have you found any reliable fallback strategies for enterprise environments where users might not have a synced apple or google account on their work machines it seems like the transition period is going to require supporting both passkeys and traditional mfa for quite a while like comment like comment 2 likes like comment button reply collapse expand xulingfeng xulingfeng xulingfeng follow ai testing storyteller writing the 36 stratagems series ancient chinese military tactics meet modern ai system meltdowns 15yr qa building ai test framework email xulingfengcn gmail com pronouns he him his joined may 20 2026 jul 28 dropdown menu copy link hide solid breakdown i ve been looking for a way to frame passkeys in a narrative context for an ongoing series i m writing 36 stratagems ai security stories the asymmetric key model replace the shared secret entirely instead of making a better password fits a few of the stratagems better than i expected the recovery flow point in the comments is gold too thanks for writing this like comment like comment 2 likes like comment button reply collapse expand thomas bonnet thomas bonnet thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 jul 28 dropdown menu copy link hide thank you like comment like comment 2 likes like comment button reply collapse expand jamesroy jamesroy jamesroy follow joined jul 13 2026 jul 28 dropdown menu copy link hide nice like comment like comment 3 likes like comment button reply collapse expand thomas bonnet thomas bonnet thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 jul 28 dropdown menu copy link hide thanks you like comment like comment 2 likes like comment button reply collapse expand cheesidibbl cheesidibbl cheesidibbl follow joined jul 28 2026 jul 28 dropdown menu copy link hide i never really understood this but now i do thanks like comment like comment 2 likes like comment button reply collapse expand thomas bonnet thomas bonnet thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 jul 28 dropdown menu copy link hide thanks for read my post like comment like comment 1 like like comment button reply view full discussion 34 comments some comments may only be visible to logged in visitors sign in to view all comments some comments have been hidden by the post s author find out more code of conduct report abuse are you sure you want to hide this comment it will become hidden in your post but will still be visible via the comment s permalink hide child comments as well confirm for further actions you may consider blocking this person and or reporting abuse thomas bonnet follow french web developer mainly but touches everything volunteer admin mod here at dev i learn nuxt at this moment and databases addict to cappuccino and music location france pronouns he him work iam consultant ariovis joined may 5 2017 more from thomas bonnet progressive web apps pwas webdev pwa pwabuilder javascript a few tips for improving your seo webdev productivity beginners seo how to create your own personal bl...
|