Episode 217 - GluuFederation/identerati-office-hours GitHub Wiki
Title: 5 billion passkeys. Are we done yet?
- Host: Mike Schwartz, Founder/CEO Gluu
- Guest: Rolf Lindemann, VP Products at OneSpan
Channels
Description
Topics to cover: Adoption, Measurement, Recovery and migration, Residual threats, Transaction security, Phishing-resistant accounts not only phishing resistant credentials, relationship to digital credentials!
Homework
- Blog by Rolf: Authentication's next era: From operating controls to orchestrating trust
- Webinar: The Great Authentication Bake-Off: Passkeys Edition
- Article: Pass the Passkey: A Novel Attack Surface in Passwordless Authentication
Takeaways
- ⚡ Five billion passkeys is not the finish line. The better metric is phishing-resistant accounts, i.e. accounts with no password, OTP, magic-link, or weak recovery path left behind.
- ⚡ Recovery is still the Achilles heel. Passkeys dramatically reduce recovery frequency, especially when synced, but recovery never reaches zero. Digital credentials could provide a stronger recovery and identity-proofing mechanism than email links or selfie-plus-ID.
- ⚡ Authentication is only half the problem. High-risk transactions need to bind the user's approval to the actual transaction details—“what you see is what you sign.” FIDO/WebAuthn transaction-confirmation support is still evolving.
- ⚡ Passkey UX is becoming the hard part. Multiple credential managers, browsers, security keys, plugins, and recovery paths create hidden complexity. Rolf argued for platform-mediated credentials, simpler flows, and identifier-first authentication to reduce user decisions and dead ends.
- ⚡ Passkeys and digital credentials are complementary. A useful division of labor is digital credentials for registration/identity proofing, passkeys for returning authentication. And the next frontier is extending this trust model to AI agents and verifiable delegation.