Episode 217 - GluuFederation/identerati-office-hours GitHub Wiki

Title: 5 billion passkeys. Are we done yet?

Channels

Description

Topics to cover: Adoption, Measurement, Recovery and migration, Residual threats, Transaction security, Phishing-resistant accounts not only phishing resistant credentials, relationship to digital credentials!

Homework

Takeaways

  • ⚡ Five billion passkeys is not the finish line. The better metric is phishing-resistant accounts, i.e. accounts with no password, OTP, magic-link, or weak recovery path left behind.
  • ⚡ Recovery is still the Achilles heel. Passkeys dramatically reduce recovery frequency, especially when synced, but recovery never reaches zero. Digital credentials could provide a stronger recovery and identity-proofing mechanism than email links or selfie-plus-ID.
  • ⚡ Authentication is only half the problem. High-risk transactions need to bind the user's approval to the actual transaction details—“what you see is what you sign.” FIDO/WebAuthn transaction-confirmation support is still evolving.
  • ⚡ Passkey UX is becoming the hard part. Multiple credential managers, browsers, security keys, plugins, and recovery paths create hidden complexity. Rolf argued for platform-mediated credentials, simpler flows, and identifier-first authentication to reduce user decisions and dead ends.
  • ⚡ Passkeys and digital credentials are complementary. A useful division of labor is digital credentials for registration/identity proofing, passkeys for returning authentication. And the next frontier is extending this trust model to AI agents and verifiable delegation.

Livestream Archive