
Tech
How passkeys work: WebAuthn, phishing and why you can't move them
A passkey is a password your device invents, never shows you, and refuses to hand to anyone, including you. That one property is why passkeys stop phishing, and it is also why a post called "I don't like passkeys" spent a day on top of Hacker News with 616 points and 605 comments. Here is how passkeys work under the hood, and why "un-phishable" and "un-movable" are the same word.
TL;DR
A passkey is a per-site key pair. The server stores only the public key, so a d...
Read the full discussion on Dev.to
This article was aggregated from Dev.to. Click to join the conversation.
View on Dev.to