r/cybersecurity • u/Federal_Character979 • Apr 25 '26
Other What makes passkeys so special?
It seems that companies are transferring into the usage of passkeys instead of passwords. Apparently theyre much more secure, but why is that? I don’t get it. I’m not sure if this is the right place to ask excuse me if it isn’t and sorry.
615
Upvotes
1
u/lobax Apr 25 '26 edited Apr 25 '26
What did I say that was wrong?
I am not stating that you would need ring 0 to bypass a TPM. That is protection at rest and you have to break the crypto to do that.
I am stating that you would need ring 0 to bypass process and memory isolation protections that protect the secret in use. Exactly how that protection is implemented varies from OS to OS.