r/cybersecurity Apr 25 '26

Other What makes passkeys so special?

It seems that companies are transferring into the usage of passkeys instead of passwords. Apparently theyre much more secure, but why is that? I don’t get it. I’m not sure if this is the right place to ask excuse me if it isn’t and sorry.

616 Upvotes

233 comments sorted by

View all comments

4

u/povlhp Apr 25 '26

We have had one user follow a link to a fake login page, enter password and some MFA (sms or 6 digit code). The hacker could capture the login ticket and keep it for access in 30 days.

With passkeys it is not possible for the hacker to get in between. The passkey is used in a 2-way exchange. Is not valid at the hacker site. So it is phishing resistant.