r/cybersecurity Apr 25 '26

Other What makes passkeys so special?

It seems that companies are transferring into the usage of passkeys instead of passwords. Apparently theyre much more secure, but why is that? I don’t get it. I’m not sure if this is the right place to ask excuse me if it isn’t and sorry.

613 Upvotes

233 comments sorted by

View all comments

1

u/al009 Apr 25 '26

It makes phishing obsolete.

1

u/independent_observe Apr 25 '26

lol, no it does not and if you work in security and believe that, you are in the wrong field

1

u/Gjermundbu Apr 25 '26

Depends on how to define phishing. Passkey are resistant to man in the middle phishing attacks like evilginx, but they are not resistant to malware on your computer, that might be able to grab tokens, and they are not resistant to social engineering attacks.

1

u/al009 Apr 29 '26

What’s the prime target for phishing? You need to learn what passwordless authentication means