Open cardosec

Case 766CC4 · Identity & AD · L2 Practitioner

Passkeys and FIDO2

Practise as: Deep dive · Explain it
  1. 01 Context
  2. 02 Mechanism
  3. 03 Lessons
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Public-key credential per site: the private key stays on the device or in a synced keychain
  2. Origin binding: the browser signs a challenge scoped to the real domain, so phishing sites get nothing usable
  3. No shared secret stored server-side, so a database breach leaks only public keys
  4. Synced passkeys trade some device-binding assurance for recoverability; device-bound keys suit admins
  5. Rollout challenges: account recovery flows, shared devices, and legacy apps that cannot do WebAuthn

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.