Case 766CC4 · Identity & AD · L2 Practitioner
Passkeys and FIDO2
Practise as: Deep dive · Explain it
- 01 Context
- 02 Mechanism
- 03 Lessons
What a strong answer covers
Try it out loud first. Then check yourself:
- Public-key credential per site: the private key stays on the device or in a synced keychain
- Origin binding: the browser signs a challenge scoped to the real domain, so phishing sites get nothing usable
- No shared secret stored server-side, so a database breach leaks only public keys
- Synced passkeys trade some device-binding assurance for recoverability; device-bound keys suit admins
- Rollout challenges: account recovery flows, shared devices, and legacy apps that cannot do WebAuthn
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.