passkeys
3 posts
Article
The attacker skips your login and steals the cookie
Passkeys defeat credential phishing but not session hijacking. How token replay, passkey enrollment, and weak recovery bypass phishing-resistant MFA.
Article
Passkeys don't stop account takeover
Passkeys stop phishing, but retained recovery paths and synced platform vaults mean the weakest accepted path still defines account takeover risk.
Article
SMS 2FA was never authentication
Microsoft is replacing SMS one-time codes with passkeys. M. Hale defines what failed, why it failed, and where the boundary still leaks.