RC RANDOM CHAOS

passkeys

3 posts

The attacker skips your login and steals the cookie
Article

The attacker skips your login and steals the cookie

Passkeys defeat credential phishing but not session hijacking. How token replay, passkey enrollment, and weak recovery bypass phishing-resistant MFA.

Passkeys don't stop account takeover
Article

Passkeys don't stop account takeover

Passkeys stop phishing, but retained recovery paths and synced platform vaults mean the weakest accepted path still defines account takeover risk.

SMS 2FA was never authentication
Article

SMS 2FA was never authentication

Microsoft is replacing SMS one-time codes with passkeys. M. Hale defines what failed, why it failed, and where the boundary still leaks.