How to do vulnerability research on passkeys: an intro to FIDO2 & WebAuthn and where to start? π€π€π€ππ
Security researcher Geoff Robinson, in his presentation earlier this year, gave a good and very practical overview of the FIDO2 standard and WebAuthn from an offensive-security perspective. A hackerβs intro to passkeys!
Why FIDO2? Hardcoded passwords for IoT, SCADA, and areas like automotive and maritime are slowly fading out; in some countries, they are already illegal, including in the EU. FIDO2 has already replaced passwords in browsers and is moving into other areas as well.
The author argues and demonstrates that passkey security depends significantly on how passkeys are stored, configured, recovered, and integrated. Plus the complexity problem, plus implementation issues, plus... plus... :)
If you want to get your hands on new and fancy devices with FIDO2 authentication, start here. Enjoy the presentation and share it with your R&D guys - there are some interesting ideas for them as well.
More details:
Passkeys in the Wild [Youtube]: https://lnkd.in/du3G7Bik
Addressing Cybersecurity Challenges in the Automotive Industry [PDF]: https://fidoalliance.org/wp-content/uploads/2025/07/Addressing-Cybersecurity-Challenges-in-the-Automotive-Industry-7-2025-1.pdf


