Skip to main content
The Better Architecture Is Biometric Assured Identity

Do Not Migrate Twice. Vishing Is Coming for Your Passkeys.

The next great cyberattack may not start with malware, a zero day, or someone furiously typing commands into a terminal. It may start with your phone ringing. “Hi, this is IT. We are completing the company’s mandatory passkey migration. Microsoft is changing its authentication requirements and your account still needs to be updated. I can walk you through it. It will only take two minutes.” That call is no longer hypothetical. Attackers are already using almost exactly this script. And they are not trying to steal your old MFA code anymore. They are after something much more valuable. They want to become your new passkey.

Kevin Surace
10 minute read
Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers Do Not Break Passkeys. They Just Trick the User.

Hackers are already adapting the same social engineering playbook that defeats MFA and authenticator apps. Soon, Phishing as a Service kits will handle the technical details for them. Token removes the manipulation paths that phone based passkeys leave open.

Kevin Surace
15 minute read
What are passkeys? Passkeys vs. Token

What Are Passkeys and Where They Fall Short

Passkeys are a genuine step forward from passwords. They use cryptographic key pairs instead of credentials you type and remember. The private key never leaves your device. The site you are logging into never sees it. There is nothing to phish, nothing to guess and nothing to leak in a breach. That matters. Most data breaches start with stolen or weak credentials. Passkeys remove that attack surface. But passkeys are not a complete solution for enterprise security. Several specific scenarios leave organizations exposed. This guide explains how passkeys work, where they are genuinely strong and where the gaps are.

Kevin Surace
4 minute read
1

Stay Identity Assured

Subscribe to The Assured Identity Brief for sharp insights on identity security, authentication, and the threats security leaders must stay ahead of.