USENIX Security2026Top-tier venue
The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web
Louis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov, Christian Mainka, Jörg Schwenk
Abstract
Passkeys provide a secure and phishing-resistant authentication method based on FIDO2 and WebAuthn. They have recently gained popularity, with an increasing number of websites adopting them. Nevertheless, a comprehensive security analysis that evaluates such websites at scale has not been fully addressed. We present PASSKEYS-RADAR, a continuously updated dataset that tracks the deployment of passkeys on the Internet since 2021. To build this dataset, we aggregated diverse sources, including community directories, Tranco 1M, CrUX 18M, and historic Internet archive data. We analyzed the collected data of 872 passkey-enabled websites and shed light on how passkeys are implemented and managed. We identify major differences in how websites allow users to add or delete passkeys and find that websites request authenticators to use deprecated cryptographic algorithms. To perform a comprehensive security evaluation of passkeyenabled websites, we developed PASSKEYS-ATTACKER. The tool allows for precise manipulation of WebAuthn messages at every step of the protocol and integrates 15 attack types of which 10 were not covered in previous work. Among them, 2 attack types have critical CVSS scores. We discovered them on 18 out of 103 evaluated websites. These attacks take over user accounts, delete their passkeys, or lock them out of their accounts. Nearly half of the tested sites (53) were vulnerable to at least one attack with a high CVSS score, exposing users to threats such as phishing and session fixation. User Relying Party Client Authenticator Relying Party " Register passkey" creationOptions = rp id , rp name , user id , user name , challenge Call API: creationOptions Request Attestation: hash(clientData), rp id&name , user id&name
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext e9f4d39d-940f-49da-849b-5d054b4d18bdCited by top-tier papers1
Ask how each one uses itBuilds on16
- Tranco: A Research-Oriented Top Sites Ranking Hardened Against ManipulationVictor Le Pochat, Tom van Goethem, Samaneh Tajalizadehkhoob, Maciej Korczynski et al.NDSS 2019 · 826 citations
- A Side Journey To TitanThomas Roche, Victor Lomné, Camille Mutschler, Laurent ImbertUSENIX Security 2021 · 49 citations
- "It's Stored, Hopefully, on an Encrypted Server": Mitigating Users' Misconceptions About FIDO2 Biometric WebAuthnLeona Lassak, Annika Hildebrandt, Maximilian Golla, Blase UrUSENIX Security 2021 · 48 citations
- Provable Security Analysis of FIDO2Manuel Barbosa, Alexandra Boldyreva, Shan Chen, Bogdan WarinschiCRYPTO 2021 · 42 citations
- Is Real-time Phishing Eliminated with FIDO? Social Engineering Downgrade Attacks against FIDO ProtocolsEnis Ulqinaku, Hala Assal, AbdelRahman Abdou, Sonia Chiasson et al.USENIX Security 2021 · 42 citations
Related papers
- Why Aren't We Using Passkeys? Obstacles Companies Face Deploying FIDO2 Passwordless AuthenticationLeona Lassak, Elleen Pan, Blase Ur, Maximilian GollaUSENIX Security 2024 · 35 citations
- Evaluating the Security Posture of Real-World FIDO2 DeploymentsDhruv Kuchhal, Muhammad Saad, Adam Oest, Frank LiCCS 2023 · 13 citations
- A Security and Usability Analysis of Local Attacks Against FIDO2Tarun Kumar Yadav, Kent E. SeamonsNDSS 2024
- The Passkey Promise: A Comparative Usability Study of MFA MethodsErwin Kupris, Thomas SchreckS&P 2026
- A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat ModelsAlaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee et al.USENIX Security 2025
