USENIX Security2026Top-tier venue
“Maybe there’s only one passkey?”: Challenges Investigating and Remediating Adversarial Passkeys
Alaa Daffalla, Grace Myers, Rosanna Bellini, Thomas Ristenpart, Nicola Dell
Abstract
Passkeys are being actively rolled out by hundreds of web services who market them as a promising passwordless authentication method. However, it remains unclear whether people understand how to manage passkeys as part of their broader account security management, particularly in the aftermath of account compromise. We conducted a qualitative lab-based study that explores how people investigate and remediate suspicious activity when passkeys are used as a vector for illicit account access on three popular, passkey-supporting services: Google, PayPal, and LinkedIn. We recruited 31 participants with diverse technical backgrounds and tasked them with: (1) investigating a potential incident of compromise involving passkeys and (2) taking steps needed to re-secure the account.
Participants struggled to manage passkeys within account security settings and on devices, even when supported by service-provided email notifications, account security interfaces (ASIs), and streamlined wizards. The design and content of notifications and ASIs were often confusing or unclear, while the service-provided wizards were incomplete or misleading. This resulted in participants missing key steps required to discover adversarial passkeys and fully secure the account to prevent continued adversarial access. We discuss design implications and opportunities for future work to improve passkey management tools in ways that better support people experiencing account compromise.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f81947fe-89f8-42d4-bd47-a9ae5fd3ff85Builds on11
- SoK: Hate, Harassment, and the Changing Landscape of Online AbuseKurt Thomas, Devdatta Akhawe, Michael D. Bailey, Dan Boneh et al.S&P 2021 · 175 citations
- Is FIDO2 the Kingslayer of User Authentication? A Comparative Usability Study of FIDO2 Passwordless AuthenticationSanam Ghorbani Lyastani, Michael Schilling, Michaela Neumayr, Michael Backes et al.S&P 2020 · 124 citations
- Clinical Computer Security for Victims of Intimate Partner ViolenceSam Havron, Diana Freed, Rahul Chatterjee, Damon McCoy et al.USENIX Security 2019 · 118 citations
- SoK: A Framework for Unifying At-Risk User ResearchNoel Warford, Tara Matthews, Kaitlyn Yang, Omer Akgul et al.S&P 2022 · 101 citations
- Provable Security Analysis of FIDO2Manuel Barbosa, Alexandra Boldyreva, Shan Chen, Bogdan WarinschiCRYPTO 2021 · 42 citations
Related papers
- No Password, No Problem? A Large-Scale Field Study of Passkey Adoption and UsageTobias Reittinger, Günther PernulS&P 2026 · 1 citation
- A Framework for Abusability Analysis: The Case of Passkeys in Interpersonal Threat ModelsAlaa Daffalla, Arkaprabha Bhattacharya, Jacob Wilder, Rahul Chatterjee et al.USENIX Security 2025
- Was This You? Investigating the Design Considerations for Suspicious Login NotificationsSena Sahin, Burak Sahin, Frank LiNDSS 2025
- Moving Beyond Passwords: Investigating the Effect of Digital Nudges on Passkey AdoptionTobias Reittinger, Magdalena Glas, Günther PernulCHI 2026 · 2 citations
- The State of Passkeys: Studying the Adoption and Security of Passkeys on the WebLouis Jannett, Andreas Mayer, Maximilian Westers, Vladislav Mladenov et al.USENIX Security 2026
