Vai al contenuto principale
Torna al wiki
Account Security

What Is a Passkey?

Ultimo aggiornamento il 4 agosto 2026

A passkey is a cryptographic login credential that replaces the password entirely. Built on the FIDO2 and WebAuthn standards, it consists of a key pair: the private key stays on the user's device (or synced through their platform account), and the public key sits with the service. Signing in means the device proves possession of the private key, unlocked locally by fingerprint, face, or PIN, and the crucial property is that the credential is bound to the website's real origin. A passkey created for a genuine domain simply does not respond on a look-alike domain, which retires the entire category of attacks that begin with "type your password into this convincing page."

How passkeys change the attack surface

Passwords fail in bulk: they leak in breaches, get reused across services, and feed the credential stuffing economy that turns one site's breach into every site's problem. Passkeys break each link of that chain. There is no shared secret on the server worth stealing: a breached database of public keys authenticates nobody. There is nothing to reuse, since every service gets its own pair. And there is nothing to phish, because origin binding makes the credential unusable on fraudulent domains, the property that defeats the real-time relay proxies cataloged under MFA bypass, which comfortably defeat one-time codes. Security guidance therefore classes passkeys with hardware keys as phishing-resistant authentication, the tier above app-generated codes in the two-factor authentication ladder.

The honest caveats

Synced passkeys concentrate trust in the platform account that syncs them: an attacker who takes over that account inherits its passkeys, which makes the recovery flow of the ecosystem account the new crown jewel. Account recovery in general remains the soft flank: a service that falls back to email links or SMS codes when the passkey is "lost" has rebuilt the phishable path beside the unphishable one, and attackers ask for the fallback by name. Adoption friction is real too: cross-ecosystem sign-ins, shared devices, and enterprise provisioning still produce edge cases, which is why most deployments run passkeys alongside legacy factors for years, leaving the weakest enabled path as the effective security level.

What passkeys leave for bot defense

Passkeys authenticate identity; they do not establish that traffic is human. Authentication endpoints still absorb automated abuse that never intends to log in legitimately: credential-stuffing runs against the password fallback, enumeration probing, recovery-flow abuse, and scripted registration of throwaway accounts that enroll passkeys like anyone else. Keeping that machine traffic away from the ceremony is the role of human verification such as CaptchaFox in front of login, registration, and recovery flows, so the strong credential's remaining weak edges, fallback and recovery, are at least not exposed to attack at machine scale. The pairing is complementary: passkeys make the authenticated path phishing-resistant, and bot defense keeps the paths around it from becoming the new entrance.

Informazioni su CaptchaFox

CaptchaFox è una soluzione conforme al GDPR con sede in Germania che protegge siti web e applicazioni da abusi automatizzati, come bot e spam. Il suo approccio distintivo e multilivello utilizza segnali di rischio e sfide crittografiche per facilitare un processo di verifica robusto. CaptchaFox consente ai clienti di essere operativi in pochi minuti, non richiede gestione continua e offre alle aziende una protezione duratura.

Per saperne di più su CaptchaFox, contattaci o inizia a integrare la nostra soluzione con una prova gratuita.

Termini correlati

What Is Account Takeover (ATO)?

Account takeover is a form of identity fraud in which an attacker gains control of a legitimate user account and exploits it for financial gain.

Continua a leggere
What Is an OTP Bot?

An OTP bot is an automated calling or messaging tool that tricks victims into revealing one-time passcodes, letting attackers bypass two-factor authentication.

Continua a leggere
What Is Credential Stuffing?

Credential stuffing is an automated attack that tests stolen username-password pairs from data breaches against login forms to take over accounts.

Continua a leggere
What Is MFA Bypass?

MFA bypass covers the techniques attackers use to defeat multi-factor authentication: phishing proxies, push fatigue, OTP interception, and token theft.

Continua a leggere

Combatti i bot e proteggi i dati dei tuoi utenti.

Non dare ai truffatori e agli spammer alcuna possibilità e proteggi il tuo sito web con CaptchaFox oggi.

CaptchaFox protegge i siti web su desktop e dispositivi mobili