Opaque, Interoperable Passkey Records (and a Go API)

This article proposes a standardized, interoperable format for passkey records to simplify server-side implementation. By treating passkey data as opaque strings, developers can integrate phishing-resistant authentication more easily across different database schemas.
Why it matters
Standardizing passkey storage is critical for the widespread adoption of passwordless security, which is essential for combating modern phishing threats.
Passkeys are the most important thing happening in information security right now because they are the only principled solution to the overwhelming effectiveness of phishing attacks. Just like memory safety is the only principled solution to memory corruption attacks.
Unfortunately, implementing them on the server side can appear more complex than using password hashes. Part of this is unavoidable because passkeys require interaction with the browser to get their phishing resistance properties. Part of it, however, could be abstracted away a little more effectively by defining interoperable passkey record encodings.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in