Skip to content

Standard

WebAuthn

WebAuthn is a W3C standard for passwordless, phishing-resistant login using public-key credentials like passkeys, biometrics, or hardware security keys.

Known aliases

  • PublicKeyCredential
  • W3C Web Authentication
  • Web Authentication
  • Web Authentication API

Current stories

buildOne report1 publisher

Laravel's passkeys packages handle WebAuthn on the server and in the browser

Laravel's two first-party passkeys packages, laravel/passkeys and @laravel/passkeys, run WebAuthn registration and login, according to a dev.to tutorial. The tutorial's own config leaves password reset switched on, so adopting the stack adds passkeys next to passwords.

Publishers:dev.to

Reality

Evidence35
Adoption
Insufficient
Hype gap+30
Incentives
Insufficient
Confidence40
securityConfirmed3 publishers

Passkey enrollment becomes a persistence trick: $10,000 kit outlives the password reset

Abnormal says iAuthFlow v2 uses a phished Google session to register an operator-controlled passkey. The standard playbook of revoking sessions and resetting the password does not remove it.

Publishers:abnormal.aisecurityaffairs.comsecurityweek.com

Perspective Coverage

3 publishers
Builder
Builder 32%
Operator
Operator 60%
Investor
Investor 8%

Reality

Evidence52
Adoption15
Hype gap+12
Incentives55
Confidence58