Passwordless track · 3 min
Why a passkey cannot be phished
A key pair, a challenge and one detail that stops fake sites.
The idea
1A passkey is a key pair
Your device keeps a private key that never leaves it. AuthMantra stores only the matching public key.
2Your device signs a challenge
At sign-in, AuthMantra sends a random challenge. Your device signs it after Face ID, Touch ID, Windows Hello or a PIN.
3The site name is part of the signature
The signature covers the real site name. A look-alike page cannot get a signature that works on the real one.
4So there is nothing to hand over
No password or code is typed anywhere. A fake page has nothing to capture and no passkey to offer.
Try it
Spot the fake page
Three sign-in pages. One is real. Pick the real one, then try a passkey on each.
This exercise needs JavaScript. Here is the answer key.
- app.authrnantra.com (fake): The address says authrnantra: an r and an n pretending to be an m.
- app.authmantra.com (real): The address is the real site, and the passkey is offered.
- login-authmantra.example.net (fake): The brand is a prefix on an unrelated site.
Check yourself
1 of 3 A fake login page asks for your passkey. What happens?
2 of 3 What does AuthMantra store for a passkey?
3 of 3 Why is a six-digit code weaker against phishing?
Answer key
- A fake login page asks for your passkey. What happens? Your device offers no passkey for the wrong site. Passkeys are bound to the site they were created for.
- What does AuthMantra store for a passkey? The public key. It can verify signatures but cannot create them.
- Why is a six-digit code weaker against phishing? A person can type it into a fake page. The attacker can relay it to the real site in time.
Go deeper
Field notes
Runbooks
Passkey rollout playbookRunbookBlueprints
PasswordlessBlueprintLexicon