Skip to content
AuthMantraPraxis
authmantra.com ↗Start free trial

Passwordless track · 3 min

Why a passkey cannot be phished

A key pair, a challenge and one detail that stops fake sites.

The idea

  1. 1A passkey is a key pair

    Your device keeps a private key that never leaves it. AuthMantra stores only the matching public key.

  2. 2Your device signs a challenge

    At sign-in, AuthMantra sends a random challenge. Your device signs it after Face ID, Touch ID, Windows Hello or a PIN.

  3. 3The site name is part of the signature

    The signature covers the real site name. A look-alike page cannot get a signature that works on the real one.

  4. 4So there is nothing to hand over

    No password or code is typed anywhere. A fake page has nothing to capture and no passkey to offer.

Try it

Spot the fake page

Three sign-in pages. One is real. Pick the real one, then try a passkey on each.

This exercise needs JavaScript. Here is the answer key.

  • app.authrnantra.com (fake): The address says authrnantra: an r and an n pretending to be an m.
  • app.authmantra.com (real): The address is the real site, and the passkey is offered.
  • login-authmantra.example.net (fake): The brand is a prefix on an unrelated site.

Check yourself

1 of 3 A fake login page asks for your passkey. What happens?

2 of 3 What does AuthMantra store for a passkey?

3 of 3 Why is a six-digit code weaker against phishing?

Answer key
  1. A fake login page asks for your passkey. What happens? Your device offers no passkey for the wrong site. Passkeys are bound to the site they were created for.
  2. What does AuthMantra store for a passkey? The public key. It can verify signatures but cannot create them.
  3. Why is a six-digit code weaker against phishing? A person can type it into a fake page. The attacker can relay it to the real site in time.