Executive Summary
WebAuthn’s resistance to phishing and replay comes from cryptographic properties passwords never had. Our research shows that when the surrounding implementation falls short, including Windows, Entra ID, and password managers, those guarantee quietly degrade. We call this category of attacks Pass-the-Passkey, because the failure modes mirror classic identity attacks like Pass-the-Hash and NTLM Relay.
The Path Forward
Passkeys are still a major improvement over passwords, and we encourage organizations to adopt them. For high-value accounts, we recommend device-bound passkeys over synced ones, with attestation enforced so only genuine, approved authenticators are used.