Breaking WebAuthn, FIDO2, and Forging Passkeys
Okay, but why does this even work? Forging Passkeys: Exploring the FIDO2 / WebAuthn Attack Surface Fri Jun 20 2025 authored by vmfunc Introduction Passwords are dying—slowly, awkwardly, and not without a fight. Large parts of the internet are already nudging users toward "passkeys", the marketing-friendly name for FIDO2 credentials that live on your phone, security key, or TPM. In theory passkeys solve phishing and credential-stuffing in one swoop. In practice... they might introduce a shin