Blog

How WebAuthn Changes the Identity Question

Password authentication forces detection systems to guess whether whoever is logging in is the account holder. Public-key authentication answers that question cryptographically, which changes what the surrounding detection is for.

The secret never leaves the device

Registration generates a key pair on the user's device, with the private key held in hardware and only the public key sent to the site.

Authentication is a challenge signed by that private key. The site verifies the signature against the stored public key, and nothing reusable ever crosses the network.

Because there is no shared secret, there is nothing for a server breach to leak and nothing for an interceptor to capture and replay.

Credentials are bound to one origin

Each key pair is scoped to the site it was created for, and the browser will only offer it to that origin. A key registered for one site cannot be used at another.

This eliminates the class of attack where a convincing imitation site collects a credential, because the browser refuses to produce a signature for the wrong origin regardless of how the page looks.

The check is performed by the browser rather than by the user, which is why it works where user vigilance consistently does not.

Detection's role moves to session risk

With authentication strong, the question stops being whether the credential is genuine and becomes whether this session should be trusted for what it is attempting.

That shifts attention to what happens after login: unusual actions, changes to recovery settings, and behaviour inconsistent with the account's history.

Device signals remain useful here, but as context for evaluating a session rather than as a substitute for identity evidence the site no longer lacks.

Recovery becomes the weak point

Keys are bound to devices, and devices are lost. Recovery paths must therefore exist, and those paths are usually weaker than the mechanism they restore access to.

Synchronised credentials held in platform accounts reduce this by making keys available across a user's devices, which trades some isolation for a substantial usability gain.

Where recovery falls back to email or messaging, the overall strength of the account reverts to the strength of that channel, and attention naturally moves there.

Adoption is uneven and mixed flows persist

Most services support public-key authentication alongside passwords rather than instead of them, which means the weaker option remains available and remains targeted.

Detection therefore continues to carry the load on the password path while the stronger path needs much less of it, and the two coexist for as long as the fallback exists.