FIDO2 & WebAuthn: Killing the Password

How the FIDO Alliance's standards use public-key cryptography to replace passwords with phishing-resistant, biometric-backed authentication.

11 min read

The Password Problem

Passwords are broken:

  • 81% of data breaches involve weak or stolen passwords (Verizon DBIR)
  • The average user has 100+ passwords — and reuses them
  • Phishing works because passwords are shareable secrets

FIDO’s thesis: Something you know is the weakest factor. Eliminate it.

How FIDO Works

FIDO authentication uses asymmetric cryptography — the same math that secures HTTPS (W3C WebAuthn).

Registration

sequenceDiagram
    participant User
    participant Browser as Browser (navigator.credentials.create)
    participant Auth as Authenticator<br/>(TPM / Secure Enclave)
    participant Server as Relying Party

    User->>Browser: Click "Register FIDO key"
    Browser->>Server: Request registration options
    Server->>Browser: challenge + RP ID + user info
    Browser->>Auth: Create key pair for origin + RP ID
    Auth->>User: Verify presence (touch / PIN / biometric)
    User->>Auth: Consent
    Auth->>Auth: Generate key pair
    Auth->>Browser: publicKey + credentialId + attestation
    Browser->>Server: Send publicKey + credentialId
    Server->>Server: Store publicKey for user
    Server->>Browser: Registration complete
    Browser->>User: FIDO key registered

Authentication

sequenceDiagram
    participant User
    participant Browser as Browser (navigator.credentials.get)
    participant Auth as Authenticator
    participant Server as Relying Party

    User->>Browser: Click "Sign in with FIDO"
    Browser->>Server: Request authentication challenge
    Server->>Browser: challenge + RP ID (+ allowCredentials)
    Browser->>Auth: Sign this challenge for RP ID
    Auth->>User: Verify presence (touch / PIN / biometric)
    User->>Auth: Consent
    Auth->>Browser: { credentialId, signature, authenticatorData }
    Browser->>Server: Send assertion
    Server->>Server: Verify signature with stored publicKey
    Server->>Server: Check RP ID + origin match
    Server->>Browser: Authentication success
    Browser->>User: Signed in

On registration:

  1. Your device generates a public/private key pair specifically for this website (RP ID)
  2. The private key stays on your device (secure enclave / TPM)
  3. The public key is sent to the server

To authenticate:

  1. The server sends a challenge: “Sign this random message”
  2. Your device signs it using the private key — only after you prove presence (touch, PIN, fingerprint)
  3. The server verifies the signature against your stored public key

FIDO2 / WebAuthn

FIDO2 is the latest specification, consisting of:

  • WebAuthn — W3C standard API in browsers (navigator.credentials.create() / .get())
  • CTAP2 (Client-to-Authenticator Protocol) — How the browser talks to the hardware key (FIDO Alliance)

This means you can use a FIDO2 security key (like a YubiKey) or a platform authenticator (Windows Hello, Touch ID, Android fingerprint) without any drivers or plugins — it just works in Chrome, Safari, Firefox, and Edge.

Types of FIDO Authenticators

FIDO authenticators fall into two broad classes, each with different use cases (FIDO classifications):

Platform Authenticators (Internal)

Built into the device. Cannot be removed without destroying the hardware.

TypeExamplesUser Verification
BiometricTouch ID, Face ID, Windows Hello, Android fingerprintFingerprint / face scan
PIN-basedWindows Hello PIN, device unlock codeDevice PIN / password

The private key is stored in the device’s secure enclave or TPM. Best for personal devices. If the device is lost, credentials are lost unless backed up via passkey sync.

Roaming Authenticators (Cross-Platform / Security Keys)

Portable hardware tokens that can be used across multiple devices.

TransportExampleRangeTypical Use
USB-A / USB-CYubiKey 5, Google TitanWiredDesktops, laptops
NFCYubiKey 5 NFCTap (< 10 cm)Mobile phones
BLEFeitian, SoloKey~10 mPhones, tablets

The private key lives on the token. User presence is proved by touching the key (USB), tapping (NFC), or pressing a button (BLE). Ideal for shared workstations, kiosks, and backup credentials.

User Verification Methods

MethodFIDO TermHow It Works
TouchuserPresence (UP)Tap the key or insert USB — minimal friction
PINuserVerification (UV)Enter PIN on device keypad or host
BiometricuserVerification (UV)Fingerprint, face scan, iris — highest assurance

Relying parties specify the required verification level via the userVerification parameter (required, preferred, discouraged).

Passkeys: Synced Authenticators

Passkeys (FIDO Alliance) are a third category: software authenticators whose private keys are synced (end-to-end encrypted) via the cloud provider’s keychain:

  • Apple — iCloud Keychain (syncs across iPhone, iPad, Mac)
  • Google — Google Password Manager (syncs across Android, Chrome, macOS, Windows)
  • Microsoft — Windows Hello / Microsoft Authenticator

This solves the backup problem — lose your phone and your passkeys are still on your laptop. However, the key material is only as secure as the cloud provider’s E2EE implementation.

What Makes FIDO Phishing-Resistant

AttackWhy It Fails
Phishing siteThe key pair is scoped to the origin (https://example.com). It won’t sign for https://examp1e.com
Credential stuffingNo reusable password to stuff
Man-in-the-middleThe signature is bound to the specific challenge and origin
SIM swapNo SMS involved
Database leakOnly public keys are stored — useless to attackers

Passkeys: FIDO Goes Mainstream

Apple, Google, and Microsoft have standardised on passkeys (FIDO passkeys) — FIDO credentials that sync across devices via the cloud. Instead of a password, you authenticate with Face ID / Touch ID / PIN, and the private key is synced (encrypted end-to-end) across all devices.

Passkeys are already supported on over 4 billion devices. They eliminate both phishing and password spray attacks by removing the shared secret entirely.

What FIDO Doesn’t Solve

  • Account recovery — If you lose all devices with no backup, you can’t recover the key. Providers need fallback flows (recovery codes, secondary email).
  • Legacy system integration — Older protocols (LDAP, RADIUS, NTLM) don’t speak WebAuthn. You need a broker or proxy.
  • Cost of hardware keys — Software passkeys solve this, but high-assurance environments still want dedicated hardware tokens like YubiKey.

FIDO is the phishing-resistant MFA layer recommended in our OIDC/OAuth and PKI posts.


FIDO2 represents the first real opportunity to kill the password at scale. With passkeys baked into every major OS and browser, passwords are finally starting to fade.

References