Passkey & FIDO Alliance News
Ongoing coverage of passkeys and the FIDO Alliance: adoption milestones, standards and specification updates, deployment lessons, and independent analysis. See also the WebAuthn / FIDO2 standard and our guide to passwordless authentication.
← All posts- News · Aug 29, 2026Amazon says 175 million customers now sign in with passkeys
Amazon reports more than 175 million customers have enabled passkeys, signing in six times faster, with passkeys now the default on mobile for anyone who has set one up. The FIDO Alliance counts five billion passkeys in use industry-wide.
- Analysis · Aug 29, 2026Passkeys had a hard month, and none of it was the cryptography
Three research teams broke passkey guarantees in August 2026 without touching WebAuthn. The weak points were event logs, sync key custody, and in-session key reuse. Here is what actually changed for your rollout.
- News · Aug 25, 2026WhatsApp lets one account hold several passkeys, closing the cross-platform gap
Meta announced on August 25, 2026 that WhatsApp accounts can register multiple passkeys, so a user carrying both iOS and Android no longer has to bind to one ecosystem. Two-step verification also moves from a six-digit PIN to a full password.
- News · Aug 10, 2026Three passkey attacks land in one week, none of them breaking the cryptography
SpecterOps, Unit 42, and Dirk-jan Mollema each demonstrated ways to defeat passkey protections without attacking WebAuthn itself, through cleartext event logs, Chrome sync key recovery, and in-session key reuse.
- News · Aug 7, 2026Malware can drive a Windows Hello key for Entra ID persistence without a PIN prompt
Dirk-jan Mollema showed that code running in a signed-in Windows session can use the victim's TPM-bound Windows Hello for Business key as a FIDO2 credential, satisfying phishing-resistant Conditional Access and acquiring a Primary Refresh Token. No admin rights, no CVE.
- Analysis · Aug 6, 2026Black Hat USA 2026 recap: passkeys get broken (twice), and AI agents get an identity perimeter
Our identity takeaways from Black Hat USA 2026: two independent passkey implementation attacks, a wave of AI agent identity and governance launches, an open source tool for dormant non-human identity trust paths, and insider risk getting AI-native and funded.
- News · Aug 5, 2026Pass-the-Passkey: a Black Hat researcher found the WebAuthn implementation bugs, not the standard
At Black Hat USA 2026, DSInternals researcher Michael Grafnetter presented a family of passkey attacks including cleartext YubiKey signatures readable by any authenticated user and a major cloud passkey implementation vulnerable to the exact attack it was built to stop.
- News · Aug 3, 2026Unit 42 finds malware can extract Google's synced passkey keys straight out of Chrome's memory
Palo Alto Networks Unit 42 disclosed three attacks, Pass-ta-key, Silver Pass-ta-key, and Golden Pass-ta-key, that extract device identity keys and the master secret behind Google's synced passkeys on Windows, undermining the claim that passkey private keys cannot be copied.
- News · Jul 15, 2026Google Workspace puts FIDO2 keys into the Windows login, days after Entra makes passkeys default
Google began rolling out FIDO2 security keys as a second factor at Windows sign-in for all Workspace customers on 13 July. Microsoft is making passkeys the default in Entra ID from 1 September. Two vendors, one direction, and the desktop is the new battleground.
- News · Jul 14, 2026Entra ID makes passkeys the default, and retires SMS and voice in 2027
From September 2026 Entra ID auto-enables passkeys for users on SMS or voice. On 1 February 2027 those two methods stop working entirely, for every tenant, with no opt-out. Admins have a hard deadline and a scanner script to find who is affected.
- News · Jun 15, 202694 percent of enterprises say they can revoke access in 24 hours. 35 percent found out they couldn't.
FIDO Alliance and HID surveyed 500 IT and security decision-makers for The State of Physical and Digital Identity in the Enterprise. The headline gap: near-universal confidence in fast access revocation next to a real failure rate more than one in three.
- Analysis · Jun 12, 2026Identiverse 2026 recap: agentic identity grows up, and passkeys get real
Our takeaways from Identiverse 2026 in Las Vegas: AI agent identity moved from theory to roadmap, passkeys turned operational, deepfakes pressured identity verification, and session security took center stage.
- News · Jun 11, 2026xMoney lets customers create a Mastercard Payment Passkey inside its banking app, a first for an issuer
xMoney says it is the first Mastercard issuer to let customers create and enroll a Mastercard Payment Passkey directly inside its mobile banking app, satisfying Strong Customer Authentication while enabling Click to Pay checkout.
- News · Jun 5, 2026HID's Enterprise Attestation checks a passkey authenticator is company-issued before it can enroll
HID added a governance layer to its FIDO2 authenticators that checks for a certificate tying a device to a known company-issued authenticator before allowing passkey enrollment, closing the gap where employees could register personal hardware without IT's knowledge.
- News · Jun 5, 2026RSA brings passwordless authentication to Linux servers, closing its last password-only gap
RSA ID Plus now covers Linux servers, developer workstations, and critical infrastructure with FIDO-based passwordless sign-in, closing the gap where organizations ran phishing-resistant authentication everywhere except the Linux estate.
- News · Jun 25, 2025Microsoft makes new consumer accounts passwordless by default
From May 2025, new Microsoft accounts are created without a password at all and default to passkeys. Existing accounts keep their passwords. It is the largest default-passwordless move to date, across Windows, Microsoft 365, and Xbox sign-ins.