Passwords get reused, stolen and guessed. Passkeys, based on the WebAuthn and FIDO2 standards, replace the password with a pair of cryptographic keys: the private key stays on the user's device, protected by fingerprint, face or PIN.
Why they are more secure
- Phishing resistant: a passkey only works on the site it was created for; a fake site cannot use it.
- No secrets on the server: the server stores only the public key; a database breach reveals no usable credentials.
- More convenient: nothing to remember, sign in with a gesture.
What changes in ASP.NET Core 10
ASP.NET Core Identity integrates passkey support: registering a passkey for the user, signing in with a passkey and managing the passkeys linked to the account. The Blazor Web App template with individual accounts already includes the necessary pages, a good starting point for other project types too.
A realistic adoption path
- Offer passkeys as an additional option to existing users.
- Suggest it at the right moment, for example right after a successful sign-in.
- Keep a secure recovery method, because users change phones.
- When most users have one, consider making the password optional.
In the meantime
builder.Services.Configure<IdentityOptions>(o =>
{
o.Lockout.MaxFailedAccessAttempts = 5;
o.Lockout.DefaultLockoutTimeSpan = TimeSpan.FromMinutes(15);
o.SignIn.RequireConfirmedEmail = true;
});
As long as passwords exist, lockout after failed attempts, confirmed email and two-factor authentication remain essential.
Comments (0)
No comments yet.