# Passkeys, under the hood

Published: 2026-09-19

A passkey is a password your device invents, never shows you and refuses to hand to anyone — including you. Under the hood: the WebAuthn ceremony (per-site key pair, challenge, signature), the one field the browser writes that kills phishing (origin), device-bound vs synced keys, the AAGUID, and why "un-phishable" and "un-movable" are the same property — which is what "I don't like passkeys" (616 points on Hacker News) is really about. Verdict: NEEDS REVIEW — the ceremony shipped, the lifecycle is a working draft.

Canonical: https://thedailydiff.dev/video/2026-09-19-passkeys-under-the-hood/

## What this video covers

- A password your device invents and never shows you
- Three numbers: 5 billion passkeys, 98% sign-in success, 1 billion Google sign-ins
- 2013 → 2022: how FIDO killed the password, slowly
- The ceremony: one key pair per site, challenge, signature
- Why phishing dies: the browser writes the origin

## Chapters

- 0:00 A password your device invents and never shows you
- 0:11 Three numbers: 5 billion passkeys, 98% sign-in success, 1 billion Google sign-ins
- 0:37 2013 → 2022: how FIDO killed the password, slowly
- 0:59 The ceremony: one key pair per site, challenge, signature
- 1:16 Why phishing dies: the browser writes the origin
- 1:29 Where the private key lives: device-bound vs synced
- 1:51 Both stories are true: faster, stronger, locked in
- 2:14 The fix: FIDO credential exchange (CXF/CXP) and where it stands
- 2:33 Monday: what to do with your accounts
- 2:54 Verdict: NEEDS REVIEW

## Transcript

### A password your device invents and never shows you

0:00 A passkey is a password your device invents, never shows you, and refuses to hand to anyone, including you, which is the entire security feature and, as of Thursday, the entire complaint.

### Three numbers: 5 billion passkeys, 98% sign-in success, 1 billion Google sign-ins

0:11 Three numbers. The FIDO Alliance counts five billion passkeys in use. Microsoft measures a 98 percent sign-in success rate with them, against 32 for passwords. And a post titled I don't like passkeys just spent a day on top of Hacker News with six hundred comments. In three minutes: where they came from, what your browser actually signs, and why un-phishable and un-movable are the same word. This is The Daily Diff, under the hood.

0:36 2013. PayPal, Lenovo and a start-up called Nok Nok form the FIDO

### 2013 → 2022: how FIDO killed the password, slowly

0:41 Alliance to kill the password. 2014, Google and Yubico ship the U2F security key. 2019, WebAuthn becomes a W3C standard. And in 2022 Apple, Google and Microsoft rename it passkeys, because nobody ever bought anything called a discoverable resident credential.

### The ceremony: one key pair per site, challenge, signature

0:59 The ceremony. At registration your device generates a fresh key pair for that one site. The public key goes to the server; the private key stays in the chip. At sign-in the server sends a random challenge, the device signs it, and the server checks the signature against the public key it stored. There is no secret on the server to leak. The phishing part is one field.

### Why phishing dies: the browser writes the origin

1:17 Before the device signs, the browser, not the page, writes the real origin into the signed data. A look-alike domain gets a signature for the wrong domain, and the real server rejects it. The user can be fooled; the math cannot. So where does the private key live?

### Where the private key lives: device-bound vs synced

1:30 Device-bound means a security key, where it never leaves, and a YubiKey holds a hundred. Synced means iCloud Keychain, Google Password Manager, 1Password or Bitwarden, where the key sits in an end-to-end encrypted vault and follows your account. The site can tell which from a sixteen-byte model id called the AAGUID, and most sites ignore it.

### Both stories are true: faster, stronger, locked in

1:51 So both stories are true. Sign-in is faster and stronger, and the FIDO survey says three in four consumers have one. But a secret you cannot read is un-phishable and un-movable in the same breath: when the phone dies, or a robot bans your Google account, every passkey inside goes with it. Hawksley calls that a perfect fit for a corporation and a poor fit for a person; Nikita Bier calls it magic fairy dust.

### The fix: FIDO credential exchange (CXF/CXP) and where it stands

2:14 The fix has a name. FIDO's credential exchange format reached proposed standard, and iOS 26 and Android now move passkeys between managers with it. The protocol beside it is still a working draft, two years in. Hardware keys never export by design, so the official backup is a second hardware key, a recommendation with a price tag.

### Monday: what to do with your accounts

2:33 So, Monday. One: keep a password and an authenticator app on every account until the export works for you; the weakest recovery path is your real security. Two: device-bound means two keys on day one. Three, if you build the login: require a resident key, verify the origin on the server, and stop asking for a passkey from someone who just used one. Verdict, under the hood: needs review.

### Verdict: NEEDS REVIEW

2:56 The ceremony shipped. The lifecycle is a working draft. If you'd rather read this than hear me say it, the diff lands in your inbox every morning, free at the daily diff dot dev, link below. And that's the diff for today. I'm Niko from Axrisi. Merge responsibly.

## Sources

- [Ethan Hawksley, "I don't like passkeys" (18 Sep 2026) — https://hawksley.dev/blog/i-dont-like-passkeys · HN (616 points)](https://news.ycombinator.com/item?id=49753211) — news.ycombinator.com
- [W3C Web Authentication Level 3](https://www.w3.org/TR/webauthn-3/) — www.w3.org
- [Trail of Bits, "The cryptography behind passkeys"](https://blog.trailofbits.com/2025/05/14/the-cryptography-behind-passkeys/) — blog.trailofbits.com
- [FIDO Alliance, "The State of Passkeys 2026" (5 billion passkeys; 90% familiar, 75% enabled; n = 11,000)](https://fidoalliance.org/the-state-of-passkeys-2026-global-consumer-and-workforce-report/) — fidoalliance.org
- [Microsoft, "Convincing a billion users to love passkeys" (98% vs 32% success, 3× faster, 7,000 password attacks/s)](https://www.microsoft.com/en-us/security/blog/2024/12/12/convincing-a-billion-users-to-love-passkeys-ux-design-insights-from-microsoft-to-boost-adoption-and-security/) — www.microsoft.com
- [Google, 1 billion passkey sign-ins across 400 million accounts (May 2024)](https://blog.google/technology/safety-security/google-passkeys-update-april-2024/) — blog.google
- [FIDO Credential Exchange specs (CXF 1.0 Proposed Standard, CXP Working Draft)](https://fidoalliance.org/specifications-credential-exchange-specifications/download-credential-exchange-specifications/) — fidoalliance.org
- [Android passkey transfer via CXF (heise, Sep 2026)](https://www.heise.de/en/news/Password-managers-on-Android-Switch-without-manual-export-11450892.html) — www.heise.de
- [Yubico, YubiKey 5.7: 100 passkeys per key](https://www.yubico.com/blog/empowering-enterprise-security-at-scale-with-new-product-innovations-yubikey-5-7-and-yubico-authenticator-7/) — www.yubico.com
- [William Brown, "Passkeys: A Shattered Dream"](https://fy.blackhats.net.au/blog/2024-04-26-passkeys-a-shattered-dream/) — fy.blackhats.net.au
