The State of Passwordless Auth on the Web – Phil Nash, JSNation 2023

Discover the latest advancements in passwordless authentication on the web, including security keys, passkeys, and Web OTP API, and learn how these innovations can improve user experience and security.

Key takeaways
  • 35% of people never reuse passwords, while 24% use a password manager.
  • Security keys can be used across devices and browsers.
  • Passkeys are a form of passwordless authentication, eliminating the need for passwords.
  • The credential management API allows for secure storage and retrieval of credentials.
  • The Web OTP API is used to verify the user’s identity.
  • Conditional mediation can be used to detect and verify the user’s identity.
  • Authentication can be a regression in user experience, but adding features like autocompletion and Web OTP can improve it.
  • Single sign-on (SSO) and passkeys can provide a more secure and seamless login experience.
  • The need for two-factor authentication (2FA) can be reduced with passkeys.
  • The pmk1 attribute can be used to enable passwordless login.
  • The Web OTP API can be used to verify the user’s identity and provide a secure login experience.
  • Passkeys are multi-device credentials that can be used across devices and browsers.
  • The credential management API allows for secure storage and retrieval of credentials.
  • The Web OTP API is used to verify the user’s identity and provide a secure login experience.
  • Conditional mediation can be used to detect and verify the user’s identity.
  • The need for 2FA can be reduced with passkeys.
  • The pmk1 attribute can be used to enable passwordless login.
  • The Web OTP API can be used to verify the user’s identity and provide a secure login experience.