Session

Passkeys Under Attack: Understanding the risks and defenses

Passkeys are steadily replacing passwords, and as adoption grows, attackers and researchers are turning their attention to new ways of abusing them. Recent work has surfaced a range of techniques — FIDO downgrade attacks, Windows Hello key abuse, and passkey replay among them — that get around phishing-resistant authentication without ever breaking the underlying cryptography.

This session walks through the latest community research into complex passkey attacks, breaking each one down to understand how it works, how much real-world risk it carries, and what it takes to pull off. From there we map the defenses: the concrete preventive controls and detections that address each technique, and how we can implement them with the Microsoft security stack. You'll leave with a clear picture of the passkey threat landscape and a practical sense of which controls matter most for your environment.

Robbe Van den Daele

MVP| MC2MC | Security Consultant & SOC Engineer

Brussels, Belgium

Actions

Please note that Sessionize is not responsible for the accuracy or validity of the data provided by speakers. If you suspect this profile to be fake or spam, please let us know.

Jump to top