Claim
Passkeys are more phishing-resistant than SMS-based two-factor authentication
FIDO2/WebAuthn passkeys are bound to the origin they were registered for, which makes them structurally resistant to the phishing attacks that defeat SMS OTP.
Would be false if: False if documented real-world attacks show passkey-based auth bypassed via phishing at rates comparable to SMS OTP interception.
Authorship
alice (100%)
Pending corrections
Worth adding: phishing resistance depends on platform support β some early Android WebAuthn implementations had downgrade attack vectors.
SourceSign in to join the debate.
For
No entries yet.
Against
No entries yet.