Understanding Passwordless Authentication
26 August 2026
Passwords have been the primary method of authentication for decades, but they remain a common target for threat actors. It's time to rethink how we verify identities online.
Last updated on 18 September 2026
Understanding Passwordless Authentication
Passwords have been the primary method of authentication for decades, but they remain a common target for threat actors. Passwordless authentication provides an alternative by allowing users to authenticate without the need for a traditional password.
Background
Passwords have been the primary method of authentication for decades, but they remain a common target for threat actors. The theft and misuse of passwords, including through phishing, credential stuffing, and data breaches continue to contribute to account compromise.
Passwordless authentication offers an alternative way to authenticate users without relying on passwords. It can be implemented using different technologies, each offering different levels of security and user convenience.
Why Move Beyond Passwords?
There are several well-known challenges when using passwords to secure devices and online accounts. Users often choose weak or predictable passwords, re-use passwords across multiple services, or store passwords insecurely, particularly when they have many passwords to manage. Passwords are also vulnerable to attacks such as:
Phishing attempts that trick users into revealing their passwords
Credential stuffing using passwords leaked from previous data breaches
Credential-stealing malware that captures passwords, records keystrokes or harvests stored credentials
Brute-force attacks that attempt to guess passwords
Even when passwords are combined with Multi-Factor Authentication (MFA), such as one-time authentication codes, the authentication process may remain vulnerable to sophisticated phishing techniques, such as adversary-in-the-middle attacks, that can trick users into providing their passwords and authentication codes.
Passwordless authentication can reduce or eliminate reliance on passwords during sign-in and, depending on the technology used, can provide stronger protection against credential theft and phishing attempts.
What is Passwordless Authentication?
Passwordless authentication refers to methods of authenticating users without requiring them to enter a traditional password during sign-in.
Instead of relying on something a user knows (a password), passwordless authentication may use one or more of the following:
Something the user has (e.g. a trusted device or security key)
Something the user is (e.g. fingerprint or facial recognition)
Something the user knows (e.g. a device pin)
However, the security properties of passwordless authentication vary depending on the technology used. Not all passwordless authentication methods are resistant to phishing.
Types of Passwordless Authentication
There are several passwordless authentication methods available but not all provide the same level of protection. Understanding which methods are phishing-resistant can help organisations and users make informed decisions when selecting an authentication method.
What does "phishing-resistant" mean?
A phishing-resistant authentication method is designed so that authentication credentials cannot be captured and reused by a fake website. Even if a user is tricked into visiting a phishing site, the authentication attempt cannot be successfully completed because the credential is cryptographically bound to the legitimate service or otherwise cannot be replayed.
Method | Description | Phishing-Resistant | Why? |
Passkeys (FIDO2/WebAuthn) | Cryptographic credentials that are typically unlocked using biometrics or device PIN. | Yes | Bound to the legitimate website using public-key cryptography. The private key never leaves the user's device. |
FIDO2 Security Keys | Physical hardware security keys (e.g. USB, NFC, or Bluetooth) used for authentication. | Yes | Uses FIDO2/WebAuthn to verify the website before authentication, preventing use on phishing websites. |
Windows Hello for Business | Passwordless sign-in using device-bound credentials, unlocked using biometrics or PIN. | Yes | Uses public-key cryptography and device-bound credentials instead of reusable passwords. |
Smart Cards / Certificate-Based Authentication | Authentication using certificates and associated private key stored on smart cards or managed devices. | Yes | Private keys remain securely stored on the smart card or managed device and are never transmitted. |
Push Authentication | Users approve sign-in requests through a trusted mobile application. | No | Users may be tricked into approving fraudulent requests. |
Magic Links | Users authenticate by clicking a unique link sent to their email. | No | The emailed link acts as the credential and may be intercepted or used if a user is deceived. |
SMS One-Time Passwords (OTP) | Authentication using SMS verification codes. | No | Users can be tricked into entering OTPs on phishing websites, and SMS is vulnerable to SIM swapping. |
Note: Passkeys and FIDO2 security keys are both based on the FIDO2/WebAuthn standards and provide phishing-resistant authentication. The main difference is where the credential is stored. Passkeys are typically stored securely on a user's phone, computer or password manager and can synchronise across trusted devices. FIDO2 security keys store the credential on a dedicated hardware device (such as a USB, NFC or Bluetooth security key) that must be physically present during authentication.
Passkeys are increasingly being adopted across consumer and enterprise services due to their phishing-resistant authentication and ease of use.
Benefits of Passwordless Authentication
For Individuals
Passwordless authentication can provide:
Easier and faster sign-in experience
Reduced need to remember and manage passwords
Reduced risks associated with weak or reused passwords
Better protection against phishing when phishing-resistant methods, such as passkeys, are used
For Organisations
Passwordless authentication can provide:
Reduced risks associated with password-based attacks that exploit weak, reused or stolen passwords
Fewer password reset requests and lower associated helpdesk costs
Residual Risks
Although passwordless authentication can reduce risks associated with passwords, it does not eliminate all cyber risks. The level of protection depends on the authentication method used and how it is implemented. Attackers may still compromise authenticated sessions or exploit other weaknesses in the authentication and account lifecycle.
For example:
Malware on a compromised device may abuse an authenticated session.
Attackers may steal session cookies after successful authentication and use them to gain unauthorised access.
Weak account recovery processes may undermine the protections provided by passwordless authentication.
Users may still be deceived through social engineering techniques that manipulate them into revealing sensitive information or performing actions that compromise their accounts.
Conclusion
Passwordless authentication can reduce the risks associated with traditional password-based authentication.
However, not all passwordless authentication methods provide the same level of security properties. When choosing a passwordless authentication method, factors such as phishing resistance, compatibility with existing systems, account recovery and device requirements should be considered.
Where supported, phishing-resistant methods should be prioritised, alongside other security measures to protect against threats that occur before, during and after authentication.
References
https://www.paloaltonetworks.sg/cyberpedia/what-is-passwordless-authentication (opens in new tab)
https://www.ncsc.gov.uk/paper/traditional-user-and-fido2-credentials-personal-use (opens in new tab)
