Improving Security: The Website Now Supports Passkeys
Now that most operating systems and browsers support PassKeys, it’s time to start getting rid of passwords!
When I watched Apple's WWDC, they made a big deal about privacy and security—as they always do—and they finally introduced a feature to iCloud Keychain that I have wanted for a long time: Passkeys.
If you're wondering what the heck a passkey is, it's essentially a new way of logging into websites and apps that does away with traditional passwords entirely. That might sound a bit nuts, but it’s significantly more secure. Rather than me trying to explain it and messing it up, here is the official word:
"Passkeys are built on the WebAuthentication (or "WebAuthn") standard, which uses public key cryptography. During the account registration process, the operating system will create a unique cryptographic key pair to associate with an account for that app or website. These keys are generated by the device, securely and uniquely, for every account.
One of these keys is public and is stored on the server. This public key is not a secret. The other key is private and is what is needed to actually sign in. The server never learns what the private key is. On devices that support Touch ID or Face ID, these authentication methods can be used to authorise use of the passkey, which then authenticates the user on the app or website. No shared secret is transmitted and the server does not need to protect the public key. This makes passkeys very strong, easy-to-use credentials that are highly phishing-resistant."
The fact that this is based on the WebAuthn standard means it’s designed to work across different operating systems and browsers, making authentication more secure for everyone—provided the website or app supports it.
Now Live on the Site
With security in mind, I have added passkey support to this website and intend to add it to every project I build moving forward. Since I use WordPress, the implementation is straightforward: I simply installed the wp-webauthn plugin and ensured my server had the necessary gmp and mbstring PHP extensions enabled.
How to set it up:
If you’d like to add passkey support to your account, it’s easy:
- Head over to your Profile page.
- Register a new authenticator at the bottom of the page.
- You can choose to use a hardware security key (like a Yubikey) or scan a QR code with your phone to use your device's built-in password manager.
From then on, whenever you log in with your username, you’ll be prompted to verify your identity via a fingerprint, face scan (FaceID, Windows Hello, etc.), or your security key.
I’ve found this setup to be faster and far more reliable than the 2FA solutions I’ve tried in the past—which seemed to lock me out three times a day!
What do you think of passkeys? Are they the future of authentication? Do you have any concerns, or do you think I’ve made a mistake by jumping on this tech early? Let me know in the comments below!
