As organizations worldwide transition from traditional passwords to passkeys, Yubico is advocating for more rigorous security standards in passkey implementation. Christopher Harrell, Yubico’s Chief Technology Officer, emphasizes that while passkeys represent a significant advancement in authentication technology, their security levels can vary considerably.
Current implementations feature two primary types of passkeys: synced passkeys, which store credentials in cloud services to enable multi-device access, and device-bound passkeys, which maintain credentials locally on specific devices. The distinction has become increasingly important as major technology companies like Microsoft push toward mandatory passwordless authentication by 2025.
“Not all passkeys are equal, not all users have the same needs, and leaving insecure fallback methods in place can provide a false sense of security,” says Harrell. The company recommends that enterprises and identity providers implement device-bound passkeys exclusively, while disabling synced passkeys for enterprise applications and eliminating non-FIDO fallback authentication methods.
Hardware security keys, such as YubiKeys, implement device-bound passkeys and are described by Harrell as the “gold standard and original passkey.” These devices provide cross-platform authentication capabilities while maintaining high security assurance levels through their physical form factor. Yubico has demonstrated this commitment to security through various innovations, including the launch of their biometric FIDO2 security keys and the development of FIPS-certified solutions for high-security environments.
Yubico’s position stems from their established role in developing FIDO2, WebAuthn, and U2F open authentication standards. Their hardware solutions currently enable passwordless authentication across thousands of consumer and enterprise applications globally, with major platforms like AWS SSO adding native support for YubiKeys.
The company’s stance on device-bound passkeys supports broader industry initiatives, including Microsoft’s password replacement efforts. Yubico specifically highlights the complementary nature of YubiKeys and Windows Hello for Business, noting that these technologies are “better together” in providing enhanced security through non-exportable credentials.
Recent research into FIDO2 and synced passkeys has revealed important security implications that support Yubico’s position on device-bound implementations. The findings become particularly relevant as organizations face increasingly sophisticated cyber threats, including targeted phishing attacks that can compromise traditional authentication methods.
In their security leadership guidance, Yubico recommends: “Enforce only device-bound passkeys in your identity providers. Require them by policy even for services outside your SSO. Disable synced passkeys for enterprise use. Use passkeys in security keys as a root of trust for self service recovery, transition, and step-up. Remove all non-FIDO fallback methods.”
Sources: Security Brief, Yubico Blog, Yubico Press Release, KuppingerCole Analyst Report