Articles

What Is FIDO2? The Standard Behind Passkeys

FIDO2 is the open authentication standard that makes passkeys and hardware security keys work, using public-key cryptography instead of shared secrets.

Chisato Chisato · · 4 min read
A set of keys resting on a surface

FIDO2 is an open authentication standard, developed by the FIDO Alliance together with the W3C, that replaces passwords with public-key cryptography verified by a physical device — a phone, a hardware security key, or a computer’s built-in security chip. It’s the underlying technical standard that makes both passkeys and dedicated hardware security keys work; passkeys are essentially FIDO2 credentials with a friendlier name and cloud sync built on top.

The two halves of FIDO2

FIDO2 is actually a pairing of two specifications that work together:

  • WebAuthn (Web Authentication API), a W3C standard that defines how a browser or app talks to an authenticator to create and use credentials — the JavaScript-level API a website calls to register or verify a user.
  • CTAP (Client to Authenticator Protocol), which defines how the browser or operating system talks to the physical authenticator itself, whether that’s a USB security key, a phone over Bluetooth, or a platform authenticator built into the device.

WebAuthn handles the website-to-browser side; CTAP handles the browser-to-hardware side. Together they cover the full path from “a site asks you to sign in” to “a physical device proves who you are.”

How the credential actually works

FIDO2 authentication is built on a public/private key pair generated locally on the authenticating device, one pair per site:

  1. Registration. When you enroll with a site, the authenticator generates a new key pair. The private key never leaves the device — it’s typically sealed inside a secure hardware element and can’t be exported even by the device’s own operating system. The public key is sent to the site and stored against your account.
  2. Authentication. When you sign in, the site sends a random challenge. The authenticator signs it with the private key, after confirming it’s really you — a fingerprint, a face scan, a device PIN, or simply the physical presence of tapping a hardware key. The site verifies the signature against the public key it stored at registration.

Because the private key never leaves the device and never transits the network, there’s no shared secret for an attacker to steal from a server breach, and nothing for a user to be tricked into typing into a fake login page. A credential registered for bank.example.com simply won’t produce a valid signature for a phishing site at bank-example.com — the origin is bound into the cryptographic challenge, which is what makes FIDO2 phishing-resistant by construction rather than by user vigilance.

FIDO2 vs older two-factor methods

Passwords + SMS/TOTP codesFIDO2
What’s transmitted at loginA password, and a one-time codeA cryptographic signature, no shared secret
Phishing resistanceLow — both can be typed into a fake siteHigh — origin-bound, unusable on the wrong domain
Server-side breach riskPassword hashes and phone numbers stored, exploitable if leakedOnly public keys stored — useless to an attacker without the private key
User frictionRemember a password, then retrieve a codeBiometric or PIN unlock, or a key tap
Works across devicesManually, by reusing the same passwordVia platform sync (passkeys) or by carrying a portable hardware key

FIDO2 doesn’t just add a second factor on top of a password — in its passwordless mode, it replaces the password outright, which is the deployment path passkeys use by default.

Roaming vs platform authenticators

FIDO2 credentials can live in two different kinds of authenticator:

  • Platform authenticators are built into a device — the secure enclave in a phone or laptop — and are what most passkey implementations use. Convenient, but tied to that device’s platform ecosystem unless synced through a cloud keychain.
  • Roaming authenticators are separate hardware, most commonly a USB or NFC security key, that can be carried between devices and used to authenticate anywhere the physical key is present. These are the standard choice for high-security environments where a shared, device-independent credential is preferable to relying on any one device’s sync ecosystem.

Many organizations that require multi-factor authentication for privileged accounts issue roaming FIDO2 keys specifically because they’re portable, phishing-resistant, and don’t depend on a phone being unlocked, charged, or in signal range.

Why it matters beyond passkeys

Passkeys have made FIDO2 visible to ordinary consumers, but the standard predates the passkey branding by years and is used far more broadly — as the backbone of hardware security key programs at companies with strict internal security requirements, and as the mechanism behind “sign in with your device” flows that never mention FIDO2 by name. Any time a login flow offers a fingerprint, face scan, or physical key tap instead of a password, it’s very likely FIDO2 underneath, whether or not the product calls it a passkey.

The takeaway

FIDO2 is the open standard — WebAuthn plus CTAP — that makes passwordless, phishing-resistant login possible, using a locally generated key pair instead of a password or shared secret sent over the network. Passkeys are FIDO2 credentials with cloud sync layered on for convenience; hardware security keys are FIDO2 credentials that stay on dedicated, portable hardware instead. Either way, the private key never leaves the device, and the origin-binding built into the protocol is what makes it resistant to phishing in a way that passwords and one-time codes simply aren’t.

The Lycoris Team The Lycoris Team · · 5 min read

Biometric Authentication Explained

Biometric authentication verifies identity using fingerprints, faces, or other traits — here's how enrollment, matching, and liveness checks work.

#Security #Authentication #Privacy
Chisato Chisato · · 4 min read

What Is a Man-in-the-Browser Attack?

A man-in-the-browser attack uses malware inside the browser itself to alter what a user sees and submits, bypassing HTTPS and session protections entirely.

#Security #Authentication #Web Development
The Lycoris Team The Lycoris Team · · 5 min read

CSRF vs. XSS: What's the Difference?

CSRF forges a request using a victim's login session; XSS runs the attacker's own code inside the victim's browser. Different mechanisms, different fixes.

#Security #Web Development #Authentication