By Johann-Philipp Thiers, Security Specialist at Swissbit.
Passkeys in the post-quantum era: Why FIDO needs more than new algorithms
Passkeys have become one of the most tangible examples of passwordless authentication. They are easier for users, more resistant to phishing, and a major step away from passwords, shared secrets, and credential reuse. But behind the…
Biometric Update
Publisher
Sep 16, 2026 at 6:11 PM UTC · 4 min de leitura

Passkeys have become one of the most tangible examples of passwordless authentication. They are easier for users, more resistant to phishing, and a major step away from passwords, shared secrets, and credential reuse. But behind the user-friendly experience sits a complex technical ecosystem: FIDO2, WebAuthn, CTAP, authenticators, relying parties, metadata services, and public-key infrastructure.
That is why the post-quantum discussion matters.
Post-Quantum Cryptography, or PQC, is gaining attention because today’s widely used public-key algorithms – including RSA and elliptic curve cryptography – are considered vulnerable to sufficiently powerful quantum computers. This is not an immediate statement about broken passkeys. It is a long-term security question: how can systems that depend on public-key cryptography be prepared before quantum computers become a practical threat?
For FIDO2 and passkeys, this question is especially relevant. Passkeys are built to provide phishing-resistant authentication by using asymmetric cryptography instead of passwords. During registration, an authenticator creates a credential-specific key pair. During authentication, it signs a challenge from the relying party with the private key. The credential is also bound to the relying party ID, typically the domain of the service, which is one of the reasons passkeys are so effective against phishing.
Article Intelligence
Topics
Sponsored
AdNewsLayer Premium
Unlock deeper intelligence.
Ad-free reading, exclusive research, and real-time onchain insights.
Go Premium
