
Identity at the Center #373 - Going Passkey Phishing with Nishant Kaushik
Sep 15, 2025
Nishant Kaushik, CTO at the FIDO Alliance and expert in digital identity, shares valuable insights into the future of authentication. He discusses the rise of passkeys and the importance of community in improving identity security. Nishant addresses common concerns regarding passkey adoption and emphasizes the need for comprehensive security frameworks. The conversation also highlights ongoing challenges in identity verification and the evolving landscape of IAM policies, stressing the role of collaboration and innovation in tackling these issues.
AI Snips
Chapters
Transcript
Episode notes
Policy Is Political Work
- Policy work is political; leaders must accept short-term noncompliance to set long-term goals.
- Get auditors and executives aligned on phased plans to defend policy gaps.
Integrate Passkeys Into Your Framework
- Treat passkeys as part of a broader authentication and identity framework.
- Build supporting infrastructure and map controls to your threat model before adoption.
Attackers Seek The Backdoor
- A passkey itself cannot be stolen, but attackers will target surrounding flows like account recovery.
- Strengthen recovery, notifications, and environment hygiene when deploying stronger auth.
