As humans, machines and autonomous agents increasingly interact on our behalf, authentication can no longer be treated as a single moment in time. Trust must be established, verified and continuously evaluated.
We have spent decades improving how users prove who they are. A new phishing technique raises a much more uncomfortable question: Why doesn’t the destination have to prove itself too?
New research into passkey attacks reveals why phishing-resistant authentication is an important advance, but cannot be the end of the identity-security conversation.
For decades, authentication has been built around one question: “Who are you?” In a world of phishing, deepfakes, AI-generated deception and nearly perfect digital impersonation, perhaps it's time we asked the other side the same question.