Story perspectives
Research Reveals Vulnerability in FIDO Passkey Authentication
8/15/2025
50 8
1 of 1
Story summary
- Researchers at Proofpoint identified a downgrade attack that can bypass FIDO-based passkey authentication.
- The attack takes advantage of fallback methods when users switch from FIDO to weaker options.
- Although not yet seen in practice, it presents a potential risk as FIDO usage grows.
- Proofpoint advises implementing FIDO-only authentication and monitoring browser anomalies to reduce risks.
