tech · quantum risk
Is Passwordless FIDO Quantum Proof? Cyber Program & PQC
Verdict
Passwordless/FIDO improves phishing resistance classically but is not automatically post-quantum. Track authenticator and RP algorithm ecosystems; still upgrade TLS and token layers in the same program.
Overview
WebAuthn credentials use public-key pairs on devices or platform authenticators.
PQC for authenticators is an evolving industry topic—inventory RPs and authenticators now.
Program inventory focus: Authenticator public keys are classical asymmetric crypto in common deployments. Typical classical surfaces: FIDO/WebAuthn authenticator public keys; Attestation algorithms. Cross-read /security/program and /assessment. Educational only—not compliance advice.
Cryptographic profile
- Signatures: FIDO/WebAuthn authenticator public keys, Attestation algorithms
- Hash: Credential ids
- Public-key exposure: Authenticator public keys are classical asymmetric crypto in common deployments.
What breaks
- Assuming passkeys end quantum risk
- Ignoring IdP token layer
FAQ
Syncable passkeys?
Adds cloud recovery crypto considerations—document vendor model.
Replace smart cards?
Program choice; both need algorithm tracking.
Key concepts (technical dictionary)
Terms used on this page — open a definition: