passkeysciamidentity management

    The Human Element: Passkeys, Abuse, and Enterprise Responsibility

    Passkeys offer strong phishing resistance, but new research highlights vulnerabilities related to human behavior and shared devices. Enterprises must understand these risks.

    Schutz IT 20 August 2026 6 min read

    The Human Element: Passkeys, Abuse, and Enterprise Responsibility

    The rapid adoption of passkeys is a double-edged sword for enterprise security. While hailed as a significant leap forward in phishing resistance and user convenience, new research highlights a critical, often overlooked dimension: the human element. For enterprise security architects, CISOs, and IAM engineers, understanding how passkeys intersect with real-world human behaviors, especially in sensitive contexts like shared devices or intimate partner abuse, is paramount to building truly resilient identity systems.

    The Promise and Peril of Passkeys

    Passkeys represent a fundamental shift away from traditional password-based authentication. By leveraging public-key cryptography and device-bound credentials, they offer inherent phishing resistance, simplify user experience, and promise to significantly reduce account takeover (ATO) risks. This technical strength has driven widespread enterprise adoption, with major platforms like Microsoft Entra ID making them a default authentication mechanism [10]. Organizations are eager to integrate passkeys into their Customer Identity and Access Management (CIAM) strategies, seeing them as a cornerstone of future-proof authentication.

    However, the very mechanisms that make passkeys secure against external, remote attacks can introduce new vulnerabilities when the threat originates from within a trusted environment or from someone with physical access to a user's device.

    The Unforeseen Attack Vector: Intimate Partner Abuse and Shared Access

    Recent research from Cornell University, presented at the USENIX Security Symposium, sheds light on a particularly troubling blind spot: how passkeys can be exploited in situations of intimate partner abuse [6, 9]. The study demonstrates that individuals with unauthorized physical access to a victim's device can easily enroll their own passkey, effectively backdooring the victim's accounts. This access persists even after the victim changes their traditional password, as the attacker's enrolled passkey remains valid and usable.

    This finding challenges the conventional enterprise security mindset, which often focuses on external threats and technical vulnerabilities. For CIAM engineers, this means considering scenarios beyond typical corporate network boundaries. While an enterprise might secure employee devices, the challenge becomes more pronounced in CIAM where consumer devices are diverse, often shared, and used in less controlled environments.

    Key Takeaways from the Cornell Research:

    • Device Binding Paradox: The core strength of passkeys—their cryptographic binding to a specific device—becomes a critical weakness in contexts of shared devices or physical device compromise. An abuser with physical access can enroll their passkey, gaining persistent access.
    • Persistent Access: Unlike compromised passwords, which can be remediated by a password reset, a malicious passkey enrollment grants continued access, even if the legitimate user changes other credentials.
    • Lack of User Awareness: The study found that users struggle to identify when a malicious passkey has been enrolled on their account and lack clear, intuitive tools to remediate such compromises.
    • Enterprise Responsibility: Organizations deploying passkeys have a responsibility to address these social vulnerabilities, not just technical ones. Neglecting this aspect can lead to significant harm to users and reputational damage.

    Beyond Phishing: The

    Keep reading