More Open Source Security episodes

WTF is a passkey with William Brown thumbnail

WTF is a passkey with William Brown

Published 26 Jan 2026

Duration: 01:02:55

Passkey technology, a passwordless authentication method, offers improved security but faces challenges, including inconsistent definitions and usability issues, as well as concerns over e-waste and user understanding.

Episode Description

William Brown is back! This time Josh chats with him about Passkeys. WTF are they? A Passkey is a form of multi factor authentication, but it's not su...

Overview

The podcast explores the development and current status of passkey technology, which is based on earlier standards like U2F and WebAuthn. Passkeys offer a passwordless authentication method by using hardware-based security components, such as YubiKeys, iPhones, or TPMs, and rely on public key cryptography to enable secure logins. However, the discussion highlights several challenges, including inconsistent definitions of passkeys across different platforms and organizations, as well as usability issues like device-bound residency, limited key management options, and reliance on usernames.

Technical difficulties such as cross-device synchronization, high latency, and occasional failures in key enrollment or retentionparticularly on Android and iOSare also mentioned. Although passkeys are viewed as more secure than traditional passwords, their usability remains a challenge for non-technical users. Additionally, concerns about electronic waste due to device limitations and the need for clear communication to help users understand how passkeys workwithout transmitting sensitive information like biometrics over the internetare raised as important considerations for broader adoption.

Recent Episodes of Open Source Security

21 Sept 2026 The curl summer of Bliss with Daniel and Stefan

"Explored open-source security challenges, highlighting curl's 'Summer of Bliss' initiative to reduce maintainer burnout, the impact of AI-generated vulnerability reports, and the need for human expertise in security management, while advocating for sustainable practices in open-source development."

31 Aug 2026 Sovereign Tech Agency with Erik Moller

"Explores the Sovereign Tech Agency's efforts to sustain open-source software as critical infrastructure, emphasizing public investment, digital sovereignty, and strategic funding for projects like *curl* and AI security."

17 Aug 2026 Maintaining EOL Open Source with Commonhaus and HeroDevs

"Explores open-source maintenance challenges, solutions for solo maintainers, and the role of organizations like Common House and HeroDevs in sustaining projects through financial, legal, and administrative support, emphasizing governance, dependency management, and enterprise-community collaboration to ensure long-term sustainability."

10 Aug 2026 Cleanup, Speedup, Levelup open source at e18e

"E18e enhances JavaScript by reducing dependencies, optimizing tools, and improving security, as seen in its work with Storybook, while promoting cleaner code and community collaboration."

More Open Source Security episodes