Part 3 · 2 chapters · ~12 min
Passkeys, WebAuthn and MFA
Why passwords fail, TOTP and SMS one-time codes and their weaknesses (SIM swap, phishing), WebAuthn registration and authentication, passkeys synced and device-bound, step-up authentication for sensitive actions, and transaction signing.
7
Passkeys and WebAuthn
A PASSKEY LOGIN (WEBAUTHN)
a signed challenge from a key that never leaves the device
swipe the figure sideways, or tap expand for full screen
1/5
the challenge
The server sends a random challenge bound to its domain (rpId). Nothing secret travels from the server.
a random challenge bound to the domainno shared secret
8
MFA options and step-up
| factor | phishing-resistant? | weakness |
|---|---|---|
| password | no | reuse, phishing, stuffing |
| SMS OTP | no | SIM swap (common in many markets), interception, phishing relays |
| TOTP app | no | real-time phishing relays |
| push approval | partly (number matching helps) | fatigue attacks ("approve to make it stop") |
| passkey / security key | yes | recovery when all devices are lost |
Step-up authentication: a logged-in session is not enough for every action. Adding a beneficiary, raising limits or large transfers require fresh strong authentication (a passkey assertion or biometric via the app, Deriv course part 10), recorded with the session (stepUpUntil) and checked by the API, not just the UI.