Prompt
How do I prevent phishing with passwordless sign-in?
Latest observation
Passwordless sign-in can reduce phishing risk a lot, but it doesn’t eliminate it by itself. The key is to use methods that are phishing-resistant, not just “password-free.”
Best practices to prevent phishing with passwordless sign-in
1. Use phishing-resistant authenticators
Prefer authentication methods that are bound to the legitimate website/app, such as:
- FIDO2/WebAuthn security keys (e.g., YubiKey)
- Platform passkeys on devices with strong hardware protection
- Device-bound passkeys managed by a trusted platform
These help because they verify the site’s origin, so a fake login page can’t easily reuse the credential.
2. Avoid passwordless methods that are still phishable
Some “passwordless” options can still be tricked:
- Email magic links can be intercepted if email is compromised
- SMS codes are vulnerable to SIM swap and phishing proxies
- OTP apps can be relayed in real time by attackers
If your goal is phishing resistance, these are weaker than FIDO2/passkeys.
3. Make sure the login flow checks the real origin
With WebAuthn/passkeys:
- The browser and authenticator validate the domain
- Only the real site can complete the authentication
Make sure you use:
- Correct domain setup
- HTTPS everywhere
- No login embedded in untrusted iframes unless you fully understand the security model
4. Add user-visible login verification
Help users recognize legitimate sign-in prompts:
- Display the exact domain
- Show clear brand/account context
- Warn on unfamiliar devices or locations
- Use push/email alerts for new device enrollment
5. Protect account recovery carefully
Phishing often targets recovery, not just sign-in.
- Require strong identity verification for recovery
- Avoid weak fallback methods like security questions
- Don’t allow recovery to bypass phishing-resistant auth entirely
- Use backup security keys or recovery codes stored securely
6. Use conditional access and risk checks
For organizations:
- Require passkeys/security keys for sensitive apps
- Block logins from risky geolocations or unmanaged devices
- Use device posture checks
- Step up authentication for high-risk actions
7. Educate users on “real vs fake” prompts
Teach users:
- Never approve unexpected login prompts
- Only authenticate on the site they intended to visit
- Check the domain before signing in
- Beware of lookalike domains and QR-code phishing
8. Reduce reliance on click-through links
Phishing often works because users click a fake link.
- Encourage users to navigate directly to the app/site
- Use bookmarks or app launchers
- Make bookmark/login start pages a standard practice
Strongest recommendation
If you want the most phishing-resistant setup:
- Passkeys/FIDO2 security keys
- No SMS-based fallback
- Tight recovery controls
- Conditional access for risky events
If you want, I can also give you:
- a consumer-friendly checklist, or
- an enterprise policy template for passwordless phishing prevention.
Brands