Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
.NET Day 2026 The death of Passwords, Implement...
Search
Sponsored
·
Your Podcast. Everywhere. Effortlessly.
Share. Educate. Inspire. Entertain. You do you. We'll handle the rest.
→
.NET Day
September 01, 2026
Technology
44
0
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
.NET Day 2026 The death of Passwords, Implementing Passkeys in .NET 10
.NET Day
September 01, 2026
More Decks by .NET Day
See All by .NET Day
.NET Day 2026 What I learned from modernizing a microservices architecture
dotnetday
0
31
.NET Day 2026 The impact and relevance of code reviews on software quality
dotnetday
0
35
.NET Day 2026 From Co-Pilot to Co-Worker: Mastering GitHub Copilot Agent Mode
dotnetday
0
43
.NET Day 2026 Are you sure your access tokens are really secure?
dotnetday
0
30
.NET Day 2026 How Banks Protect Their Applications with FAPI
dotnetday
0
28
.NET Day 2026 AI Your Way: MCPs vs Skills vs SubAgents 🤖🚀
dotnetday
0
39
.NET Day 2026 The Past, Present and Future of Programming Languages
dotnetday
0
43
.NET Day 2026 Mis-Estimating – why estimating effort does not work
dotnetday
0
44
.NET Day 2026 Supercharge Your Agents: Custom Tools, MCP, and Microsoft Foundry
dotnetday
0
44
Other Decks in Technology
See All in Technology
AI coding 整合正規方法
philipz
0
350
研究開発部の紹介 / Sansan R&D Profile
sansan33
PRO
5
25k
銀行勘定系システムにおける開発プロセス刷新×AIによる環境モダナイゼーション / Development Process Transformation and AI-Driven Environment Modernization
muit
1
2.4k
SREの視点で考えるSIEM活用術 〜AWS環境でのセキュリティ強化〜
cscengineer
PRO
0
130
リアーキテクチャ後の障害ゼロを目指したShadow Testingの取り組み
nihonbuson
PRO
1
160
SREは、MCPとAutopilotをこう使え!
kazumax55
3
910
山手線を徒歩で一周してわかった、 位置情報アプリは「足」が最強のデバッガー
hinakko
0
170
AIを活用するために決めた "やらないこと" - 価値に注目する / Not betting on AI
soudai
PRO
3
560
SREへの勘違いに気づいた後の話
tomodakengo
0
110
Claude Code本って、 読む必要あるの?
oikon48
2
490
beyond jj: config & tools ecosystem
indirect
0
5.4k
C#コードの結合を可視化する Roslyn解析による設計改善と リファクタリング判断
dora56
0
210
Featured
See All Featured
Leo the Paperboy
mayatellez
10
2.3k
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
23k
The Anti-SEO Checklist Checklist. Pubcon Cyber Week
ryanjones
0
250
Refactoring Trust on Your Teams (GOTO; Chicago 2020)
rmw
35
3.8k
Utilizing Notion as your number one productivity tool
mfonobong
4
590
How to Think Like a Performance Engineer
csswizardry
28
2.8k
How GitHub (no longer) Works
holman
316
150k
Redefining SEO in the New Era of Traffic Generation
szymonslowik
1
420
Designing Dashboards & Data Visualisations in Web Apps
destraynor
232
55k
The #1 spot is gone: here's how to win anyway
tamaranovitovic
4
1.2k
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
The Impact of AI in SEO - AI Overviews June 2024 Edition
aleyda
6
1.2k
Transcript
Passkeys .NET 10 Andrew Clymer © 2026 Rock Solid Knowledge
Agenda • Why do we need to move away from
Passwords • Introducing Passkeys, the antidote to Passwords • Adding Passkeys to a WebApp with .NET 10 © 2026 Rock Solid Knowledge 2
What are passwords • A shared secret • Been used
for 1000s of years • To effectively protect, It should be • unique per site • Not guessable • May have to meet minimum complexity rules © 2026 Rock Solid Knowledge 3
Issues with passwords Issue #1 : Non technical people are
responsible for creating strong passwords • Password complexity rules “assist” • It must be at least eight characters • It must have upper and lower case letters • It must have a digit • It must have a special symbol • Password1! for the win • Ridiculous rules • Can’t have two characters the same next to each other • Limiting the characters you can use, sorry can’t use $ • Must change it every 90 days © 2026 Rock Solid Knowledge 4
Issues with passwords Issue #2, Make it strong, make it
unique per site but don’t write it down • How many sites do you have accounts with? • Without assistance, you probably can’t do both • How many internet users know about or use password managers? © 2026 Rock Solid Knowledge 5
Issues with passwords Issue #3: One big honey pot •
Bad actors love stealing passwords from websites • A customer has to trust the site stores the password securely • If passwords are re-used, it only takes one site to leak the secret © 2026 Rock Solid Knowledge 6
Issues with passwords Issue #5: Multiple Attack Vectors • Can
be susceptible to many attack vectors • Password Spraying • Credential Stuffing • Phishing • When “stolen”, can be hard to know © 2026 Rock Solid Knowledge 7
Phishing • What percentage of cyber security incidents start with
an employee getting phished? • 91% of cyber attacks begin with a phishing email to a victim. • Passwords, SMS , TOTP can’t prevent phishing © 2026 Rock Solid Knowledge 8
Can happen to anyone Troy Hunt © 2026 Rock Solid
Knowledge 9
Passkeys to the rescue • WebAuthN built into the browser
• The user is no longer responsible for generating a password • Generated securely and can’t be guessed • Credentials are unique to each site • Organisations don’t store user secrets • Anti-phishing • Credentials can never be used for the wrong site © 2026 Rock Solid Knowledge 11
Registration • Unique Public/Private key pair generated bound to the
website Registration www.kahootz.com All users Public Keys User Private Key Credential Store © 2026 Rock Solid Knowledge 12
Private key store • Key per site • On a
portable device • USB • NFC • On a platform • MacOS • Windows Hello • iOS • Andriod • Password Manager • 1Password • Apple Keychain © 2026 Rock Solid Knowledge Site Private Key www.kahootz.co.uk MIIBOgIBAAJBAKj34GkxFhD90vcNLYLIn FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu… www.bbc.co.uk FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu KUpRKfFLfRYC9AIKjbJTWit+CqvjWYzv… 13
Authentication Request to Sign in with Passkey www.kahootz.com Server sends
challenge User unlocks key, bound to kahootz Browser encrypts challenge with private key, sends to server Server gets user public key Server creates session © 2026 Rock Solid Knowledge The server verifies the encrypted challenge with public key
Anti phishing authentication Request to Sign in with Passkey www.kahoootz.com
Server sends challenge User unlocks key, bound to kahoootz FAILS, No KEY © 2026 Rock Solid Knowledge 15
Data breach • Bad actors can only obtain • Usernames
and Public keys • Public keys of no use in an attack © 2026 Rock Solid Knowledge User Public Key
[email protected]
MIIBOgIBAAJBAKj34GkxFhD90vcNLYLIn FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu…
[email protected]
FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu KUpRKfFLfRYC9AIKjbJTWit+CqvjWYzv… 16
Passkey support in .NET 10 • New ASP.NET Identity (V3)
• SignInManager – Create and Verify Keys • UserStore – Extensions to store keys and find keys • EF Migrations required to support passkeys • Provides .NET APIs that consume JSON from WebAuthN API calls • You need to provide API endpoints to facilitate the Passkey handshakes • Registration • Verification © 2026 Rock Solid Knowledge 17
Bootstrapping ASP.NET identity for EF • ApplicationDbContext for UserStore •
Add Identity Version 3 • Bind to EF Provider public class ApplicationDbContext(DbContextOptions<ApplicationDbContext> options) : IdentityDbContext<IdentityUser>(options); builder.Services.AddDbContext<ApplicationDbContext>(options => options.UseSqlServer(builder.Configuration.GetConnectionString("IdentityConnection"))); builder.Services .AddIdentity<IdentityUser,IdentityRole>(options => { options.Stores.SchemaVersion = IdentitySchemaVersions.Version3; }) .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultTokenProviders(); © 2026 Rock Solid Knowledge 18
Registering a passkey © 2026 Rock Solid Knowledge 19
Registering a passkey Client Side • Server side generates the
options to supply to navigate.credentials.create • navigate.credentials.create requires some of the options to be in a binary format • PublicKeyCredential.parseCreationOptionsFromJSON converts the JSON format returned by the server into a compatible form (binary encoded) const options = await PublicKeyCredential.parseCreationOptionsFromJSON(optionsAsJson); // Browser interacts with user to create the passkey // credentials returned contains, credential id and public key, (server side will process this) const credentials = await navigator.credentials.create({publicKey:options}); © 2026 Rock Solid Knowledge 20
Registering a passkey Server Side • Create two API endpoints
• Start registration – issue create credential options • Complete registration – validate browser response, store credentials © 2026 Rock Solid Knowledge 21
Registering a passkey Server Side – Passkey Creation Options •
Id : Server side id for the user (typically a guid) • Display Name: The name of the key (e.g. 1Password Key) • Name : Server side sign-in name for the user var passKeyEntity = new PasskeyUserEntity() { Id = …, DisplayName = …, Name = … }; string creationOptions = await signInManager.MakePasskeyCreationOptionsAsync(passKeyEntity); return Ok(creationOptions); © 2026 Rock Solid Knowledge 22
Registering a passkey Server Side – Verify and Store New
Passkey Credentials • passkeyCredentialsAsJson: JSON result from WebAuthN • user: IdentityUser to bind the passkey credential to • PerformPasskeyAttestationAsync validates the new credential • AddOrUpdatePasskeyAsync associates the credential with a user PasskeyAttestationResult attestationResult = await signInManager.PerformPasskeyAttestationAsync(passkeyCredentialsAsJson); var addResult = await userManager.AddOrUpdatePasskeyAsync(user, attestationResult.Passkey); © 2026 Rock Solid Knowledge 23
Registering a Passkey Authenticators • An authenticator will only allow
one credential per site • If the authenticators support usernames, can have multiple credentials, but only one per username • Avoids the situation where you create multiple passkeys for the same site on the same Authenticator © 2026 Rock Solid Knowledge 24
Sign-in with a Passkey © 2026 Rock Solid Knowledge 25
Sign-in with a Passkey Client Side • Server side generates
the options to supply to navigate.credentials.get • navigate.credentials.get requires some of the options to be in a binary format • PublicKeyCredential.parseRequestOptionsFromJSON converts the JSON format returned by the server into a compatible form (binary encoded) const options = await PublicKeyCredential.parseRequestOptionsFromJSON(optionsAsJson); // Browser attempts to find credentials for site from an authenticator // If found encrypts challenge with private key const credentials = await navigator.credentials.get({publicKey:options}) // send credentials to server to validate © 2026 Rock Solid Knowledge 26
Sign-in with a Passkey Server Side – Passkey Request Options
• user : the IdentityUser if known • requestOptions : JSON to return to browser for input to navigator.credentials.get method string requestOptions = await signInManager.MakePasskeyRequestOptionsAsync(user); © 2026 Rock Solid Knowledge 27
Sign-in With a Passkeys Server Side – Passkey Credential Validation
• credentials : stringyified JSON from the browser navigator.credentials.get method • requestOptions : JSON to return to browser for input to navigator.credentials.get • PasskeySignInAsync validates credentials, and if ok signs the user in SignInResult result = await signInManager.PasskeySignInAsync(credentials); if (!result.Succeeded) { return Unauthorized(); } © 2026 Rock Solid Knowledge 28
Username can be optional at sign-in • Only for resident
Passkeys • Providing a username provides hint to authenticators • If you have multiple Passkey authenticators, routes quicker { "challenge" : "4ig2yq3yQvMhuN85ezYR0V5-aaNEyFu3_U5BWQezPDXh6Gv8YRgidQdRCFLK3wynOVvwJRdVfqMVgNooGb6pOw", "timeout" : 180000, "rpId" : "localhost", "allowCredentials" : [ { "type" : "public-key", "id" : "0mBp9IY-nedaWsU_eQ4WkMImjY0", "transports" : [ "hybrid", "internal" ] } ], "userVerification" : "required", "hints" : [ ] } © 2026 Rock Solid Knowledge 29
Auto sign-in • Does NOT show a modal popup •
Integrates with the login form • Passkeys in the username field dropdown • Works like password autofill • Makes for a good user experience <input type="text" id="userName" name="userName" class="form-control” autocomplete="username webauthn"/> . . . const credentials = await navigator.credentials.get({publicKey:options,mediation:"conditional"}); © 2026 Rock Solid Knowledge 30
Safe account recovery • What happens if I loose my
Passkey? • Need a trusted fallback mechanism • Passkeys are a very strong authenticator • Falling back to a weaker mechanism weakens the use of passkeys • SMS • TOTP • Email • Recovery needs to be at least as strong, only viable option is via support • Unless Passkeys are just being used for convenience and a stronger password © 2026 Rock Solid Knowledge 31
Prevent the need for account recovery • Users use a
keystore that is backed up • Password Managers • OS Platforms • Create multiple keys per account • Create UX to encourage it © 2026 Rock Solid Knowledge 32
Passkeys in .NET 10 – 1Password Interop issue • Passkeys
stored in 1Password return a credential without clientExtensionResults • This causes server-side failure: • “JSON deserialization… missing required properties including: clientExtensionResults” • Solution • On the client side manually serialize the credential, and assign an empty object clientExtensionResults property © 2026 Rock Solid Knowledge 33
UX • Adoption requires consistent look and feel across the
entire internet • Passkeys will eventual become as common as username and password • FIDO alliance have UX style guide • https://fidoalliance.org/wpcontent/uploads/2023/05/FIDO-Alliance-UXGuidelines-for-Passkey-Creation-and-Signins.pdf © 2026 Rock Solid Knowledge 34
Adopt passkeys today • Phishing Resistant • Frictionless • It
is becoming the standard authentication method of the web © 2026 Rock Solid Knowledge This SurveyMonkey online poll was conducted April 13-14, 2025 among a global sample of 1,389 adults ages 18 and up. Respondents for this survey were selected from the nearly 3 million people who take surveys on the SurveyMonkey platform each day. Data for this survey has been weighted for age, race, sex, education, and geography to adequately reflect the demographic composition of the United States, United Kingdom, China, South Korea and Japan. The modeled error estimate for this survey is plus or minus 3.5 percentage points. 35
Summary • Passwords are not safe for the modern age
• Hard to manage • Multiple attack vectors • Passkeys • Easy to manage, Strong credentials • Anti-phishing • Need to action today © 2026 Rock Solid Knowledge 36
Contact Information •
[email protected]
• https://www.linkedin.com/in/andy-clymer/ • Want to know
more about Passkeys • fido.identityserver.com • For help and advice
[email protected]
• Open.IdentityServer, the free forever OIDC/OAuth platform • Single Sign-On (SSO) • Identity and Access Management • Authorization © 2026 Rock Solid Knowledge 37