Upgrade to Pro — share decks privately, control downloads, hide ads and more …

.NET Day 2026 The death of Passwords, Implement...

Sponsored · SiteGround - Reliable hosting with speed, security, and support you can count on.
Avatar for .NET Day .NET Day
September 01, 2026

.NET Day 2026 The death of Passwords, Implementing Passkeys in .NET 10

Avatar for .NET Day

.NET Day

September 01, 2026

More Decks by .NET Day

Other Decks in Technology

Transcript

  1. Agenda • Why do we need to move away from

    Passwords • Introducing Passkeys, the antidote to Passwords • Adding Passkeys to a WebApp with .NET 10 © 2026 Rock Solid Knowledge 2
  2. What are passwords • A shared secret • Been used

    for 1000s of years • To effectively protect, It should be • unique per site • Not guessable • May have to meet minimum complexity rules © 2026 Rock Solid Knowledge 3
  3. Issues with passwords Issue #1 : Non technical people are

    responsible for creating strong passwords • Password complexity rules “assist” • It must be at least eight characters • It must have upper and lower case letters • It must have a digit • It must have a special symbol • Password1! for the win • Ridiculous rules • Can’t have two characters the same next to each other • Limiting the characters you can use, sorry can’t use $ • Must change it every 90 days © 2026 Rock Solid Knowledge 4
  4. Issues with passwords Issue #2, Make it strong, make it

    unique per site but don’t write it down • How many sites do you have accounts with? • Without assistance, you probably can’t do both • How many internet users know about or use password managers? © 2026 Rock Solid Knowledge 5
  5. Issues with passwords Issue #3: One big honey pot •

    Bad actors love stealing passwords from websites • A customer has to trust the site stores the password securely • If passwords are re-used, it only takes one site to leak the secret © 2026 Rock Solid Knowledge 6
  6. Issues with passwords Issue #5: Multiple Attack Vectors • Can

    be susceptible to many attack vectors • Password Spraying • Credential Stuffing • Phishing • When “stolen”, can be hard to know © 2026 Rock Solid Knowledge 7
  7. Phishing • What percentage of cyber security incidents start with

    an employee getting phished? • 91% of cyber attacks begin with a phishing email to a victim. • Passwords, SMS , TOTP can’t prevent phishing © 2026 Rock Solid Knowledge 8
  8. Passkeys to the rescue • WebAuthN built into the browser

    • The user is no longer responsible for generating a password • Generated securely and can’t be guessed • Credentials are unique to each site • Organisations don’t store user secrets • Anti-phishing • Credentials can never be used for the wrong site © 2026 Rock Solid Knowledge 11
  9. Registration • Unique Public/Private key pair generated bound to the

    website Registration www.kahootz.com All users Public Keys User Private Key Credential Store © 2026 Rock Solid Knowledge 12
  10. Private key store • Key per site • On a

    portable device • USB • NFC • On a platform • MacOS • Windows Hello • iOS • Andriod • Password Manager • 1Password • Apple Keychain © 2026 Rock Solid Knowledge Site Private Key www.kahootz.co.uk MIIBOgIBAAJBAKj34GkxFhD90vcNLYLIn FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu… www.bbc.co.uk FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu KUpRKfFLfRYC9AIKjbJTWit+CqvjWYzv… 13
  11. Authentication Request to Sign in with Passkey www.kahootz.com Server sends

    challenge User unlocks key, bound to kahootz Browser encrypts challenge with private key, sends to server Server gets user public key Server creates session © 2026 Rock Solid Knowledge The server verifies the encrypted challenge with public key
  12. Anti phishing authentication Request to Sign in with Passkey www.kahoootz.com

    Server sends challenge User unlocks key, bound to kahoootz FAILS, No KEY © 2026 Rock Solid Knowledge 15
  13. Data breach • Bad actors can only obtain • Usernames

    and Public keys • Public keys of no use in an attack © 2026 Rock Solid Knowledge User Public Key [email protected] MIIBOgIBAAJBAKj34GkxFhD90vcNLYLIn FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu… [email protected] FEX6Ppy1tPf9Cnzj4p4WGeKLs1Pt8Qu KUpRKfFLfRYC9AIKjbJTWit+CqvjWYzv… 16
  14. Passkey support in .NET 10 • New ASP.NET Identity (V3)

    • SignInManager – Create and Verify Keys • UserStore – Extensions to store keys and find keys • EF Migrations required to support passkeys • Provides .NET APIs that consume JSON from WebAuthN API calls • You need to provide API endpoints to facilitate the Passkey handshakes • Registration • Verification © 2026 Rock Solid Knowledge 17
  15. Bootstrapping ASP.NET identity for EF • ApplicationDbContext for UserStore •

    Add Identity Version 3 • Bind to EF Provider public class ApplicationDbContext(DbContextOptions<ApplicationDbContext> options) : IdentityDbContext<IdentityUser>(options); builder.Services.AddDbContext<ApplicationDbContext>(options => options.UseSqlServer(builder.Configuration.GetConnectionString("IdentityConnection"))); builder.Services .AddIdentity<IdentityUser,IdentityRole>(options => { options.Stores.SchemaVersion = IdentitySchemaVersions.Version3; }) .AddEntityFrameworkStores<ApplicationDbContext>() .AddDefaultTokenProviders(); © 2026 Rock Solid Knowledge 18
  16. Registering a passkey Client Side • Server side generates the

    options to supply to navigate.credentials.create • navigate.credentials.create requires some of the options to be in a binary format • PublicKeyCredential.parseCreationOptionsFromJSON converts the JSON format returned by the server into a compatible form (binary encoded) const options = await PublicKeyCredential.parseCreationOptionsFromJSON(optionsAsJson); // Browser interacts with user to create the passkey // credentials returned contains, credential id and public key, (server side will process this) const credentials = await navigator.credentials.create({publicKey:options}); © 2026 Rock Solid Knowledge 20
  17. Registering a passkey Server Side • Create two API endpoints

    • Start registration – issue create credential options • Complete registration – validate browser response, store credentials © 2026 Rock Solid Knowledge 21
  18. Registering a passkey Server Side – Passkey Creation Options •

    Id : Server side id for the user (typically a guid) • Display Name: The name of the key (e.g. 1Password Key) • Name : Server side sign-in name for the user var passKeyEntity = new PasskeyUserEntity() { Id = …, DisplayName = …, Name = … }; string creationOptions = await signInManager.MakePasskeyCreationOptionsAsync(passKeyEntity); return Ok(creationOptions); © 2026 Rock Solid Knowledge 22
  19. Registering a passkey Server Side – Verify and Store New

    Passkey Credentials • passkeyCredentialsAsJson: JSON result from WebAuthN • user: IdentityUser to bind the passkey credential to • PerformPasskeyAttestationAsync validates the new credential • AddOrUpdatePasskeyAsync associates the credential with a user PasskeyAttestationResult attestationResult = await signInManager.PerformPasskeyAttestationAsync(passkeyCredentialsAsJson); var addResult = await userManager.AddOrUpdatePasskeyAsync(user, attestationResult.Passkey); © 2026 Rock Solid Knowledge 23
  20. Registering a Passkey Authenticators • An authenticator will only allow

    one credential per site • If the authenticators support usernames, can have multiple credentials, but only one per username • Avoids the situation where you create multiple passkeys for the same site on the same Authenticator © 2026 Rock Solid Knowledge 24
  21. Sign-in with a Passkey Client Side • Server side generates

    the options to supply to navigate.credentials.get • navigate.credentials.get requires some of the options to be in a binary format • PublicKeyCredential.parseRequestOptionsFromJSON converts the JSON format returned by the server into a compatible form (binary encoded) const options = await PublicKeyCredential.parseRequestOptionsFromJSON(optionsAsJson); // Browser attempts to find credentials for site from an authenticator // If found encrypts challenge with private key const credentials = await navigator.credentials.get({publicKey:options}) // send credentials to server to validate © 2026 Rock Solid Knowledge 26
  22. Sign-in with a Passkey Server Side – Passkey Request Options

    • user : the IdentityUser if known • requestOptions : JSON to return to browser for input to navigator.credentials.get method string requestOptions = await signInManager.MakePasskeyRequestOptionsAsync(user); © 2026 Rock Solid Knowledge 27
  23. Sign-in With a Passkeys Server Side – Passkey Credential Validation

    • credentials : stringyified JSON from the browser navigator.credentials.get method • requestOptions : JSON to return to browser for input to navigator.credentials.get • PasskeySignInAsync validates credentials, and if ok signs the user in SignInResult result = await signInManager.PasskeySignInAsync(credentials); if (!result.Succeeded) { return Unauthorized(); } © 2026 Rock Solid Knowledge 28
  24. Username can be optional at sign-in • Only for resident

    Passkeys • Providing a username provides hint to authenticators • If you have multiple Passkey authenticators, routes quicker { "challenge" : "4ig2yq3yQvMhuN85ezYR0V5-aaNEyFu3_U5BWQezPDXh6Gv8YRgidQdRCFLK3wynOVvwJRdVfqMVgNooGb6pOw", "timeout" : 180000, "rpId" : "localhost", "allowCredentials" : [ { "type" : "public-key", "id" : "0mBp9IY-nedaWsU_eQ4WkMImjY0", "transports" : [ "hybrid", "internal" ] } ], "userVerification" : "required", "hints" : [ ] } © 2026 Rock Solid Knowledge 29
  25. Auto sign-in • Does NOT show a modal popup •

    Integrates with the login form • Passkeys in the username field dropdown • Works like password autofill • Makes for a good user experience <input type="text" id="userName" name="userName" class="form-control” autocomplete="username webauthn"/> . . . const credentials = await navigator.credentials.get({publicKey:options,mediation:"conditional"}); © 2026 Rock Solid Knowledge 30
  26. Safe account recovery • What happens if I loose my

    Passkey? • Need a trusted fallback mechanism • Passkeys are a very strong authenticator • Falling back to a weaker mechanism weakens the use of passkeys • SMS • TOTP • Email • Recovery needs to be at least as strong, only viable option is via support • Unless Passkeys are just being used for convenience and a stronger password © 2026 Rock Solid Knowledge 31
  27. Prevent the need for account recovery • Users use a

    keystore that is backed up • Password Managers • OS Platforms • Create multiple keys per account • Create UX to encourage it © 2026 Rock Solid Knowledge 32
  28. Passkeys in .NET 10 – 1Password Interop issue • Passkeys

    stored in 1Password return a credential without clientExtensionResults • This causes server-side failure: • “JSON deserialization… missing required properties including: clientExtensionResults” • Solution • On the client side manually serialize the credential, and assign an empty object clientExtensionResults property © 2026 Rock Solid Knowledge 33
  29. UX • Adoption requires consistent look and feel across the

    entire internet • Passkeys will eventual become as common as username and password • FIDO alliance have UX style guide • https://fidoalliance.org/wpcontent/uploads/2023/05/FIDO-Alliance-UXGuidelines-for-Passkey-Creation-and-Signins.pdf © 2026 Rock Solid Knowledge 34
  30. Adopt passkeys today • Phishing Resistant • Frictionless • It

    is becoming the standard authentication method of the web © 2026 Rock Solid Knowledge This SurveyMonkey online poll was conducted April 13-14, 2025 among a global sample of 1,389 adults ages 18 and up. Respondents for this survey were selected from the nearly 3 million people who take surveys on the SurveyMonkey platform each day. Data for this survey has been weighted for age, race, sex, education, and geography to adequately reflect the demographic composition of the United States, United Kingdom, China, South Korea and Japan. The modeled error estimate for this survey is plus or minus 3.5 percentage points. 35
  31. Summary • Passwords are not safe for the modern age

    • Hard to manage • Multiple attack vectors • Passkeys • Easy to manage, Strong credentials • Anti-phishing • Need to action today © 2026 Rock Solid Knowledge 36
  32. Contact Information • [email protected] • https://www.linkedin.com/in/andy-clymer/ • Want to know

    more about Passkeys • fido.identityserver.com • For help and advice [email protected] • Open.IdentityServer, the free forever OIDC/OAuth platform • Single Sign-On (SSO) • Identity and Access Management • Authorization © 2026 Rock Solid Knowledge 37