According to Verizon DBIR Report 2023, 80% of web application attacks are due to stolen credentials/passwords. While MFA is introduced to reduce the attacks, it is not immune to phishing. It's time to think beyond passwords. FIDO2 standards define specifications to go passwordless. Let us see what the standards define and how to implement them.