Passkey Technology is Making Credential-Based Attacks Impossible

Jasson Casey and Josh Johansen talk about how passkey technology is great for security.

Phishing attacks don’t succeed because people are stupid or careless. They succeed because passwords are stealable. That’s a big problem. And in industries like hospitality, a single wrong click can compromise an entire organization. The idea of a world without passwords seems like it would be more dangerous, but passkey technology means it may actually be more secure. Device-bound identity may turn out to be the future of security.


See Identity Without Passwords with Jasson Casey and Josh Johansen for a complete transcript of the Easy Prey podcast episode.

Jasson Casey is the co-founder and CEO of Beyond Identity, a company providing an identity security platform that makes credential-based attacks impossible. His background is technical, and he started his career as an engineer designing and building largescale security systems. Today, that’s still what he does, just with a much bigger scope.

Josh Johansen is the Director of IT Systems and Technology at Brandt Hospitality Group, the organization that owns and operates hotels, including the Marriott, Hilton, Hyatt, and IGH brands. He worked at hotels to put himself through aviation school, but graduated just after 9/11, when there weren’t a lot of opportunities for pilots. The hotel he worked at asked him if he’d ever considered becoming a hotel manager, and at first he was against the idea, but eventually decided to give it a try. After ten years in operations, he moved to the support side and worked his way up from there.

Solving Credential Attacks for Hospitality

Hospitality is an industry that is extremely vulnerable to phishing. Hospitality roles don’t hire people for their technical knowledge and ability to be suspicious of every email – they hire people for friendliness, outgoing personality, sales ability, and willingness to help guests. That’s pretty much everything a cybercriminal loves in a target.

Hospitality is very vulnerable to phishing attacks.

Josh Johansen

Brandt Hospitality Group’s cyber insurance required them to have multi-factor authentication (MFA). Each individual brand under the group had its own solution, and Josh was already hearing complaints about MFA fatigue because people had to put in the little codes so much. He was looking for a solution with less friction. He had gone through a multi-month process with one company that looked like a good option, but at the last minute there was a typo in the contract that needed fixed before he would sign. The company came back and said that they’d just had a meeting this morning, and the company was dropping all unsigned contracts with less than a certain number of users, effective immediately.

So Josh ended up going back through the other options he’d previously looked at trying to find a replacement, and one of the companies he reached out to was Beyond Identity. They replied to his initial message within an hour, and put together a demo of their passkey technology that afternoon. The process went quickly, and soon they were rolling out a solution.

Training Isn’t Enough Protection

The best folks in the hospitality industry will go above and beyond to help guests or potential guests. Which means they may also do things that are not secure as part of that. Part of security compliance requires employees to do cyber awareness training. But no matter how much training people have, a single click can circumvent it. There has to be a layer of protection on the technical side, too.

The reality is it just takes one click for [training] to go out the window if you don’t have some other layer of protection on the back end.

Josh Johansen

Josh loves passkey technology as a solution because it takes that massive vulnerability away. People have so much going on. The general manager of a hotel is thinking about budgets, sales, metrics, logistics, scheduling, and more on a regular basis. They have a long list of things coming at them all the time. And now we’re asking them to become cybersecurity experts and putting the responsibility to avoid phishing on them, too. It’s another thing on their plate taking them away from making their hotel successful.

Passkey technology is something Josh can do on the support side to help. It gets rid of that attack surface entirely. Hotel operations staff don’t have to worry about identifying if a message is legitimate anymore. Even if they click on a phishing message, it can’t do any damage. We’ve all been conditioned that good passwords are key to good security, and it’s a mental shift to have a system with no password that’s actually more secure. But once people adjust, it’s not only more secure, it’s more efficient.

How Passkey Technology Solves Phishing

The big thing Beyond Identity did to protect Josh’s hotels from phishing was get rid of the password that criminals can steal. Most phishing attacks are designed to steal credentials. But if there is no password, it doesn’t matter if someone clicks on the phishing message or not – a criminal can’t steal something that doesn’t exist.

With Beyond Identity, everyone at Brandt Hospitality Group is using this passkey technology instead of a password. Not long after the rollout, Josh got a call from a manager convinced she needed a password. She got a message that looked like an overdue invoice from a travel agency, and she wanted to pay it. When she clicked on the link, it went to a Microsoft login page, but it asked for a password instead of giving the passkey prompt. Josh told her that it was phishing and she could ignore it, but she was convinced she had to pay this invoice.

That was an eye-opening event for Josh. This person was great at her job and very in-tune with what was going on, but was still vulnerable to this phishing attack. And this wasn’t the only similar call Josh got, either. This is how he knew the shift to passkey technology was the right way to go. Suddenly, passwords were no longer a breach point. Switching to passkeys can be a difficult mental shift for people sometimes. But Josh thinks it’s completely worth it.

I know that the passkey is a bit of a lift for folks, but it’s well worth the effort.

Josh Johansen

How Passkey Technology Works

Beyond Identity’s passkey technology doesn’t replace a company’s existing protections – it just gets added in, like an identity protection module for whatever else you’re using. It does that by taking over authentication and taking advantage of hardware that exists on pretty much all modern devices to create a passkey that can’t move.

Really secure passkey technology creates passkeys that can't move and so can't be stolen.

The majority of security incidents are based on stealable credentials. This includes passwords, but also things like API bearer tokens, access tokens, session cookies, SSH keys, and similar things. Anything that can be copied can also be stolen. And in modern technology architecture, things get copied a lot.

70-80% of all security incidents that you deal with right now are based on stealable credentials … anything that can be copied can be stolen.

Jasson Casey

Beyond Identity’s big innovation is developing a system where you don’t have to move the thing you want to keep secure. Think of it like a small jail with no doors holding a monkey with a pen. If you need something signed, you pass the document through the bars to the monkey and the monkey signs it and passes it back. The pen can’t be stolen because it never leaves that jail. That pen can even have additional conditions, like requiring biometrics or a PIN. This is the same thing that happens when you use Apple Pay or Google Pay to buy something.

Of course, you can only trust this device-bound credential if the hardware itself isn’t compromised. So you also need other security on the device. And the device also needs to be secure enough for whatever the user is trying to access. So the authentication isn’t just about who you are, but also about what the device is and how secure it is. And the authentication is continuous.

Common Mistakes with Passkey Technology

Josh didn’t come to his role from an IT background. All of his IT understanding has been from what he learned through working on processes and with partners as part of his role. So he’s not always entirely clear on the nuances of the terminology. That was occasionally a difficulty when getting Beyond Identity integrated. There were many points where something wasn’t working how it should, and it turned out to be because what Josh had said they had was slightly different from what they actually had. A good understanding of how identity and credentials currently function in your organization is crucial to getting passkey technology implemented properly.

Another mistake some companies make when making this change is securing higher-level people with access, but leaving lower-level employees with stealable passwords. But compromise through a lower-level employee login is still a compromise that can do a lot of damage. Have a rollout plan for how you’re going to secure different groups and also how you’re going to train and educate them about the shift. It’s also crucial to integrate it into your onboarding going forward.

Much of the switch to passkeys is a mental shift. Most organizations are constantly being targeted with phishing, and there’s a non-zero percentage of those attacks that work. Removing the bit of the equation that makes clicking on phishing links dangerous is a different perspective. Users are still clicking, but there’s no longer anything to steal. One of Beyond Identity’s other customers had a dedicated phishing response team, but once they implemented passkey technology, that team had to start working on other tasks. So many security incidents come back to phishing, and passkeys can get rid of those compromises.

You don’t have to get better detection. You could actually make [phishing] go away.

Jasson Casey

Beyond Identity Does Passkey Technology Differently

One thing that comes up in any conversation about passkeys is the passkey rollouts that companies like Google, Facebook, and Amazon have started doing. Josh has had a couple instances where new employees have heard they use passkeys and have complained that their Google or Facebook passkey doesn’t work and requested to have a password instead.

But these companies have a few key differences from Beyond Identity’s passkey technology. One is that you can still use your password even if you have the passkey set up. Beyond Identity doesn’t support passwords at all. The second is that these consumer passkeys can be moved and copied, so they’re not nearly as secure.

Think of Beyond Identity’s passkey like your Android Wallet or Apple Pay. It’s based on the device – when you get a new phone, you have to put your card info in again. Beyond Identity’s passkeys are tied to devices like that. You have to get it set up on every device you want to use it on. But once it’s set up, there’s no logging in or MFA codes or resetting your password every ninety days. Once you’ve unlocked the device, you can access everything you need.

Consumer Passkeys are Solving a Different Problem

When Jasson’s team developed the Beyond Identity passkey technology, they had all kinds of cool, technical names for it. But the marketing team said no – people knew the term “passkeys,” so they would call it that for the familiarity. But the consumer passkeys you see on websites like Facebook and Amazon are solving a different problem. The consumer marketplace doesn’t care about security. They care about conversion rates. These passkeys aren’t about keeping your accounts more secure, they’re about making it quicker and easier to do what you’re trying to do.

Consumer passkeys are very much about the consumer marketplace. And the consumer marketplace generally does not actually care about security.

Jasson Casey

This isn’t a bad thing. But it’s solving a different problem. When you register a new device with one of these consumer passkeys, the passkey gets copied through the cloud to that new device. And because it’s copyable, it’s stealable. Beyond Identity’s passkeys, on the other hand, don’t move. When you register a new device, it creates a new, device-bound, immovable passkey, but sets it up as a “child” of an existing device, so it’s essentially being authorized by another device. Enterprise-scale passkeys are fundamentally different from consumer passkeys. They both provide ease of access, but for enterprise passkeys that’s a side effect of better security.

Learn more about Beyond Identity at their website, beyondidentity.com. They also recently launched an exciting agent identity project at beyondidentity.ai. You can also connect with them on Twitter @beyondidentity or LinkedIn, or connect directly with Jasson Casey and Josh Johansen on LinkedIn.