ResearchIn testing
Identity without SMS
An authentication path built on passkeys and hardware keys, and never on a code received by text message.
Updated
Roadmap
One-time codes over SMS remain the most widely deployed second factor, and one of the weakest: a phone number can be hijacked at the carrier, with no trace on the victim’s side.
The hard part is not technical — WebAuthn is mature — but account recovery. That is where most rollouts quietly reintroduce SMS through a back door, and precisely what this research is trying to avoid.
Technologies
- WebAuthn
- Passkeys
- Zero Trust
Milestones
2 / 4- Done —Passkey registration path
- Done —Account recovery with no SMS channel
- Upcoming —Hardware keys for admin access
- Upcoming —Measuring drop-off against SMS