All projects
ResearchIn testing

Identity without SMS

An authentication path built on passkeys and hardware keys, and never on a code received by text message.

Updated

Roadmap

One-time codes over SMS remain the most widely deployed second factor, and one of the weakest: a phone number can be hijacked at the carrier, with no trace on the victim’s side.

The hard part is not technical — WebAuthn is mature — but account recovery. That is where most rollouts quietly reintroduce SMS through a back door, and precisely what this research is trying to avoid.

Technologies

  • WebAuthn
  • Passkeys
  • Zero Trust

Milestones

2 / 4
  1. Done —Passkey registration path
  2. Done —Account recovery with no SMS channel
  3. Upcoming —Hardware keys for admin access
  4. Upcoming —Measuring drop-off against SMS