Passkeys in Production: How One Developer Replaced Passwords with Face ID in Three Days Using FastAPI and Next.js
Passkeys are no longer future technology. They already power authentication in major banking apps on phones, including Alpha-Bank, Tinkoff, and Sber. GitHub, Apple, and Google have also adopted them. Yet many web services still require users to create passwords with uppercase letters, numbers, and special characters, followed by monthly reset prompts.
Yaroslav Morozov, who builds Continental IT consulting and an internal product, decided to skip password friction when implementing authorization. The team chose Passkeys and completed the rollout in three days. This article delivers complete production code from database migration to the Face ID login button, using FastAPI on the backend and Next.js on the frontend.
Why Passkeys Matter
Passkeys offer superior security and convenience. Passwords can be phished on fake sites, while Passkeys bind cryptographic keys to the correct domain. Database leaks expose bcrypt hashes that attackers can crack, but private keys never leave the device. Users no longer need to invent, remember, or reset passwords; a fingerprint or facial scan suffices. Unlike reused passwords across sites, each Passkey pair is unique per domain.
According to the FIDO Alliance, more than 15 billion accounts already support Passkeys. Google, Apple, and Microsoft have integrated support at the operating system level. Technically, Passkeys implement the WebAuthn standard from the FIDO2 family.
How Passkeys Work
A Passkey consists of an asymmetric key pair. The private key resides in the device Secure Enclave and never leaves it. The public key is sent to the server during registration. During authentication the server issues a random 32-byte challenge. The device signs it after biometric confirmation, and the server verifies the signature with the stored public key. No password travels over the network.
Discoverable credentials enable automatic synchronization across devices via iCloud Keychain on Apple platforms or Google Password Manager on Android. Passkeys replace only the login-password step; after successful verification the backend still issues standard JWT access and refresh tokens.
Database Schema and Models
Two PostgreSQL tables store everything. The webauthn_credentials table holds credential_id, public_key, sign_count, transports, and device_name. The webauthn_challenges table manages one-time challenges with a five-minute TTL. SQLAlchemy models map these tables with proper relationships and cascade deletes.
Backend Service with py-webauthn
The service uses only three environment variables for RP ID, RP name, and origin. Custom exceptions handle verification failures, missing credentials, and deactivated accounts. Methods generate registration and authentication options, verify responses, save and pop challenges, and manage user credentials. All cryptographic operations rely on the mature py-webauthn library.
Related articles
Yandex Disk Files Become Partially Inaccessible After Sasovo Data Center Incident
A detailed user report reveals that approximately one percent of files stored on Yandex Disk are currently unavailable for download following reported incidents at the Sasovo data center. The problems manifest in three distinct states: missing thumbnails with downloadable originals, visible thumbnails with inaccessible originals returning 504 Gateway Time-out errors, and cases where both thumbnails and originals fail to load. Technical analysis using curl requests traced the failures to specific storage nodes such as s418klg.storage.yandex.net, indicating that some data shards may reside in affected infrastructure while others remain operational. Yandex support requested original files for diagnosis but closed the ticket without providing an official explanation or confirming data integrity. The author emphasizes that the issue affects files across both the Photos and Files sections and recommends maintaining offline backups due to the lack of guaranteed availability during data center failures.
Keurig K-Supreme Smart Coffee Maker Generates Nearly 1 TB of Outbound Traffic in Ten Days
A Keurig K-Supreme Smart coffee maker unexpectedly produced around 1008 GB of outgoing traffic over ten days, overwhelming a home UniFi access point while generating only 9.94 GB of inbound data. The device had been placed on a separate network segment, yet the traffic remained largely internal to the home LAN rather than traversing the internet connection. The anomaly was discovered by user Nomad while assisting family members with network maintenance through the UniFi dashboard. After the coffee maker was powered off, the issue could not be reproduced in subsequent testing, and no packet captures were available to determine the content or root cause of the traffic. The model requires internet connectivity for remote control, scheduling, capsule recognition, and automatic reordering of coffee supplies. No similar incidents have been reported by other users, and the manufacturer has not issued any statement regarding the event.
Hash Functions Part 1: Core Properties, Security Requirements and Practical Applications
The article provides a detailed introduction to hash functions, explaining how they map arbitrary-length input to fixed-length output while satisfying three fundamental security properties. It covers preimage resistance, second preimage resistance, and collision resistance, along with the avalanche effect that makes even minor input changes produce unrecognizable output. The text explains why a 256-bit digest is required to achieve 128-bit collision resistance, referencing the birthday paradox and its implications for MD5 and SHA-1. Practical guidance includes using OpenSSL for hashing, applying hashes in commitment schemes, enforcing subresource integrity on web pages, and securely storing passwords with Argon2 and bcrypt. The post emphasizes that hash functions alone do not guarantee integrity without proper transmission of the digest and announces a follow-up on SHA-2 and SHA-3 internals.
Digital Twins Enable Pre-Deployment Testing and Post-Change Control in Complex Multi-Vendor Networks
UserGate and Hadal Project experts presented a joint approach at Saint HighLoad++ that combines physical labs, emulation, and simulation into a single lifecycle for validating network changes. The method addresses recurring failures such as IPsec tunnel outages after routine software updates that pass vendor checks yet break branch connectivity. Three complexity sources—multi-vendor environments, historical configuration debt, and continuous dynamic updates—are mitigated by maintaining an always-current network model. Physical laboratories provide hardware-level accuracy for critical devices, while uInfraTwin emulation allows rapid, repeatable testing of configuration scenarios with traffic generators. Simulation tools including Batfish, Hadal, Forward Networks, and IP Fabric deliver end-to-end reachability analysis across tens of thousands of nodes without sending test traffic on production networks. The integrated digital twin continuously updates from live infrastructure, feeds selected segments into safe test environments, and verifies policy compliance after deployment.