Skip to content

Occulta vs Passkeys

Yura edited this page Jun 27, 2026 · 1 revision

What Passkeys Actually Are (and Who Controls Them)

A passkey is a FIDO2 credential — a P-256 key pair generated on your device, where the relying party (a website or service) stores your public key and challenges you to prove the private one each time you authenticate.

The third-party control problem:

  • Apple/iCloud Keychain syncs your passkeys across your devices. That sync goes through Apple's servers — you are trusting Apple to store, secure, and transmit your private key material (encrypted, but Apple-operated infrastructure).
  • Google Password Manager does the same for Android and Chrome.
  • 1Password, Bitwarden, Dashlane — commercial passkey managers — hold your passkeys in their cloud vaults, behind their auth, on their servers.
  • The relying party (the website) ultimately controls what "you" means. If a service disables your account, your passkey is useless even if you still have the private key — the server decides.

The private key may never leave hardware in theory. In practice, the sync mechanism that makes passkeys usable across devices introduces an intermediary that controls recovery, availability, and continuity.

The central vulnerability: Passkeys are bound to accounts, not to you. If Apple disables your Apple ID, you lose your passkeys. If a passkey provider is subpoenaed, they can produce the encrypted vault. If iCloud Keychain is compromised, so is every passkey synced through it.


Occulta's Fundamental Difference

Property Passkeys Occulta
Key generation On-device (correct) On-device, Secure Enclave
Key custody Synced via Apple/Google/password manager Never leaves the SE — ThisDeviceOnly
Identity root Email or phone number (account-based) Physical proximity ≤ 25 cm (UWB-gated)
Trust anchor Certificate authority / platform vendor Physics — you were standing next to them
Who can revoke your identity Apple, Google, the relying party Nobody. The key is yours.
Third-party dependency Mandatory (platform vendor syncs/holds keys) Zero
Subpoena exposure Apple/Google hold encrypted vaults Nothing exists to produce
Server infrastructure Required (relying party auth server) None
Account compromise path Exists (Apple ID, Google account phishing) No account to compromise
Cross-device availability Automatic (via sync) Manual (by design — no sync = no leak)
Post-quantum resistance None (standard FIDO2 is classical P-256) ML-KEM-1024 hybrid (iOS 26+)
Forward secrecy Not applicable (authentication, not encryption) Per-message ephemeral prekeys (v3fs)

The Precise Attack Surface Passkeys Leave Open

1. Platform Vendor Compromise

iCloud Keychain holding synced passkeys is a high-value target. Apple's server infrastructure could be compelled by law (CLOUD Act, national security letters), breached, or fail — taking your passkeys' availability with it. Your passkey exists at the pleasure of the platform.

2. Account Takeover Transference

Passkeys are protected by your Apple ID or Google account. SIM-swap your phone number → reset Apple ID → access iCloud Keychain → all your passkeys. Occulta's key is hardware-bound to a specific Secure Enclave chip. Compromising any account gives an attacker nothing — there is no account that controls the key.

3. Relying Party Control

A passkey for a banking app is only valid while the bank's servers accept it. The bank can disable your account, invalidate your credential, or change authentication requirements without your consent. Occulta identities are not controlled by any third party.

4. Metadata and Enrollment Linkage

Passkey enrollment creates a record: your device registered with this service at this time, from this IP, on this platform. That metadata exists on the relying party's servers and is subpoenable. Occulta UWB key exchange produces no server-side record of the exchange — nothing to produce.

5. Self-Enrollment MITM (No Physical Bootstrap)

FIDO2 assumes you're registering your own device — but it cannot verify the human relationship. A passkey for "alice@company.com" proves a device authenticated, not that Alice physically gave you her key. Occulta's UWB ceremony (≤ 25 cm + Diceware voice verification) is unforgeable — no remote attacker can insert a key without being physically present.


Where Passkeys Are Better

Passkeys are the right tool for website authentication. Occulta doesn't compete there:

  • Broad ecosystem support — works everywhere FIDO2 is supported (thousands of sites)
  • Cross-device sync — genuinely convenient for most users; Occulta's deliberate non-sync is a security tradeoff, not universally superior
  • No in-person requirement — for most people, in-person key exchange is friction without payoff
  • Platform-maintained — Apple/Google handle recovery; Occulta requires users to manage their own migration

Passkeys are excellent at replacing passwords. They are not designed for what Occulta does: establishing a trust graph of physically-verified human identities, enabling serverless E2E encryption across any channel.


The Positioning

Passkeys solve the password problem. Occulta solves the identity problem.

Passkeys ask: "Is this device authorized to access this account?"
Occulta asks: "Is this person who they say they are, cryptographically — and did I verify that in person?"

These are different questions. Passkeys are account-layer trust. Occulta is physical-presence trust. Both are right for what they were designed for. Only one of them has no server — and only one of them can prove you were in the room.


Talking Points

  • "Passkeys are the right tool for login authentication. They weren't designed for what Occulta does: a physically-bootstrapped, serverless identity layer."
  • "The FIDO2 standard explicitly describes passkeys as bound to a relying party. Your identity in Occulta is bound to a Secure Enclave chip on your specific device — no relying party exists."
  • "Passkey sync is a deliberate convenience tradeoff. Occulta's ThisDeviceOnly constraint is a deliberate security tradeoff. Different tools, different audiences, different threat models."
  • "Passkeys can be used by anyone who controls your Apple ID. Occulta requires your SE and biometrics on a specific device — account recovery gets you nothing."
  • "Passkeys require a server to be valid. Occulta identity is valid offline, forever, because there's no server to validate against — the key is the identity."

Claims to Avoid

  • ❌ "Passkeys are insecure" — they are significantly better than passwords
  • ❌ "Passkeys are broken" — no known cryptographic weaknesses in FIDO2
  • ❌ "Occulta replaces passkeys" — they solve different problems
  • ❌ "Passkeys expose your keys" — iCloud Keychain encrypts synced material
  • ❌ Implying Occulta prevents account takeover — it doesn't

Clone this wiki locally