Wednesday 

Room 3 

15:00 - 16:00 

(UTC+01

Talk (60 min)

Have I Been Pwned - A Passkey Journey

I am sure most of you have heard of passkeys by now. But how do they actually work? What's wrong with normal passwords? What is the difference? Do they improve user experience? What problems do they solve?

Application Security
Experience report
People

We decided to implement passkeys for Have I Been Pwned, gathered metrics and a lot of other data just so we could tell you about it!

I'll show you what we did, what technology we used and if it has made things better or worse, so you can do it too!

Stefán Jökull Sigurðarson

Stefán Jökull has been a professional programmer for over 20 years, although he wrote his first BASIC program on an old Amstrad CPC 464 way back in 1986. He works at Have I Been Pwned remotely from Iceland where he focuses on improving Have I Been Pwned. He has a lot of experience with systems that require attention to details and have high customer impact.

Stefán is also a Microsoft MVP, a member of the .NET Foundation, and specializes in all things .NET with a focus on performance, security, and analytics/telemetry.

When he's not working, he enjoys time with the family, working on OSS software, building Lego sets and having the occasional beer when meeting fellow developers.