E-mail senden E-Mail Adresse kopieren
2026-11-18

Exploring the Complexities of Passkey Revocation

Zusammenfassung

The passkey ecosystem lacks a way to invalidate access across authenticators and relying parties, as required in scenarios such as device theft, offboarding, or account unsharing. Although cryptographic revocation protocols have been proposed, they are not yet part of the ecosystem. Currently, users must sign in to each service and manually delete passkeys while tracking them across devices and passkey providers. In this work, we investigate passkey revocation from both technical and user perspectives. We systematize existing passkey revocation proposals and derive four revocation mechanisms that abstract cryptographic protocols into user-facing interaction models. We then conduct an online survey (n=308) to examine when users would consider revoking access across scenarios, complemented by semi-structured interviews (n=20) exploring users' awareness, concerns, and preferences regarding the four revocation mechanisms. We find that revocation intention closely follows perceived severity, with high-risk scenarios eliciting near-universal willingness to revoke, while lower-risk scenarios show more varied responses. Our qualitative results show that users perceive the available revocation flow as cumbersome and difficult to manage at scale, but also share conflicting opinions on the proposed mechanisms, none of which represents a ready-to-use solution. Our results highlight the need to design more usable revocation mechanisms, for which we provide recommendations.

Konferenzbeitrag

ACM Conference on Computer and Communications Security (CCS)

Veröffentlichungsdatum

2026-11-18

Letztes Änderungsdatum

2026-10-07