Australian flagJoin us at the FIDO seminar in Melbourne – Feb 7, 2025!

What are the risks of transitioning from SMS OTPs to passkeys?

Vincent Delitz

Vincent

Created: January 8, 2025

Updated: January 9, 2025

Do you want to learn more?

Read full blog post

What are the risks of transitioning from SMS OTPs to passkeys?#

Transitioning from SMS One-Time Passwords (OTPs) to passkeys is a significant step toward improving security and user experience. However, this process involves certain risks that organizations should carefully address.

risks transitioning sms otps to passkeys

Key Risks in Transitioning to Passkeys#

1. User Resistance to Change#

  • Some users may resist adopting new authentication methods due to unfamiliarity with passkeys.
  • Lack of understanding can lead to reduced trust and slower adoption rates.

2. Device and Browser Compatibility Issues#

  • Not all devices and browsers may support passkeys, particularly older models or outdated software.
  • This can leave some users unable to authenticate if fallback methods are not maintained.

3. Disruption During the Transition#

  • A poorly executed migration can result in user lockouts, login issues, or increased support inquiries.
  • Testing and phased rollouts are essential to minimize disruption.
Substack Icon

Subscribe to our Passkeys Substack for the latest news, insights and strategies.

Subscribe

4. Security Gaps in Hybrid Systems#

  • During the transition period, maintaining both SMS OTPs and passkeys can create potential vulnerabilities.
  • It’s crucial to ensure that both methods are secure and cannot be exploited simultaneously.

5. Lack of MFA Fallbacks#

  • Removing SMS OTPs without providing other fallback methods could alienate users who are not ready for passkeys.
  • Maintaining alternate MFA options ensures continuity and user accessibility.

Mitigation Strategies#

  • User Education: Provide clear guidance and resources to help users understand and adopt passkeys.
  • Compatibility Analysis: Use tools like Corbado’s Passkeys Analyzer to assess your user base’s readiness for passkeys.
  • Gradual Rollouts: Transition to passkeys in phases, starting with a subset of users before expanding.
  • Maintain MFA Fallbacks: Keep SMS OTPs or other MFA options available during the initial rollout.

Conclusion#

While transitioning from SMS OTPs to passkeys has numerous benefits, careful planning and execution are necessary to mitigate risks. Addressing user resistance, ensuring compatibility, and maintaining robust fallback options will help ensure a smooth and successful transition.

Do you want to learn more?

Read full blog post

Share this article


LinkedInTwitterFacebook

Enjoyed this read?

🤝 Join our Passkeys Community

Share passkeys implementation tips and get support to free the world from passwords.

🚀 Subscribe to Substack

Get the latest news, strategies, and insights about passkeys sent straight to your inbox.


We provide UI components, SDKs and guides to help you add passkeys to your app in <1 hour

Start for free