Webinar Description
Key Takeaways
- Technical deep-dive into hardware-backed signatures using passkeys and CTAP 2.3 protocol extensions
- Designed for developers and security engineers implementing phishing-resistant authentication
- Hosted by Yubico with hands-on demonstrations of YubiKey integration
- Addresses credential theft mitigation and password-free authentication workflows
- Virtual webinar format focused on practical implementation guidance
Introduction
DEV-TO-DEV: Building Hardware-Backed Signatures with Passkeys and CTAP 2.3 Extensions is a technical webinar aimed at developers and security engineers working on authentication systems. Hosted by Yubico, the session examines how hardware-backed cryptographic signatures can strengthen identity verification while reducing exposure to phishing attacks and credential theft. The timing reflects growing industry momentum behind passkeys as a password replacement, with CTAP 2.3 introducing capabilities that expand what hardware authenticators can accomplish within modern authentication flows.
About This Event
This virtual technical session provides practical guidance for integrating hardware security into authentication workflows. Rather than presenting conceptual overviews, the webinar emphasises hands-on demonstrations showing how passkeys and CTAP 2.3 extensions function in real implementation scenarios. Yubico, the company behind the widely adopted YubiKey hardware security key, leads the session with a focus on developer education.
The format suits practitioners who need to understand not just what these technologies do, but how to deploy them within existing application architectures. Attendees can expect code-level insights and configuration guidance rather than high-level marketing presentations.
Hardware-Backed Signatures and CTAP 2.3
Hardware-backed signatures differ fundamentally from software-based authentication by anchoring cryptographic operations to a physical device. Private keys never leave the hardware authenticator, which means they cannot be extracted through malware, phishing, or server-side breaches. This architecture provides stronger assurance that the person authenticating actually possesses the registered device.
CTAP 2.3, the latest version of the Client to Authenticator Protocol, extends the capabilities available to developers building on the WebAuthn standard. These extensions enable more sophisticated interactions between applications and hardware authenticators, supporting use cases that earlier protocol versions could not address. The session explores these new capabilities and demonstrates how they translate into practical authentication features.
The Shift Toward Passkeys
Passkeys represent a significant evolution in authentication, offering a credential type designed to replace passwords entirely. Built on FIDO2 and WebAuthn standards, passkeys combine the security benefits of public-key cryptography with a user experience that eliminates memorised secrets. Major platform vendors have integrated passkey support into operating systems and browsers, accelerating adoption across consumer and enterprise applications.
For organisations evaluating passkey implementations, hardware-backed options provide additional security guarantees. While platform authenticators store credentials within device secure enclaves, roaming authenticators like YubiKey offer portability and work across multiple devices without synchronisation dependencies. Understanding when to use each approach—and how to support both—is a key consideration for developers building flexible authentication systems.
Who Should Attend
The session targets technical practitioners responsible for authentication implementation. Software developers building identity features, security engineers designing access controls, and technical architects evaluating authentication strategies will find the content directly applicable. Product managers working on security roadmaps may also benefit from understanding the technical possibilities and constraints these technologies present.
Organisations with elevated security requirements—financial services, healthcare, government, and technology companies handling sensitive data—represent the primary audience. However, any team moving away from password-based authentication toward phishing-resistant alternatives will find relevant guidance.
Addressing Authentication Vulnerabilities
Credential theft remains one of the most exploited attack vectors in security breaches. Traditional passwords, even when combined with SMS or app-based second factors, remain vulnerable to phishing, SIM swapping, and real-time interception attacks. Hardware-backed authentication addresses these weaknesses by binding credentials to physical devices and requiring cryptographic proof of possession that cannot be replicated remotely.
The webinar examines how these protections work at a technical level and provides implementation patterns that developers can apply to their own applications. By grounding the discussion in standards-based protocols, the session ensures that attendees learn approaches compatible with the broader authentication ecosystem rather than proprietary solutions.

