Unlike passwords, which can be stolen, or QR codes, which scammers can trick users into scanning, passkeys verify a private key stored on the user’s device against a public key registered in the Singpass system.
Because no passwords or one-time passwords are entered or transmitted during login, there is nothing for scammers to intercept – even if a user lands on a fraudulent website.
If a device is lost or stolen, the Singpass app and the passkey on it will be automatically deactivated when the user sets up Singpass on another device.
Read Full Article At Source





