Passwordless authentication
Authentication that removes the password a user types and a server stores, commonly replacing it with a cryptographic key held on a device and unlocked locally by a PIN or biometric.
Passwordless authentication removes the shared secret that a user types and a server stores. The ISC2 exam outline names it as an example under objective 5.2. The common form uses a key pair held on the user’s device, such as a passkey built on the FIDO2 specifications or a key on a smart card. The server keeps only the public key, and the private key is unlocked locally by a PIN or biometric, so the device plus its unlock can meet multi-factor authentication.
Where the key is bound to the verifier and the password is removed rather than kept as a fallback, the relayable password and the stolen password database both go away. Device loss, account recovery and the strength of the unlock remain. A passkey that syncs between devices also moves part of the trust to the account and service that sync it, a point NIST SP 800-63B-4 Appendix B makes about syncable authenticators, and because its private key must be exportable it is not accepted at AAL3 (section 2.3.2). A sign-in by a code sent in a text message is also often called passwordless, but it is not phishing-resistant.
Exam relevance: questions in this area tend to turn on two traps, that passwordless means single-factor and that it removes all authentication risk. Candidates are expected to see account recovery and device loss as the remaining weak points.