Newsportal

 

 

International recognition

IT security: A landmark award for a computer scientist from Wuppertal

20.08.2026|09:30 Uhr

Christian Mainka, a professor of computer science at the University of Wuppertal, and colleagues from Ruhr University Bochum and Heilbronn University of Applied Sciences were honoured at one of the world’s most prestigious conferences on IT security for their work on security vulnerabilities associated with the use of passkeys. The technology enables users to log in to websites without a password.

Smartphone liegt auf Laptop, der Smartphonebildschirm zeigt ein Schutzschild mit einem Schloss

Passkeys are a modern technology that completely replaces traditional passwords. // Photo: Colourbox/#185712

“Passkeys represent a significant step forward for IT security. Our analysis highlights where improvements are still needed,” explains Christian Mainka, professor of Robust, Secure and Privacy-Preserving Smart Systems at the University of Wuppertal. His colleague from Bochum and lead author of the study, Louis Jannett, elaborates: “Until now, there has been a lack of a comprehensive security analysis evaluating passkey-enabled websites. Our research not only fills this gap but also provides website developers and operators with tools to make future authentication technologies even more secure.”  

The USENIX Security Conference is a world-leading, vendor-neutral forum for cutting-edge international research in IT security. The Distinguished Paper Award presented there to the research team from Germany is regarded as one of the most prestigious honours in the field of IT security.

Why passkeys are so important

The award-winning paper examines the security of a modern authentication technology considered to be extremely secure: passkeys. Passkeys replace the traditional password with a digital key pair – one part remains securely stored on the user’s own device, such as a smartphone or laptop, whilst the other is stored by the website operator.

Given that billions of passwords continue to be stolen worldwide, this offers significant advantages for users. “Passkeys protect us from so-called phishing: unlike passwords, they cannot be stolen via fake websites. The web browser automatically recognises whether the website is genuine before releasing the digital key,” explains Mainka. This eliminates the risk posed by weak passwords, as well as the hassle of having to remember complex passwords; the login experience is significantly more convenient and secure for users.

Mann mit Brille, blaues Hemd, kurze Haare, leichter Vollbart, mitteldunkles Haar, lächelt

Prof. Dr Christian Mainka // Photo: Friederike von Heyden

Implementation still flawed

Through their study, the researchers sought to find out more about the current state of this relatively new technology, which has only been available to users for just over five years. In the process, they discovered that its implementation on many websites is still flawed. For instance, security tests were not implemented correctly, which could lead to real risks such as account takeover or users being locked out of their accounts. “The underlying technology remains secure. We’re finding the vulnerabilities on the websites that offer this login method. With the help of our findings, they can now improve the implementation of the technology in their systems,” reports Louis Jannett. The researchers also contacted the website operators concerned and drew their attention to the security vulnerabilities, some of which were serious.

For users, the findings do not change anything. At present, passkeys are usually offered only as an additional login option and are not yet proposed as a complete replacement for passwords. “Uncovering such security vulnerabilities is a standard research procedure that further improves new technologies and, so to speak, cures them of their teething problems. This also demonstrates just how important research is,” explains Prof. Mainka.

An award with symbolic significance

For the Wuppertal-based scientist, the award he has won represents more than just a significant personal honour from the scientific community. The computer science professor attaches great importance to the symbolic significance it carries. Despite the AI boom, computer science remains indispensable, particularly in the field of cyber and information security. Companies, for example, urgently need specialists who can develop and implement secure authentication and protection systems.

“At the University of Wuppertal, this is precisely what we are focused on: shaping our digital future securely. Through our research, we are making an important contribution to the global advancement of cyber security – and that is what this award also stands for. In our teaching, we focus on practical training to educate the next generation of computer scientists,” emphasises Mainka, who has directly incorporated the methodology and findings of the Passkey study into his lectures. In doing so, he also appeals to prospective students not to let anything dampen their motivation to study computer science.

Methodology and results of the study

In their work, the researchers developed two key tools: Passkey-Radar is a database that provides the most comprehensive overview to date of Passkey-enabled websites and their prevalence since 2021. The Passkey-Attacker is a testing tool that enables the researchers to simulate 15 different attack scenarios and thereby specifically identify vulnerabilities in the application of the technology.

Analysis of a total of 103 websites tested reveals that none of the sites examined meets all the required security checks; more than half of the sites exhibit serious vulnerabilities, and in 18 cases, particularly critical vulnerabilities were found.

Link to the publication

Jannett, L., Mayer, A., Westers, M., Mladenov, V., Mainka, C., & Schwenk, J. The State of Passkeys: Studying the Adoption and Security of Passkeys on the Web.

* The rights to use this image are held by the university of Wuppertal. It is not licensed for publication by third parties.