Here are this week’s topics that you don’t wanna miss out on!
🦁 Passkeys in Brave Browser (2026): What Works and Breaks
🛡️ Insurance Customer Portal Passkeys Guide
Brave runs Chromium’s WebAuthn code with exactly one visible change, a string that renames “Incognito” to “Private” in the passkey save dialog, so on paper passkeys should behave exactly like they do in Chrome. They do, right up to the moment the operating system gets involved. On de-Googled Android like GrapheneOS or CalyxOS, registration and sign-in simply time out, an open bug since April 2025 that Firefox does not share.
On Windows, switching off Brave’s passkey settings does not stop Windows Hello from appearing, because browser autofill settings never controlled the boundary between the page and the OS.
Since April 2024 the native prompt has also kept taking over Bitwarden and 1Password flows, with the flag people used to disable it gone since version 146. The three clusters have 24 open issues between them and none of them sit in the WebAuthn code itself. If your test matrix says “Chromium, so it is covered”, who is telling you about the Brave users who quietly gave up?
In October 2025 NYDFS fined eight auto insurers a combined 19 million dollars because their public-facing quoting systems had no MFA, which let attackers stuff credentials and collect driver data. The cost side is quieter: a carrier with 5 million policyholders logging in twice a month spends 1.2 to 6 million dollars a year on SMS codes alone.
Between 5 and 15 percent of those codes never arrive, in a channel where authentication questions already make up 20 to 40 percent of call center volume at 5 to 25 dollars a call.
Three carriers went first: Aflac sits at 500,000 passkey enrollments with a 96 percent login success rate, Branch cut support tickets roughly in half and HealthEquity made passkeys mandatory with no opt-out. The post then digs into what is actually different about insurers: one rpID across auto, home and life brands, agents versus policyholders and the fact that most customers log in maybe twice a year.
There is a four level maturity model at the end, written for the slide you will need in front of a board. If a policyholder only shows up after a claim, when exactly do you ask them to create a passkey?
Our mission is to free the world from passwords to make the Internet a safer place - this can only be accomplished together.
Join our passkeys community to connect with other passkey enthusiasts, stay up-to-date, get implementation support and show your passkeys projects!
No posts

Comments
Nothing yet. Say the first thing.
Sign in to join the conversation.