It breaks nothing. No vulnerability to patch. Both ends see a login that worked, because one did. A zero-day needs a flaw nobody has found yet. This one needs no flaw at all.
MagicEndpoint · End-to-end cryptography
The most secure login is
no login at all.
The global industry gives the warning on AI-enabled attacks.
WinMagic gives the fix.
Let us tell you
how ↓
Your endpoint holds a key that exists only while you are there. It proves who you are on every connection. No password, no prompt, and no token for anyone to steal.
What is the biggest cybersecurity threat right now?
AI-enabled attacks. AI makes attacks faster, cheaper and far more convincing, and breach data already shows it.
The industry's warning
More than a thousand technology, security and financial organizations signed one letter urging the industry to act immediately: AI-enabled attacks will become far more widespread and sophisticated in the coming months, the window to strengthen defenses is limited, and the status quo will not be enough.
How do you fight AI attacks?
The industry's recommendation is more tooling. That will not cut it, because the flaw is in the tools. Cryptography is used everywhere in security, but in pieces. Online, cryptography is the best defense, and humans cannot do cryptography. So the endpoint does it for you, on every connection.
The mother of all attacks.
What is an adversary-in-the-middle attack?
It is the one attack that defeats every login method in use today without breaking any of them. It lets the real person complete the real login, and takes what comes out of it.
It beats every method. Password, one-time code, push, passkey. It takes the result, so the factor does not matter.
It leaves no signal. The attacker ends up holding a legitimate session.
AI removed its one cost. A lure convincing enough to fool a careful person is now close to free.
Proofpoint reported in December 2024 that almost half of all accounts taken over had MFA configured.
Why is adversary-in-the-middle the hardest attack to stop?
Because nothing in the exchange is false. A relay does not steal an identity. It steals the result of a real login, so a stronger way of proving who you are does not help.
The real person signed in. The real identity provider approved it. Neither of those says who is holding the token a second later.
Do passkeys and FIDO2 stop adversary-in-the-middle attacks?
Passkeys avoid the attack. They do not solve it. Passkeys, built on FIDO2, are what most phishing-resistant MFA rests on today: the browser checks that the site is the real one, and where that check holds, the relay is refused. But the check rests on many parts that all have to stay correct (the browser, names, certificates, enrolment, recovery), it is not there outside the browser, and the login still ends in a token that works for whoever holds it.
How do you stop adversary-in-the-middle attacks?
Make the login produce a key that exists only on your endpoint and cannot be copied off it. Relay every byte and the attacker still holds nothing usable, because the part that matters never left the machine. That is what MagicEndpoint does.
What is the best defense against AI cyberattacks?
End-to-end cryptography, starting at the login: a login that produces a key, with the party you are about to talk to.
Nothing in use for online access today does it. Passwords, multi-factor and passkeys all end in a verdict that the login succeeded, and something agreed separately protects what follows. That seam is what AI-enabled attacks exploit. We published this flaw in 2024, before AI made it urgent.
How does mutual TLS secure a login?
In mutual TLS, both sides prove who they are in one handshake, and that same handshake produces the key that protects everything they say next. Machines have worked this way for decades. It never reached people, because it asked them to carry cards and handle certificates. What was missing was a key that could stand for a person. The endpoint provides it.
That is the whole picture
How do you strengthen login against AI attacks without replacing Entra ID, Okta or Ping?
Three moves, one for each part of online access. None of them waits for an application rewrite or a new standard.
Close it
MagicEndpoint signs you in from the endpoint's hardware to the identity provider you already run.
- No password
- No one-time code
- No approval to tap
- No application changes
Shorten it, then bind it
Re-authentication needs no user action, so sessions can expire in minutes and nobody notices. Where Chrome offers device-bound sessions, turn them on too.
Narrow it, and test it
Nobody has closed this gap yet. Single-use, short-lived assertions and strict redirect validation narrow it. That is the part we want the world to test.
What is session hijacking or token theft, and how do we stop it?
Session hijacking is when an attacker steals the session token or cookie a service issues after login and uses it from their own machine. The token works for whoever holds it, so no password or MFA is needed.
-
1
Shorten sessions See the session card above.
-
2
Bind the token to the device Where the browser supports it.
-
3
Issue no token at all Carry identity in the connection itself. This step needs service providers, which is why we are asking them to build it with us.
How do you stop AI phishing and deepfake attacks?
Remove the prompt. AI makes a convincing fake page, email, deepfake voice or video almost free, and every other login keeps a human decision inside it for the fake to target. MagicEndpoint has none, so there is nothing to put in front of anyone.
A typical login
MagicEndpoint
No password, no code, no prompt. The key never leaves this device.
What it does not do
- A real-time relay, present at the moment a session is registered, is not removed.
- An endpoint that is already compromised is inside the boundary the design rests on.
- The decision moves to enrolment, where the key is bound to the person once, under controlled conditions.
- Your weakest enabled login sets the level. Check that no other method reaches the same resources.
We do not call it AI-proof or unphishable.
How can researchers and developers work with WinMagic on MagicEndpoint?
Three ways, all in the open: attack it, build the session side, or take it through the standards. No company closes this alone.
Attack it
We are preparing an open test of the authentication exchange. The scope, rules and written safe harbour will be published before it opens, and we will publish what comes back, including anything that succeeds. Register interest now.
Build the session side
Speak mutual TLS with the endpoint and login and session become one connection. The reference code is public; partners get further source.
Take it through the standards
A W3C proposal in March 2026, IETF drafts on workload identity and OAuth, and comments on the record with MITRE. Nothing proprietary.
What is MagicEndpoint?
MagicEndpoint is WinMagic's zero-trust passwordless authentication with no user action, built on end-to-end cryptography: a login that produces a key. It authenticates from the endpoint's hardware to the identity provider you already run. There is no password in the exchange, no one-time code, no approval to tap and no application changes.
What is AI phishing and how do I recognize it?
AI phishing uses generative AI to produce convincing fake emails, login pages, deepfake voices and video at scale, personalized and free of the mistakes people were trained to spot. Warning signs still include unexpected urgency, a link asking you to sign in or approve something, and a sender or domain name that is slightly off. But recognition alone is losing. The durable fix is a login with nothing to recognize: with passwordless, no-user-action login such as MagicEndpoint, there is no prompt for a fake to imitate.
What does an AI-enabled breach cost?
IBM's July 2026 study found that AI-enabled breaches cost organizations about $6 million on average, roughly $1 million more than the global average breach cost of $4.99 million. One in four malicious breaches was AI-enabled, up 56% in a year.
What is an adversary-in-the-middle attack?
An adversary-in-the-middle attack relays between the user and the real service. It lets the real person complete the real login and takes what comes out of it. It breaks nothing, beats every login method at once and leaves no signal, because both ends see a login that worked. AI removed its one cost: a lure convincing enough that a careful person proceeds.
Why is adversary-in-the-middle called the mother of all attacks?
Because it needs nothing to be wrong. Every other attack on a login needs a weakness: a guessed or stolen password, a phished code, a tired user tapping approve. Even a zero-day needs a flaw, and once the flaw is found, it can be patched. Adversary-in-the-middle needs no flaw at all, so there is nothing to patch, today or later. It works against a correctly configured system used by a careful person, it beats every login method at once, and AI has made the lure it needs almost free.
Is MFA enough to stop AI attacks?
Not on its own. The attack AI has made cheapest, adversary-in-the-middle, lets the real person pass MFA and then takes the result of the login. A relay does not steal an identity, it steals a result, so a stronger way of proving who you are does not help. Proofpoint reported in December 2024 that almost half of all accounts taken over had MFA configured.
What is end-to-end cryptography for login?
A login has to produce a key, with the party you are about to talk to. Passwords, multi-factor and passkeys all end in a verdict, a statement that the login succeeded, and then something agreed separately protects everything that follows. With end-to-end cryptography the login and the key that protects what follows are the same act, so there is no seam for a relay to use.
What is mutual TLS (mTLS)?
Mutual TLS is TLS in which both sides prove who they are with a key, not only the server. It has authenticated machines to each other for decades, and the same handshake produces the key that protects the connection. It never reached people because it asked them to carry cards and handle certificates. MagicEndpoint holds the key in the endpoint's hardware, so mutual TLS can stand for a verified person, with no user action.
What is passwordless authentication?
Passwordless authentication signs a user in without a password, usually with a key held on a device. Many passwordless methods still ask the user to approve a prompt or complete a ceremony, which an AI-generated fake can imitate. MagicEndpoint is passwordless with no user action at all: the endpoint proves its key on every connection.
Do passkeys and FIDO2 stop adversary-in-the-middle attacks?
Passkeys avoid the attack. They do not solve it. Passkeys, built on FIDO2, are what most phishing-resistant MFA rests on today: the browser checks that the site is the real one, and where that check holds, the relay is refused. But the login still ends in a token that works for whoever holds it, and outside the browser there is no check at all. Solving it means the login produces a key that never leaves your endpoint, so a relayed login is worth nothing. That is what MagicEndpoint does.
How do you stop adversary-in-the-middle attacks?
Make the login produce a key that exists only on your endpoint and cannot be copied off it. A relay can pass every byte and the attacker still holds nothing usable, because the part that matters never left the machine. This is end-to-end cryptography for login, and it is what MagicEndpoint does.
Does MagicEndpoint work beyond the browser?
It is designed to. Passkeys' protection against a relay is computed by the browser from the name of the site, so paths without a browser, such as desktop apps, RDP and SSH, are often left on a password. MagicEndpoint's key and policy live on the endpoint, not in the browser, and the same presence and policy conditions apply to those paths through the mechanism that fits each one, for example a per-service key for SSH. Check with WinMagic which protocols your deployment covers.
Does MagicEndpoint work with Microsoft Entra ID, Okta and Ping?
Yes. MagicEndpoint authenticates from the endpoint's hardware into the identity provider you already run, and it has been tested with Microsoft Entra ID, Okta and Ping. You do not replace your identity provider, and no application changes are needed.
What is session hijacking or token theft, and how do you stop it?
Session hijacking is when an attacker steals the session token or cookie a service issues after login and uses it from their own machine. The token works for whoever holds it, so no password or MFA is needed. Stop it in three steps: shorten sessions, which MagicEndpoint makes painless because re-authentication needs no user action; bind tokens to the device where the browser and identity provider support it; and carry identity in the connection itself, so no token is issued at all.
What can I deploy today?
Close the login with MagicEndpoint. Make sessions short, which becomes practical because re-authentication needs no user action, and bind them where the browser can, such as Google's device-bound sessions in Chrome. Narrow the transition between the identity provider and the application with single-use, short-lived assertions and strict audience and redirect validation.
What happens if the identity provider is down?
The policy engine is on the endpoint. Access keeps working through an outage and stops the moment posture degrades, so no break-glass account on a weaker method is needed.
What happens if a user loses a device?
The user keeps working from their other enrolled device. If a user loses their phone, their manager can approve sign-in to the computer at pre-boot or Windows login, confirming from the manager's own phone with a PIN or biometrics, so the user is not left waiting on a helpdesk ticket. If the computer is lost, it will not export its sign-in key, and where pre-boot authentication is deployed, its disk stays encrypted until someone authenticates at pre-boot. Talk to us about which recovery options fit your policy.
What does MagicEndpoint not protect against?
An attacker relaying in real time, present at the moment a session is registered, is not removed. An endpoint that is already compromised is inside the boundary the design rests on. The human decision does not vanish, it moves to enrolment, where the key is bound to the person once under controlled conditions, so enrolment is where the care goes. And if another, weaker login method still reaches the same resources, that method sets the security level. WinMagic does not call MagicEndpoint AI-proof or unphishable.
Can researchers test MagicEndpoint?
WinMagic is preparing an open test of the authentication exchange. The scope, rules and written safe harbour will be published before it opens, and WinMagic will publish what comes back, including anything that succeeds. The reference implementation of the key and the handshake is already public at github.com/WinMagic/LIT. Register interest at research@winmagic.com.
Stop asking people to spot better fakes. Let the endpoint do the cryptography.
Each step is worth having on its own, and the first one is running in production already.
Read the research