Passkeys are the future of authentication, offering enhanced security and convenience over passwords, but widespread adoption faces challenges that the NCSC is working to resolve.

What’s wrong with passwords – why do we need passkeys?

Most cyber harms that affect citizens occur through abuse of legitimate credentials. That is, attackers have obtained the victim’s password somehow – whether by phishing or exploiting the fact the passwords are weak or have been reused.

Passwords are just not a good way to authenticate users on the modern internet (and arguably weren’t suitable back in the 1970s when the internet was used by just a few academics). Adding a strong – phishing-resistant – second factor to passwords definitely helps, but not everyone does this and not every type of Multi-Factor Authentication (MFA) is strong.


More

Security Boulevard: Driving Passwordless Adoption with FIDO and Biometric Authentication

The Passwordless Imperative For decades, passwords have been the default mechanism for securing digital access.…

Read More →

Biometric Update: Maker builds FIDO2-compliant LionKey USB dongle for passwordless security

With their fiddly and indirect nature, one-time passwords (OTPs) are a curse of modern life.…

Read More →

Cybersecurity Market: Bitwarden Doubles Down on Identity Security as Passwords Finally Start to Lose Their Grip

Bitwarden’s latest round of product updates reads less like a feature dump and more like…

Read More →


123307 Next

Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.