Passkeys are the future of authentication, offering enhanced security and convenience over passwords, but widespread adoption faces challenges that the NCSC is working to resolve.

What’s wrong with passwords – why do we need passkeys?

Most cyber harms that affect citizens occur through abuse of legitimate credentials. That is, attackers have obtained the victim’s password somehow – whether by phishing or exploiting the fact the passwords are weak or have been reused.

Passwords are just not a good way to authenticate users on the modern internet (and arguably weren’t suitable back in the 1970s when the internet was used by just a few academics). Adding a strong – phishing-resistant – second factor to passwords definitely helps, but not everyone does this and not every type of Multi-Factor Authentication (MFA) is strong.


More

CIO.com: Passwordless MFA: The Single Way To Mitigate the Top 5 Threats to Your Customer Identities 

Consumers are increasingly targeted by cybercriminals that use various techniques in account takeover (ATO) attacks.…

Read More →

Nextgov: CISA’s Newest Advisor Could Soon Have Agencies Asking: ‘Does This Spark Joy?’

Another CISA advisor has referred to Bob Lord as a “digital Marie Kondo,” tidying up…

Read More →

The Wall Street Journal: Technology Alliance Says it is Closer to Killing Off Passwords 

The FIDO Alliance, whose members include Apple, Google and Microsoft, says it is readying a…

Read More →


Subscribe to the FIDO newsletter

Stay Connected, Stay Engaged

Receive the latest news, events, research and implementation guidance from the FIDO Alliance. Learn about digital identity and fast, phishing-resistant authentication with passkeys.