Facebook
Britain's News Portal
Around The Clock
BREAKING
Loading latest headlines…

Passkeys: Are Smartphone Pins Truly Safer Than Complex Passwords?

Experts advocate for passkeys as a superior security measure, despite public concerns over smartphone theft. This new authentication method aims to combat prevalent online hacking risks.

  • Passkeys offer enhanced security over traditional passwords by eliminating the 'shared secret' vulnerability.
  • They are unique to a device and unphishable, as the passkey itself is never transmitted to the website.
  • Concerns exist regarding the security of passkeys if a smartphone is lost or stolen, though experts suggest rapid revocation is possible.
  • The National Cyber Security Centre (NCSC) supports the adoption of passkeys for improved digital safety.

The age-old problem of passwords has long plagued our online lives, but it seems a new kid on the block could be about to shake things up. Passkeys, touted by the UK's National Cyber Security Centre (NCSC) as a significant step forward in digital security, are gaining traction – and sparking debate among users and experts alike.

A core advantage of passkeys lies in their underlying technology, which cleverly sidesteps the weakness inherent in passwords: the 'shared secret'. When logging in with a password, it must be transmitted to a website for verification, creating a potential vulnerability if the website's server is compromised. In contrast, a passkey initiates a complex mathematical calculation on the user's device, sending only the result to the website for verification – and crucially, the passkey itself remains on the device.

This 'unphishable' nature is a key differentiator. Unlike passwords, which can be stolen remotely through phishing attacks from anywhere in the world, a passkey's vulnerability is largely confined to physical access to the device it's stored on. Experts argue that while a stolen phone poses a risk, users are typically quick to notice such an event and can promptly revoke access to their accounts – unlike password breaches, which can go unnoticed for extended periods.

For UK businesses, the shift towards passkeys presents both opportunities and challenges. Enhanced security could reduce the financial and reputational damage caused by data breaches, which are increasingly costly. However, implementing passkey support requires investment in new infrastructure and potentially user education – and it's not just about tech firms stepping up their game: regulators like the UK ICO and EU AI Act will likely encourage adoption of such advanced security measures.

Despite the advantages, some users remain wary, preferring their own methods of password management or worrying that the push for passkeys might be driven by software companies rather than genuine necessity. Yet cybersecurity professionals are united in their view: passkeys represent a robust evolution in digital protection, offering a significant upgrade from password-based systems.

Why this matters: Understanding passkeys is crucial for UK individuals and businesses to navigate the evolving digital security landscape, protecting personal data and financial assets from sophisticated cyber threats.

What this means for you: What this means for you: Adopting passkeys could significantly enhance your online security, making your accounts less vulnerable to hacking and phishing attempts, even if it means adjusting to a new login method.

Related Articles

Get the news that matters.

Join thousands of readers getting the best of British news straight to their inbox.