What is a passkey, how does it work and why is it better than a password?

A picture


The UK’s National Cyber Security Centre has called time on the password – from now on, you should use a passkey.The NCSC said this week it would no longer recommend using passwords where passkeys were available.They should be consumers’ first choice of login across all digital services because passwords were not secure enough to stand up to modern cyber threats.Security officials describe a passkey as a “digital stamp” that allows you to sign in to apps and websites and is stored on your device.It is a password-free form of login.

Unlike a password, it cannot be stolen in a phishing attack, where people are fooled into handing over their credentials, which can later appear on the dark web,It just requires your smartphone or device to confirm that it is you trying to log in, by using biometric methods such as facial recognition or your phone’s pin,That triggers the “stamp” – or secure passkey – which confirms to the app or website that you are who you say you are,Each account you are registered with will have a different passkey,Even if an app or website using passkeys is breached, it is of no use to an assailant because the device holds the “private” passkey needed to complete a login.

Passkeys can also be synced across devices,The NCSC says you can go to account security or privacy settings on apps and websites you already use, or look out for prompts from services asking you to upgrade to passkeys,You may also be offered to set one up when creating a new account for an app or website,Google says just over 50% of users of its services in the UK have a passkey registered,They are not passwords, which can be wheedled or conned out of users via phishing emails or can be found on the dark web.

Last year, researchers at Cybernews, an online tech publication, said they had found billions of login credentials.The datasets were in the format of a URL, followed by login details and a password.Experts were sceptical about the report, saying the data was probably already in circulation online and many of the details could be duplicates.Nonetheless, they said it emphasised the need to update passwords regularly and adopt tough security measures such as two-factor authentication, where users are asked to give another form of verification along with their password.“Passwords have never been a perfect solution from a user perspective because we need to keep adding things to try and make them more secure,” said Dave Chismon, a senior tech expert at the NCSC.

“And yet, they are still phishable and the extra security involved makes users’ lives harder.“Whilst the technology is complex, for a user passkeys are quicker and simpler than remembering a password or going through two-factor authentication.”Bypassing biometric checks on a device is difficult.Alan Woodward, a professor of cybersecurity at Surrey University, says facial recognition has improved significantly.“It’s not just the recognition algorithms that have become better but devices now include ‘proof of liveness’ to stop images being used.

As with all cybersecurity it’s a game of whack-a-mole.Hackers’ ploys improve and the countermeasures also improve,” he says.There could be an issue with, for instance, a family member or partner knowing your phone pin.Experts say an obvious defence against this is keeping your pin private – even from family members.A major threat to people’s personal cybersecurity is their own behaviour.

“Most attacks against individuals still happen because of a lack of basic cyber-hygiene – getting the fundamentals right really does work,” said Chismon,Some basic recommendations are to get passkeys or, if you are using passwords, to use two-factor authentication,Another is to always use strong passwords, especially a strong and separate one for your email account,And use a password manager, which creates and stores passwords securely,You should update apps and operating software on your devices regularly.

Phishing attacks, where assailants attempt to access your login details or trick you into downloading malicious software, can be avoided by looking out for (and not clicking on) dodgy-looking emails, links and attachments.The most common passwords in the world look like a godsend for hackers.According to Nordpass, a password manager app that stores passwords securely, the most used password – based on an analysis of public data breaches and dark web data stockpiles – is “123456”.Others in the top 10 are “admin”, “password” and “admin123”.If those are your passwords, then passkeys are definitely for you.

technologySee all
A picture

Grok tells researchers pretending to be delusional ‘drive an iron nail through the mirror while reciting Psalm 91 backwards’

Elon Musk’s AI chatbot Grok 4.1 told researchers pretending to be delusional that there was indeed a doppelganger in their mirror and they should drive an iron nail through the glass while reciting Psalm 91 backwards.Researchers at the City University of New York (Cuny) and King’s College London have published a paper on how various chatbots protect – or fail to safeguard – users’ mental health.Experts are increasingly warning that psychosis or mania can be fuelled by AI chatbots.The Cuny and King’s pre-print study – which has not been peer-reviewed – examined five different AI models: Open AI’s GPT-4o and GPT-5

A picture

Microsoft and Meta announce large staff reductions as they spend big on AI

Meta and Microsoft are trimming their workforces by thousands as they make heavy investments in AI and executives claim that the technology is meeting their companies’ productivity needs.Meta told staff on Thursday that on 20 May it would cut some 10% of its personnel – just under 8,000 employees– to boost efficiency, part of a layoff plan made months ago. The company is also closing about 6,000 open roles. The same day, Microsoft announced to employees, for the first time, that it would offer voluntary retirement to about 7% of its American workforce of roughly 125,000.In an internal memo to Meta’s staff, Janelle Gale, the chief people officer, didn’t mention AI explicitly but said the cuts would allow the company to “offset the other investments we’re making”

A picture

Thousands call on UK ministers to cut ties with US tech giant Palantir

More than 200,000 people have called on ministers to break contracts with Palantir in an apparent groundswell of public concern about the US tech company’s role in the NHS, police, military and councils.Two petitions have attracted 229,000 signatures, one calling for the government to end all public contracts with the company, the software of which is used by Donald Trump’s ICE immigration enforcement programme and the Israeli military, and another urging the health secretary, Wes Streeting, to cancel its £330m patient data contract with the NHS.This week, the Guardian revealed the Metropolitan police was in talks to use the company’s AI to analyse sensitive intelligence, and Palantir published a manifesto described by one MP as the “ramblings of a supervillain”.But the tech company is pushing back against the multipronged campaign challenging its work in the UK by taking issue with claims made widely on social media by the Green party leader, Zack Polanski, and the legal campaigner Jolyon Maugham, who this week launched a podcast investigation into Palantir. The Liberal Democrats are also calling for the NHS contract to be cancelled and new contracts to be halted

A picture

Private health records of half a million Britons offered for sale on Chinese website

The confidential health records of half a million British volunteers have been offered for sale on Chinese website Alibaba, the UK government has confirmed.The “de-identified” data, belonging to participants in the UK Biobank project, was found for sale on three separate listings last week. Ian Murray, the technology minister, told the Commons on Thursday that, after working with the Chinese government and Alibaba, the records had now been removed. It is not believed any sales were made.The latest breach comes after the Guardian revealed last month that sensitive UK Biobank data has been exposed online dozens of times, raising further questions about whether security has been too lax

A picture

Some Interrail travellers told to cancel passports as hacked data posted online

Holidaymakers across Europe are facing the stress and expense of getting new passports after their personal data was posted on the dark web after a hack of the Interrail company Eurail.Personal data, including passport numbers, names, phone numbers, email and home addresses and dates of birth of more than 300,000 European travellers was accessed in December. But this week Eurail revealed to customers that “data copied during the security incident has been offered for sale on the dark web and a sample dataset has been published on Telegram”.The announcement has led to renewed anger and confusion. The UK Passport Office has told at least one customer they needed to “cancel their passport to prevent it being used for fraudulent activity”, with the Home Office agency also indicating they needed to pay the full £102 fee for a replacement

A picture

Chinese hackers using everyday devices to target UK firms, warns cybersecurity agency

British businesses are being urged to step up their vigilance against a China-linked hacking ploy that uses everyday devices for espionage.The UK’s National Cyber Security Centre (NCSC) and agencies in nine other countries have warned of persistent attempts by Beijing-backed groups to hack equipment such as wifi routers to launch cyber-attacks.Known as “covert networks” or “botnets”, they typically target vulnerable equipment – for instance devices that have not had a software update or are old – as a base for staging activities such as surveillance and data theft.The NCSC said the technique was used by the majority of China-linked hackers. Richard Horne, the centre’s chief executive, said on Wednesday that China’s intelligence and military agencies had an “eye-watering level of sophistication in their cyber-operations”