Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.
The NCSC (a part of GCHQ) has officially declared a new era for digital security, announcing that passkeys are now ready for mass adoption and should be the primary login choice for all consumers.
The End of the Password Era
In a landmark report released at the CYBERUK conference in Glasgow, experts confirmed that traditional passwords are no longer resilient enough to withstand modern cyber threats. Consequently, the NCSC has overhauled decades of security guidance, no longer recommending passwords as the primary defense when passkeys are an option.
Why Passkeys?
- Superior Security: Technical analysis shows that passkeys are generally more secure than even the strongest password combined with two-step verification (2SV).
- User-Friendly: They eliminate the need to remember or type complex strings, requiring only a simple user approval (such as biometrics or a device PIN).
- Phishing Resistant: Because most cyberattacks begin with stolen credentials, passkeys represent a major breakthrough in neutralizing phishing attempts.
Market Readiness and Adoption
While the NCSC previously withheld a full endorsement due to technical hurdles, recent industry progress has resolved these concerns.
- Leading the Way: Major platforms like Google, eBay, and PayPal already support the technology.
- UK Momentum: The UK is currently a global leader in adoption; Google data reveals that over 50% of active UK users have already registered a passkey.
Recommendations
- For Individuals: Migrate to passkeys wherever possible to enjoy a “simpler and safer digital lifestyle.”
- For Businesses: Adopt passkeys as the default authentication option for customers to improve organizational resilience.
For services that do not yet support passkeys, the NCSC continues to advise consumers to use a password manager to generate strong, unique passwords combined with two-step verification (2SV).
However, shifting the default recommendation to passkeys marks a significant turning point in how we manage and protect our digital identities.
Primary Benefits of Passkeys
- Unmatched Speed: Passkey logins are frictionless and can be up to eight times faster than the traditional process of entering a username, password, and 2SV code.
- Built-in Phishing Protection: Unlike passwords, passkeys are highly resilient to social engineering. They cannot be guessed, intercepted by attackers, or reused across different sites.
- Elimination of Password Fatigue: Users no longer need to create or memorize complex passwords. This removes the temptation to use weak, predictable patterns or reuse passwords across multiple accounts.
- Cost-Effective Security: For service providers, passkeys are both safer and cheaper. They replace expensive SMS-based verification systems, reducing overhead while increasing security.
Government Implementation
Following its previous announcement, the UK government is actively rolling out passkey technology across its digital services. By moving away from SMS-based verification, the government expects to enhance national security while saving several million pounds annually in operational costs.
More reading
https://www.ncsc.gov.uk/news/ncsc-leave-passwords-in-the-past-passkeys-are-the-future