惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

月光博客
月光博客
小众软件
小众软件
爱范儿
爱范儿
Y
Y Combinator Blog
博客园 - Franky
美团技术团队
博客园 - 【当耐特】
The Cloudflare Blog
罗磊的独立博客
Hugging Face - Blog
Hugging Face - Blog
Jina AI
Jina AI
IT之家
IT之家
人人都是产品经理
人人都是产品经理
奇客Solidot–传递最新科技情报
奇客Solidot–传递最新科技情报
让小产品的独立变现更简单 - ezindie.com
让小产品的独立变现更简单 - ezindie.com
大猫的无限游戏
大猫的无限游戏
Apple Machine Learning Research
Apple Machine Learning Research
博客园 - 聂微东
WordPress大学
WordPress大学
V
Visual Studio Blog
博客园_首页
阮一峰的网络日志
阮一峰的网络日志
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
有赞技术团队
有赞技术团队

The Guardian

New Zealand’s North Island braces for Cyclone Vaianu with thousands ordered to evacuate Artemis II splashdown – in pictures Swalwell denies allegations of sexual assault as calls grow for him to withdraw from California governor race Trump news at a glance: Epstein survivors have words for Melania Trump after surprise statement Multiple people face charges, including murder, in California fireworks blast Rory McIlroy surges into six-shot Masters lead with stunning second-round flourish Roberto De Zerbi targets ‘Ange-ball’ revival to save Spurs from relegation Bath hit back to reach semi-final after stunning Northampton in 11-try epic Australia crash out of BJK Cup after Britain secure upset with doubles win Zebras, wealth and power: Hungary’s election tests Orbán’s grip on power ‘TikTok effect’ brings sellout crowds and younger fans to Grand National meeting King signs up David Beckham to his Chelsea flower show team The war over Omagh’s gold: the £21bn mine plan tearing a community apart Britain’s shadow workforce is paid as little as 65p an hour. Who cares for the carers? Tim Dowling: my wife is on a quest to restore my thinning hair SUVs are making Britain’s potholes worse, say scientists Blind date: ‘She claimed she was usually shy. I wouldn’t have guessed’ I’m a sauna person now: the Becky Barnicoat cartoon ‘I got everything I dreamed of – when I had no ability to handle it’: Lena Dunham on toxic fame, broken friendships and her ‘lost decade’ Six great reads: the man who let snakes bite him, masked heavy metal and the brutal reality for foreign students in the UK Meera Sodha’s recipe for noodles with rose beancurd, spring greens and egg Cuba’s doctors were a lifeline for the world. Now the Caribbean is shamefully complicit in the US drive to expel them An environmental disaster in Moldova has Russia’s fingerprints all over it ‘This is as important as your teeth’: are you skipping this key part of mouth hygiene? Man arrested after four die trying to cross Channel in small boat Ukraine war briefing: doubts linger in Kyiv over Moscow’s promise to uphold Orthodox Easter ceasefire Ichiro Suzuki statue unveiling goes awry as bronze bat snaps during ceremony Arrest of national war hero Ben Roberts-Smith cuts deeply to core of Australian psyche European football: Real Madrid held at home by Girona to extend winless run ‘You come back different’: how rugby players change after motherhood
What is a passkey, how does it work and why is it better ...
Dan Milmo Gl · 2026-04-24 · via The Guardian

The UK’s National Cyber Security Centre has called time on the password – from now on, you should use a passkey.

The NCSC said this week it would no longer recommend using passwords where passkeys were available. They should be consumers’ first choice of login across all digital services because passwords were not secure enough to stand up to modern cyber threats.


What is a passkey?

Security officials describe a passkey as a “digital stamp” that allows you to sign in to apps and websites and is stored on your device.

It is a password-free form of login. Unlike a password, it cannot be stolen in a phishing attack, where people are fooled into handing over their credentials, which can later appear on the dark web.

It just requires your smartphone or device to confirm that it is you trying to log in, by using biometric methods such as facial recognition or your phone’s pin. That triggers the “stamp” – or secure passkey – which confirms to the app or website that you are who you say you are. Each account you are registered with will have a different passkey.

Even if an app or website using passkeys is breached, it is of no use to an assailant because the device holds the “private” passkey needed to complete a login.

Passkeys can also be synced across devices.


How do you set up a passkey?

The NCSC says you can go to account security or privacy settings on apps and websites you already use, or look out for prompts from services asking you to upgrade to passkeys. You may also be offered to set one up when creating a new account for an app or website.

Google says just over 50% of users of its services in the UK have a passkey registered.


Why are passkeys good?

They are not passwords, which can be wheedled or conned out of users via phishing emails or can be found on the dark web.

Last year, researchers at Cybernews, an online tech publication, said they had found billions of login credentials. The datasets were in the format of a URL, followed by login details and a password. Experts were sceptical about the report, saying the data was probably already in circulation online and many of the details could be duplicates. Nonetheless, they said it emphasised the need to update passwords regularly and adopt tough security measures such as two-factor authentication, where users are asked to give another form of verification along with their password.

“Passwords have never been a perfect solution from a user perspective because we need to keep adding things to try and make them more secure,” said Dave Chismon, a senior tech expert at the NCSC. “And yet, they are still phishable and the extra security involved makes users’ lives harder.

“Whilst the technology is complex, for a user passkeys are quicker and simpler than remembering a password or going through two-factor authentication.”


Is facial recognition vulnerable?

Bypassing biometric checks on a device is difficult. Alan Woodward, a professor of cybersecurity at Surrey University, says facial recognition has improved significantly.

“It’s not just the recognition algorithms that have become better but devices now include ‘proof of liveness’ to stop images being used. As with all cybersecurity it’s a game of whack-a-mole. Hackers’ ploys improve and the countermeasures also improve,” he says.

There could be an issue with, for instance, a family member or partner knowing your phone pin. Experts say an obvious defence against this is keeping your pin private – even from family members.


What other precautions should people follow?

A major threat to people’s personal cybersecurity is their own behaviour. “Most attacks against individuals still happen because of a lack of basic cyber-hygiene – getting the fundamentals right really does work,” said Chismon.

Some basic recommendations are to get passkeys or, if you are using passwords, to use two-factor authentication. Another is to always use strong passwords, especially a strong and separate one for your email account. And use a password manager, which creates and stores passwords securely.

You should update apps and operating software on your devices regularly. Phishing attacks, where assailants attempt to access your login details or trick you into downloading malicious software, can be avoided by looking out for (and not clicking on) dodgy-looking emails, links and attachments.

The most common passwords in the world look like a godsend for hackers. According to Nordpass, a password manager app that stores passwords securely, the most used password – based on an analysis of public data breaches and dark web data stockpiles – is “123456”. Others in the top 10 are “admin”, “password” and “admin123”. If those are your passwords, then passkeys are definitely for you.