In light of a massive data breach revealing 16 billion passwords exposed online, it's time to critically examine our reliance on passwords as the primary form of digital security. This breach, reported by Cybernews, highlights a stark reality: the password, once a staple of online security, is increasingly inadequate against sophisticated cyber threats.
The leaked data, harvested through malware known as infostealers, includes credentials for significant platforms like Apple, Google, and Facebook. This breach not only endangers accounts protected solely by passwords but also raises concerns regarding the effectiveness of two-factor authentication (2FA). If an account doesn't reset its cookies after a password change, attackers could potentially bypass 2FA, using stolen session tokens.
Given these vulnerabilities, cybersecurity experts are advocating for a shift away from traditional passwords to more secure alternatives, such as passkeys. Passkeys are tied to personal devices and require strong authentication methods like biometrics, making them significantly less susceptible to theft.
While not all services currently support passkeys, users should enhance their password security by employing strong, unique passwords, utilising password managers, and activating 2FA wherever available. As the landscape of cybersecurity evolves, so must our approaches to safeguarding our digital identities.
Enter Passkeys: The Future of Authentication
Cybersecurity professionals are urging a shift toward passkeys, a modern, phishing-resistant alternative. Unlike passwords:
What You Can Do Right Now
Until passkeys become universal, here are practical steps to safeguard your online life:
As users, we must take proactive steps, but platforms also need to accelerate the shift away from password dependence.
You may have read
Jason article about 16 billion passwords being leaked online, including data from Apple, Google, and more. If you've not, you should..
It's clear that passwords alone aren't enough anymore. Even 2FA isn't bulletproof if stolen session cookies can be reused.
Are passkeys the answer? Is anyone here actually using them yet? How should we be protecting ourselves?
Would love to hear your thoughts, and whether we should be worried or not.
The leaked data, harvested through malware known as infostealers, includes credentials for significant platforms like Apple, Google, and Facebook. This breach not only endangers accounts protected solely by passwords but also raises concerns regarding the effectiveness of two-factor authentication (2FA). If an account doesn't reset its cookies after a password change, attackers could potentially bypass 2FA, using stolen session tokens.
Given these vulnerabilities, cybersecurity experts are advocating for a shift away from traditional passwords to more secure alternatives, such as passkeys. Passkeys are tied to personal devices and require strong authentication methods like biometrics, making them significantly less susceptible to theft.
While not all services currently support passkeys, users should enhance their password security by employing strong, unique passwords, utilising password managers, and activating 2FA wherever available. As the landscape of cybersecurity evolves, so must our approaches to safeguarding our digital identities.
Enter Passkeys: The Future of Authentication
Cybersecurity professionals are urging a shift toward passkeys, a modern, phishing-resistant alternative. Unlike passwords:
Passkeys are tied to your device.
They often rely on biometric authentication (like Face ID or fingerprint).
They're nearly impossible to phish or reuse.
What You Can Do Right Now
Until passkeys become universal, here are practical steps to safeguard your online life:
- Use a password manager – Tools like Bitwarden, 1Password, or LastPass can generate and store unique passwords.
- Enable 2FA – Use an app (like Authy or Google Authenticator) rather than SMS where possible.
- Reset passwords – If your accounts were part of a known breach, change your credentials immediately.
- Regularly clear sessions – Log out of devices and reset your sessions after changing your password.
- Check if you were breached – Use Have I Been Pwned to see if your email or password appears in public leaks.
As users, we must take proactive steps, but platforms also need to accelerate the shift away from password dependence.
You may have read
It's clear that passwords alone aren't enough anymore. Even 2FA isn't bulletproof if stolen session cookies can be reused.
Are passkeys the answer? Is anyone here actually using them yet? How should we be protecting ourselves?
Would love to hear your thoughts, and whether we should be worried or not.