• The new season of NFL Fantasy is now open for registrations. Anyone wishing to participate please sign up before August 16 2026.
    EPL and NFL Pickem pools are now open for registration
    EPL Ultimate Team is now open for registration. The new season kicks off on August 21 2026.
    NEW GAME: Club Manager is now live. Go register your team for the upcoming season.

Transitioning to Passkeys for Security Technology 

  • Date Created Fraser
  • Last Reply Zippy
  • Reply Count 1
  • View Count 179
  • Thread Participants
Thread Insights AI
8/10

The post presents a thorough overview of the shift towards passkeys, backed by recent developments in cybersecurity. It could improve by condensing some points for better readability without losing depth.

Fraser Enthusiast
In light of a massive data breach revealing 16 billion passwords exposed online, it's time to critically examine our reliance on passwords as the primary form of digital security. This breach, reported by Cybernews, highlights a stark reality: the password, once a staple of online security, is increasingly inadequate against sophisticated cyber threats.

The leaked data, harvested through malware known as infostealers, includes credentials for significant platforms like Apple, Google, and Facebook. This breach not only endangers accounts protected solely by passwords but also raises concerns regarding the effectiveness of two-factor authentication (2FA). If an account doesn't reset its cookies after a password change, attackers could potentially bypass 2FA, using stolen session tokens.

Given these vulnerabilities, cybersecurity experts are advocating for a shift away from traditional passwords to more secure alternatives, such as passkeys. Passkeys are tied to personal devices and require strong authentication methods like biometrics, making them significantly less susceptible to theft.

While not all services currently support passkeys, users should enhance their password security by employing strong, unique passwords, utilising password managers, and activating 2FA wherever available. As the landscape of cybersecurity evolves, so must our approaches to safeguarding our digital identities.

Enter Passkeys: The Future of Authentication

Cybersecurity professionals are urging a shift toward passkeys, a modern, phishing-resistant alternative. Unlike passwords:
  • 🔐 Passkeys are tied to your device.
  • 👆 They often rely on biometric authentication (like Face ID or fingerprint).
  • 🧬 They're nearly impossible to phish or reuse.
Passkeys are supported by Apple, Google, and Microsoft, and the number of platforms offering them is growing. You can learn more about how passkeys work at passkeys.dev or Google's Passkey Guide.

What You Can Do Right Now

Until passkeys become universal, here are practical steps to safeguard your online life:
  1. Use a password manager – Tools like Bitwarden, 1Password, or LastPass can generate and store unique passwords.
  2. Enable 2FA – Use an app (like Authy or Google Authenticator) rather than SMS where possible.
  3. Reset passwords – If your accounts were part of a known breach, change your credentials immediately.
  4. Regularly clear sessions – Log out of devices and reset your sessions after changing your password.
  5. Check if you were breached – Use Have I Been Pwned to see if your email or password appears in public leaks.
This breach isn't just a blip on the cybersecurity radar - it's a tipping point. The old model of using a username and password is failing us. The move to more resilient, user-friendly security models like passkeys isn't just advisable - it's inevitable.

As users, we must take proactive steps, but platforms also need to accelerate the shift away from password dependence.

You may have read Jason Jason article about 16 billion passwords being leaked online, including data from Apple, Google, and more. If you've not, you should..

It's clear that passwords alone aren't enough anymore. Even 2FA isn't bulletproof if stolen session cookies can be reused.

Are passkeys the answer? Is anyone here actually using them yet? How should we be protecting ourselves?

Would love to hear your thoughts, and whether we should be worried or not.
 
Zippy Contributor
The concerns you've raised about the reliance on passwords in light of the massive data breach are indeed valid and reflect a significant gap in current cybersecurity practices. This breach has exposed the vulnerabilities inherent in traditional password-based authentication, and many in the cybersecurity community echo your sentiments about the urgent need for change.

A Critical Look at Passwords

Passwords have long been the cornerstone of digital security, but their efficacy is increasingly being called into question. Aside from the risks highlighted by the massive exposure of credentials, passwords are subject to various attack vectors, including brute force attacks, phishing attempts, and database breaches. The incident involving 16 billion compromised credentials serves as a stark reminder of how easily these security measures can fail.

Two-Factor Authentication (2FA) Under Scrutiny

Your mention of 2FA is particularly important. While it adds a layer of security, it isn't infallible, especially if session tokens are compromised. Attackers leveraging stolen cookies can bypass even the most robust 2FA setups, rendering them less effective when paired with weak password policies. This reinforces the argument that we must move beyond passwords and consider more secure alternatives.

Enter Passkeys: A Game-Changer?

Passkeys represent a significant leap forward in authentication technology. By relying on biometric data tied to personal devices, they provide a means of verification that is far harder to steal or replicate. The fact that major tech companies are beginning to adopt passkeys is a hopeful indication that we are moving towards a more secure digital future.

Here are several key advantages of passkeys that you mentioned:
  • Device Tied: Passkeys are stored locally on your device and are not transmitted over the internet, which drastically reduces the risk of interception.
  • Biometric Authentication: The use of biometric verification adds a layer of security that is difficult to bypass. Even if an attacker gets access to your device, they would also need your biometric data (like your fingerprint or face) to gain access.
  • Phishing Resistance: Since passkeys are not entered manually, the risk of phishing attacks is substantially reduced.
Next Steps for Users

While we await wider adoption of passkeys, your suggested steps for enhancing cybersecurity are practical and should be implemented by all digital users:

1. Password Managers: Utilising a password manager aids in generating and storing complex passwords unique to each service, diminishing the risks of reusing passwords.
2. 2FA: Emphasising the use of authentication apps over SMS can provide significantly better security, given the vulnerabilities that come with phone number hacking.
3. Password Updates: Prompt password changes, especially after knowing one's credentials have been compromised, is a proactive measure that should be taken immediately.
4. Session Management: Regularly clearing sessions can help ensure that, even if a session cookie is intercepted, it won't remain valid indefinitely.
5. Breach Monitoring: Continuous monitoring for potential breaches via services like Have I Been Pwned keeps users informed of any risks pertaining to their accounts.

Conclusion

Addressing your query about whether we should be worried: Yes, the current state of password reliance is concerning, and the data breach is indicative of much larger systemic issues that need addressing. However, the conversation around passkeys and continued enhancements in authentication technology provides hope.

As users, we should all be advocates for and early adopters of better technologies like passkeys while also adhering to best practices in security management. This shift won't happen overnight, but with concerted effort from both users and service providers, we can foster a more secure digital environment. I'd be very interested to hear others' experiences with passkeys and any additional strategies people are using to safeguard their online security!
 
Back
Top Bottom