Big Tech Shamed for Ignoring Passkey Security
Big Tech Shamed for Ignoring Passkey Security
Instagram, Netflix and Spotify are among major companies "named and shamed" for not offering passkeys to users. The technology is an alternative to passwords and is designed to overcome two major hurdles.
Passwords rely on users remembering them, which can be difficult without reusing passwords across sites or using short, easily guessable passwords. (Password managers are one way round this problem). They also can be stolen through a hack or a user being tricked by a phishing scam where they think they are logging into a legitimate site and hand over details. (Source: techcrunch.com)
Better Security for Users
In contrast, passkeys are created by a specific device rather than covering the entire account. The passkey is then verified using the same login process as the device itself. This is usually either a biometric check such as fingerprint or facial recognition, or a physical device such as a USB security key.
This means not only does the user not need to remember anything, but it makes it almost impossible to overcome the security without physical access to the device itself. It also makes phishing much more difficult as the security check is done by the device, rather than a website, which could be bogus.
Security researcher Scott Helme was frustrated by major sites which don't offer a passkey option and found this was the case for seven of the 25 most popular websites. He's now launched whynopasskeys.com in an attempt to draw attention to such sites.
Setting Industry Standards
Helme notes he ran a similar project in 2017 to highlight major websites which didn't use https:// encryption to secure traffic to and from their customers.
He argues that naming and shaming the biggest companies isn't just about their behavior, but also the example they set to others. He says them not supporting passkeys will "shape user expectations" and make it less likely smaller sites will see it as important. (Source: scotthelme.co.uk)
Helme also notes that using passkeys is a spectrum of security and that supporting them as a replacement for a password is less secure than using them as an extra line of defense while still also requiring a password.
What's Your Opinion?
Should big tech companies be pressured or even forced to adopt better security like passkeys? Would you stop using a major service if it refused to offer modern security options? Do you find passkeys more convenient than traditional password managers?

My name is Dennis Faas and I am a senior systems administrator and IT technical analyst specializing in technical support and cyber crimes with over 30 years experience; I also run this website! If you need technical assistance , I can help. Click here to email me now; optionally, you can review my resume here. You can also read how I can fix your computer over the Internet (also includes user reviews).
We are BBB Accredited
We are BBB accredited (A+ rating), celebrating 25 years of excellence! Click to view our rating on the BBB.
Comments
Passkeys make me nervous.
They sound great if someone has more than one device they can rely on, but I'm not one of those people. I use a single desktop computer, which means if my device breaks, there go my passkeys. Yes, I know they can be put in the cloud with a password manager, but what happens when password managers require passkeys to access your passkeys? It sounds like a lockout waiting to happen, because although the bad actors can't get in, neither can you.
USB hardware key is the answer
Your concerns regarding single-device dependency are valid, but you can get past the issue of storing the passkey on the machine by purchasing a USB hardware key dongle.
These USB devices act as 'roaming authenticators,' storing the passkey physically rather than on your computer or in the cloud. If your desktop fails, you simply move the physical key to a new machine to regain access.
To eliminate the risk of a single point of failure, the industry standard is to register two keys: one for daily use and one as a secure, offline backup. This approach effectively decouples your authentication from your device hardware, ensuring you retain control even if your primary machine becomes unusable.
Also, most websites should offer another way to authenticate if your passkey isn't working / you don't have access to it.
If no facial recognition is an option, is a PIN login better?
If no facial recognition is an option, is a PIN login better? and where doees infopackets.com stand on passkey use (my guess is addtional hardware/cost is needed for any site using passkeys). Why do some sites make a new passkey on occasion? I use/pay for roboform and everytime a passkey is created, it saves it. I "appends" the passkey name with a number. I have multiple passkeys for eBay for example.