Cyber Awareness - Cybersecurity

Passkeys and Passwords – Inspiring News Every User Should Know

Last month, we looked at Strong reasons to use biometrics as a second form of authentication which gave us some very valuable tips. In the same fashion, we are going to delve deeper on authentication methods and ask ourselves – Is the password + biometric combination the best mode of digital authentication or is there something better? In fact, recent industry developments make this question important and timely. Microsoft, one of the world’s leading technology giants has made passkeys the default authentication method on its Entra ID platform for all public users.  What does this mean for the future of passwords? Will other technology giants follow suit? And what exactly are passkeys anyway?

GamsGo - We offer 100+ AI, streaming & gaming subscriptions up to 85% off, featuring 3s instant delivery & 24/7 support.

What are Passkeys?

In very simple terms, passkeys provides passwordless authentication based on the Fast Identity Online 2 (FIDO2) standards.  It uses a technology called Public Key Cryptography instead of sharing a ‘secret’ like “P@$$w0rd” to authenticate and validate users. The introduction of the Public Key Cryptography in authenticating users is the game changer here. Surely, users do not need to understand how the technology works, however, they can rely on its security and convenience.

To elaborate, Public Key Cryptography works with a pair of matching keys. A public key and a private key. The system grants access only after the two keys work together. The website or platform you want to access stores the public key while you keep the private key in your possession on a device like a laptop or mobile phone.

How Passkeys Work

To complete a sign in process, a website will request access to its matching private key on your device. Before unlocking the private key, your device verifies your identity by requesting biometric data (facial recognition or fingerprint) or PIN. This identity verification process ensures a legitimate person authorizes the website or platform to unlock and match the key pairs. After a system confirms a match, it authenticates your account.

passkeys

Again, all this happens in the background, and you do not need to know about it. A typical user sign in experience includes typing in your username, completing biometric verification and accessing your account. It might seem you are completing the biometric multi-factor authentication (MFA) process you know but that is not the case. Passkeys embed MFA within the authentication flow, making it part of the same step rather than a second step.

Most importantly, keep in mind that unlike passwords sent to a portal, resource or website for authentication, your private key never leaves your device. Thus no one can steal or intercept it while in transit. Let’s look at some other advantages of passkeys.

What makes them better than passwords

Firstly, the use of passkeys greatly reduces potential avenues through which an attacker can compromise the digital authentication process. Unlike passwords, there is no “secret” to share with any website or portal you are trying to sign into. Hence malicious actors cannot trick you into revealing your password through social engineering attacks. Similarly, because passkeys rely on biometrics instead of SMS codes or voice calls, attackers cannot easily duplicate or intercept it with SIM swapping or vishing attacks. This makes it strong and resistant to phishing attacks.

passkeys sign-in

Another passkey characteristic is, they bind to their origin.This means the public and private keys shared between a website and your device is unique. Even if an attacker sets up a fake website to harvest your credentials, they will not be successful. This is because the private key on your device will not match the public key on the fake website. This represents a major upgrade on password technology that cannot determine the authenticity of a website.

Additionally, passkeys prevent remote attacks which is one of the main ways malicious actors operate. The device where a passkey was setup validates it locally unlike passwords that validates on websites from anywhere. Providing your biometric or device pin locally on the device is the only way to unlock your private key. An attacker in a remote location cannot perform this action.

Finally, from the user point of view, passkeys present a faster and smoother sign-in experience when compared to passwords. It takes an average of 31.2 seconds to login with passwords and MFA as opposed to 8.5 seconds with passkeys. Furthermore, passwords have an average 63% login success rate when compared to a 93% success rate with passkeys.

WEBROOT is an all-in-one protection for you and your family. It's simple, quiet, efficient, and built to protect your devices, identity and privacy.
Why use passkeys when passwords are working just fine?

Several reasons account for this, and your first guess is as good as mine.  Artificial Intelligence (AI) threats.  AI threats have radically changed the speed, scale and sophistication with which attackers operate. AI enabled attacks have an incredibly higher success rate than traditional cyber attacks. They can easily compromise user identity, automate discovery and enhance user privileges at speeds humans struggle to match and contain.

Secondly, passkeys solve the problem of password reuse and resets. With passkeys there is no ‘secret’ to create, memorize, write down or forget. This makes it difficult for attackers to steal passwords and attempt to use it on other websites their victims visit. Passkeys relieve from the burden of creating complex passwords for different accounts and changing them from time to time.

Are there any drawbacks?

Like many other technologies, passkeys come with some challenges. The first has to do with user reception and understanding. This has been one of the biggest drawbacks of the technology so far. For example, some users are resistant to change and are unwilling to adapt. From their point of view, passwords work just fine and there is no need for a change. These users fail to recognize the threat factors mentioned earlier.

Bitdefender - global leader in cybersecurity protection.

Again, there is the issue of user mistrust. Some users are yet to fully trust technology vendors with the use, safeguarding and storage of their biometric information. They prefer authentication methods that do not require the involuntary release of their biometric data. Also, the industry has not made passkey recovery methods well known, understood and documented. These factors causes panic and anxiety among users making them resistant to embrace passkeys.

Finally, there are challenges with the technology itself. Although industry giants such as Amazon, Microsoft, Apple and Google integrate passkeys well on their platforms, compatibility with certain devices, websites, applications and legacy systems remain an issue.

It’s time to adapt!

From all indications, passkeys are here to stay. The threat landscape has radically changed with the presence of artificial intelligence, and the security industry sees passkeys the viable solution to securing digital user authentication.

Although the switch from passwords is not going to be immediately, it will happen sooner rather than later. Technology giants have made passkeys a security priority and in the very near future, it will become mainstream. For now, users have a personal responsibility to understand passkey technology and satisfy themselves with its pros and cons. There are more conversations to have about this technology so look out for future articles and let me know your thoughts on this one.

Leave a Reply

Your email address will not be published. Required fields are marked *