Solutions4IT Logo
Money Back Guarantee
6 Month Trial Period
Plain English IT Support
No jargon, no tricky words
Trustworthy & Reliable
4.9* Google Reviews
Happy clients
99% Customer Satisfaction

Are Passkeys Causing the Death of Passwords?

Passwords have been around for about as long as computers have. Frankly, they’ve had a good run!

But they’re increasingly becoming a weaker part of our online security defence. We reuse them, forget them, write them down and get tricked into handing them over.

Now, the major companies and organisations worldwide are starting to implement passkeys, and we can actually see a big example in the UK right now.

So, what exactly is a passkey, why are more people adopting them, and does this actually mean the end of passwords?

 

What is a passkey?

A passkey is a way of signing into an account without having to type a traditional password.

Instead, your device uses something you already use to unlock it, such as:

  • Your fingerprint
  • Facial recognition
  • A PIN
  • Another form of device authentication

You might already use this every day without really thinking about it.

For example, if you unlock your phone with your fingerprint and then sign into an app without typing a password, you may already be using passkey-based technology.

The distinction is what happens behind the scenes, which we don’t see. Rather than sending a password to a website that could potentially be stolen, passkeys use cryptographic keys to prove that you are authorised to access the account. That makes them considerably harder for an attacker to steal through traditional phishing attacks. I mean, it’d be pretty difficult to be tricked into giving up your fingerprint via a scam email!

 

Why are passkeys more secure than passwords?

Back on track about cryptographic keys, passkeys are cryptographically linked to the website or service they were created for. In simple terms: If you are tricked into visiting a fake website, the passkey shouldn’t authenticate you there.

So, even if an attacker creates a remarkably convincing copy of a login page (likely with AI), there’s no password sitting there waiting to be typed in.

This is why passkeys are considered phishing-resistant authentication.

That’s a pretty significant improvement over hoping Dave in accounts notices that the login page URL says rnicrosoft.com.

 

Example of Passkey Rollout: GOV.UK

The UK government has started rolling out passkeys through the GOV.UK One Login system.

This covers access to a range of government services, including things such as:

  • Tax services
  • Childcare support
  • Checking your State Pension
  • Other services accessed through GOV.UK One Login

The rollout follows a trial involving more than 300,000 people.

The government says that almost one in ten daily GOV.UK One Login sign-ins are already being made using passkeys.

We’ve been talking about security and phishing resistance so far, but another thing to consider is simply convenience! Rather than entering a username, password, and potentially waiting for a two-step verification code to arrive by text, users can authenticate using the same fingerprint, face scan or PIN they already use to unlock their device. I think this is important for everyone to know, as a lot of people will probably view passkeys as an annoying extra layer of security they have to set up; however, it’ll likely save them more time than the previous security methods.

 

Does this mean passwords are dead?

Not yet.

The government isn’t removing passwords completely, and passkeys aren’t going to suddenly replace every password you use tomorrow morning.

Instead, we’re likely to see a gradual shift towards passwordless authentication.

Passkeys are not simply a better type of password. However, we are already seeing major technology companies move in this direction.

Apple, Google and Microsoft have all introduced passkey support across their platforms, meaning the technology is becoming increasingly normal for consumers and businesses.

The more widely supported passkeys become, the less reliant we can be on passwords.

 

Are passkeys completely unhackable?

No.

And this is where it’s worth avoiding the slightly misleading idea that passkeys are some magical, completely unhackable technology.

They’re much more resistant to certain attacks, particularly phishing, but no authentication system is perfect.

Researchers have demonstrated attacks against the systems used to store, synchronise and recover passkeys.

For example, if malware has already compromised a computer, an attacker may potentially be able to target the device or the systems responsible for managing authentication credentials.

Think of it like locking your front door. Having a very strong lock is useful, but if you’ve left a spare key under the doormat, your security isn’t impenetrable.

 

What does this mean for businesses?

For organisations using cloud services such as Microsoft 365, Google Workspace and other online platforms, authentication is one of the most important parts of their security.

Passwords are still going to exist for some time, but businesses should be looking at ways to reduce their reliance on them.

That could include:

  • Enabling passkeys where they are supported
  • Removing unnecessary SMS-based authentication where better options exist
  • Making sure account recovery processes are properly secured
  • Reviewing which employees have access to important systems
  • Making sure compromised devices cannot simply be used to bypass authentication

It’s also important to remember that passkeys don’t replace every other security measure.

If an employee’s laptop is already infected with malware, changing the way they authenticate doesn’t clean the laptop.

 

So, are passwords finally on their way out?

Probably, but don’t expect them to disappear overnight!

The move towards passkeys is part of a much bigger change in cyber security: making authentication less dependent on something you know and more dependent on something you have, combined with something you are.

For consumers, that could mean fewer passwords to remember.

For businesses, it could mean fewer credentials for attackers to steal through phishing.

And for organisations like GOV.UK, moving millions of people towards more secure authentication could have a meaningful impact on the number of successful account takeover and phishing attacks.

Passkeys aren’t perfect, but compared with the traditional username-and-password combination, they’re a pretty significant step forward.

We hope you’ve enjoyed our blog on passkeys! We release two weekly uploads, so stay tuned for the latest headliners in cyber security, as well as articles where we pitch in our own experience as a Managed IT Service Provider. Stay safe!

© Copyright Solutions 4 IT Ltd 2026. All Rights Reserved. Terms & Conditions Privacy Policy
Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.