The UK's National Cyber Security Centre has officially moved away from recommending passwords, endorsing passkeys as the more secure login method for digital services. Passkeys offer stronger protection against phishing and data breaches.
The National Cyber Security Centre (NCSC) announced it will no longer recommend passwords where passkeys are available, marking a significant shift in digital security guidance.
What are passkeys?
Passkeys are login credentials stored directly on users' devices—smartphones, tablets, or computers. Rather than typing a password, users authenticate through biometric data like fingerprints or face recognition, or device PIN codes.
How they work
When logging into an app or website, passkeys use cryptographic technology to verify identity without transmitting sensitive information across networks. The system stores a unique key on the user's device and keeps a corresponding public key with the service provider. Authentication happens locally on the device, not through a centralized server.
Security advantages
Passkeys eliminate several vulnerabilities that plague traditional passwords. They are resistant to phishing attacks because they cannot be tricked into authenticating on fake websites. Users cannot be socially engineered into revealing them, as there is no shared secret to compromise.
Passkeys also provide protection against large-scale data breaches. Even if a service provider's database is compromised, attackers cannot use stolen credentials to access accounts elsewhere, since each passkey is unique to its service.
Industry adoption
Major technology companies have already begun supporting passkeys. Google, Apple, and Microsoft now allow users to create and manage passkeys across their platforms. Financial institutions and major websites are gradually integrating passkey support as an authentication option.
The transition
The NCSC's guidance positions passkeys as consumers' first choice for login across all digital services. The agency cited modern cyber threats as the primary reason for moving beyond password-based security.
While complete password replacement will take time due to infrastructure requirements, the NCSC's endorsement accelerates industry momentum toward phishing-resistant, breach-resistant authentication methods.
Artificial intelligence is accelerating the rate at which security flaws are discovered, overwhelming traditional remediation systems designed for slower timelines. Organizations now face pressure to modernize their vulnerability management infrastructure.
Nicola Coughlan, Hugh Bonneville, and Matt Lucas are among approximately 80 signatories backing a campaign to ban AI voice cloning. The group has submitted an open letter to Manchester Mayor Andy Burnham demanding legal protections for voice ownership.
Brave browser version 1.94 now includes Email Aliases, a feature that generates disposable email addresses for new service signups. The tool helps users mask their primary email and reduce tracking across platforms.
The Department of Homeland Security is leveraging a little-known legal provision to request records from journalists, non-profits, and unions, according to reporting from The Guardian. The tactic raises concerns about surveillance overreach and First Amendment protections.