Asian Spectator

Men's Weekly

.

What are passkeys? A cybersecurity researcher explains how you can use your phone to make passwords a thing of the past

  • Written by Sayonnha Mandal, Lecturer in Interdisciplinary Informatics, University of Nebraska Omaha
What are passkeys? A cybersecurity researcher explains how you can use your phone to make passwords a thing of the past

Passwords could soon become passé.

Effective passwords are cumbersome, all the more so when reinforced by two-factor authentication. But the need for authentication and secure access to websites is as great as ever[1]. Enter passkeys.

Passkeys[2] are digital credentials stored on your phone or computer. They are analogous to physical keys. You access your passkey by signing in to your device using a personal identification number (PIN), swipe pattern or biometrics[3] like fingerprint or face recognition. You set your online accounts to trust your phone or computer. To break into your accounts, a hacker would need to physically possess your device and have the means to sign in to it.

As a cybersecurity researcher[4], I believe that passkeys not only provide faster, easier and more secure sign-ins, they minimize human error in password security and authorization steps. You don’t need to remember passwords for every account and don’t need to use two-factor authentication.

How passkeys work

Passkeys are generated via public-key cryptography[5]. They use a public-private key pair to ensure a mathematically protected private relationship between users’ devices and the online accounts being accessed. It would be nearly impossible for a hacker to guess the passkey – hence the need to physically possess the device the passkey is accessed from.

Passkeys consist of a long private key – a long string of encrypted characters – created for a specific device. Websites cannot access the value of the passkey. Rather, the passkey verifies that a website possesses the corresponding public key. You can use the passkey from one device to access a website using another device[6]. For example, you can use your laptop to access a website using the passkey on your phone by authorizing the login from your phone. And if you lose your phone, the passkey can be stored securely in the cloud with the phone’s other data, which can be restored to a new phone.

Passkeys explained in 76 seconds.

Why passkeys matter

Passwords can be guessed, phished or otherwise stolen. Security experts advise users to make their passwords longer with more characters, mixing alphanumeric and special symbols. A good password should not be in the dictionary or in phrases, have no consecutive letters or numbers, but be memorable. Users should not share them with anyone. Last but not least, users should change passwords every six months at minimum for all devices and accounts. Using a password manager[7] to remember and update strong passwords helps but can still be a nuisance.

Even if you follow all of the best practices to keep your passwords safe, there is no guarantee of airtight security. Hackers are continuously developing and using software exploits, hardware tools and ever-advancing algorithms to break these defenses. Cybersecurity experts and malicious hackers are locked in an arms race.

Passkeys remove the onus from the user to create, remember and guard all their passwords. Apple, Google and Microsoft are supporting passkeys[8] and encourage users to use them instead of passwords. As a result, passkeys are likely to soon overtake passwords and password managers in the cybersecurity battlefield.

However, it will take time for websites to add support for passkeys, so passwords aren’t going to go extinct overnight. IT managers still recommend[9] that people use a password manager like 1Password[10] or Bitwarden[11]. And even Apple, which is encouraging the adoption of passkeys, has its own password manager[12].

References

  1. ^ as great as ever (www.theguardian.com)
  2. ^ Passkeys (developers.google.com)
  3. ^ biometrics (csrc.nist.gov)
  4. ^ cybersecurity researcher (scholar.google.com)
  5. ^ public-key cryptography (www.techtarget.com)
  6. ^ to access a website using another device (developers.google.com)
  7. ^ password manager (www.wired.com)
  8. ^ supporting passkeys (techcrunch.com)
  9. ^ still recommend (www.pcmag.com)
  10. ^ 1Password (1password.com)
  11. ^ Bitwarden (bitwarden.com)
  12. ^ own password manager (www.wired.com)

Authors: Sayonnha Mandal, Lecturer in Interdisciplinary Informatics, University of Nebraska Omaha

Read more https://theconversation.com/what-are-passkeys-a-cybersecurity-researcher-explains-how-you-can-use-your-phone-to-make-passwords-a-thing-of-the-past-196643

Magazine

Gembar-gembor aksi iklim Indonesia berbanding terbalik dengan nasib pahit pekerja informalnya

● Semangat menanggulangi perubahan iklim selalu disampaikan pemerintah sejak lama.● Bahkan dalam COP-30 belum lama ini pemerintah berkomitmen menggelontorkan Rp16 triliun untuk inisiasi da...

Ingatan tsunami, ujian Senyar: Bagaimana memaksimalkan peran kampus dalam situasi bencana

● Tsunami 2004 dan Siklon Senyar 2025 membuktikan bahwa kampus dapat berperan penting dalam situasi bencana.● Universitas dipercaya publik karena sumber daya dan posisi gandanya sebagai ko...

TikTok dan algoritma kian jumawa: Apa kabar seni tradisional kita?

Firman Marek_Brew/pexels, cottonbro studio/pexelsTahun 2025 hampir berakhir. Jika kita menengok ke belakang, lanskap media kita telah berubah total. Dominasi TV dan radio di tahun 2000-an kini diganti...

hacklink hack forum hacklink film izle hacklink หวยออนไลน์matbetPusulabetสล็อตเว็บตรงgamdom girişpadişahbetMostbetpradabetmatbetholiganbetslot888trendbetsetrabetjojobetmarsbahis girişpusulabet girişbetnanotürk ifşaBets10pusulabetMavibet色情marsbahisnakitbahisjojobet girişYakabet1xbet girişjojobetgrandpashabetbetofficezbahis türkiyematadorbet adresienjoybetpradabetkingroyalholiganbetgiftcardmall/mygiftultrabetbets10royalbetmamibetmeritkingcasibommeritkingdamabetugwin288casibomteknoloji haberlericasibom girişJojobetmeritkingmeritkingPorno İzlecasibom girişsweet bonanzakingroyalgalabetcasibomcasibom girişjokerbetjokerbetyakabetCasibombetpuanmeritkingmatbet girişdinamobetmasterbettingvdcasinoSekabet girişmarsbahisbetkolikultrabetprimebahismeritkingprimebahismeritkingbets10yakabetyakabetyakabetjojobetprizmabetkulisbetSahabetpacho casinoaertyercasibomvbetcolor pickerkavbetkralbet girişmavibetmavibetmavibetbetnano girişcratosslot girişCasibomdeneme bonusu veren siteleronwinonwinholiganbetantalya escortbetnano girişbahsegeltimebetbetnanocasibom güncel girişcasibom girişbahiscasinojojobetbets10matbetroyal reelsstarzbet girişKayseri Escortjojobet girişjojobetbetasusbeylikdüzü escortŞişli EscortbettiltcasibomBetplayaviator gametimebetbahisoistanbul escort telegramcasibombetparkprimebahisholiganbet girişnorabahis girişmarsbahiscasibomvaycasinoholiganbet girişholiganbetpadişahbetbetparkgiftcardmall/mygiftttpat.com링크모음주소모음 주소킹주소모음 주소모아eb7png pokiesbest online casino australiabest online pokies australiabcgame96 casinocrown155 hk casinobest online casino in cambodiaBetplayStreameastgalabetmarsbahisgalabetholiganbet girişjojobetcasibombets10bets10MMA StreamjojobetJojobet 1112matadorbetkavbetcasibomcasibomasdsadasdasdasdasfdasfasfsadfasdfsdfasdasdasdasdkingroyal girişjojobetbahiscasinobetasuspin upmamibetslot gacorcasibombetasusmeybetcasibompusulabetcanlı maç izleSahabet girişcratosroyaljojobet girişcasibomแทงหวย24casibomjokerbetcasibom girişsultanbetbetbaba girişwonoddseasons-bandb.comikasbet.orgolimposcasinositus slot gacormatbet