Why isn’t it World Passkey Day?

I really despise two security-related things: passwords and World Password Day.

My hatred, and that’s not too strong a word, for passwords is born out of experience. I suspect that at least half of the incidents that I analyse, the attacks that I write about and the victims that I help can trace the root cause back to a compromised password.

World Password Day, on the other hand, is on my sh1tlist for the opposite reason: it makes 0% difference in the real world.

I mean, seriously, is anyone actually waiting for today to come along to take their credentials security seriously? Is there a single person who has experienced a password epiphany on May 1st? Let me answer both of those questions for you: hell no.

Now, given that it’s 2025 and everyone knows how weak the password paradigm is, why aren’t we celebrating World Passkey Day? If the aim of the special day is to spread awareness, then surely passkeys are way more deserving of that than passwords.

Not only are they more secure and easier to use, but they need an awareness push to get more organisations to deploy them and more users on board.

Pushing for World Passkey Day

I’m not alone in thinking this way, you should be happy to hear.

Steven Furnell, a senior member of the Institute of Electrical and Electronics Engineers and Professor of Cybersecurity at the University of Nottingham, agrees that we have better options than passwords, with passkeys and biometrics “playing their part in reducing the burden and improving protection”.

The problem being that when users set up accounts the signposting for passwordless options is often poor. He pointed out that it often “varies whether other login options are signposted, or even available”.

This needs to stop and it needs to be better managed by the organisations already moving a passwordless approach.

“This year,” Furnell concluded, “the real message should not be aimed at users – who often have no choice but to rely on passwords – but at the websites and providers that continue to demand them.”

Kevin Curran agrees. And he’s worth listening to as a fellow IEEE senior member and another Professor of Cybersecurity, this time at Ulster University. “Weak passwords, reused logins and phishing scams dominate headlines – but simply pointing out the problem won’t move us forward,” he said.

“What matters is what we do next.”

The real challenge, Curran told me, isn’t a technical one but rather cultural. “Habits built over decades are hard to break,” Curran said, “and as the digital world evolves, so must our approach to authentication.”

Let’s start that change with World Passkey Day 2026.

FIDO’s World Passkey Day move

It appears that I’m not whistling in the wind: last month, the FIDO Alliance put its weight behind rebranding the occasion this year.

It also encouraged “all online service providers and authentication product and service vendors” to take its Passkey Pledge, a collection of measures to push everyone to a passwordless future.

The 145-strong list of names includes notables like Apple, Google, IBM and Microsoft, so let’s hope it continues to gain momentum.

I’m also heartened by these words from Simon McNally, a cybersecurity expert at Thales.

“We welcome the FIDO Alliance’s commitment to World Passkey Day and its push for a passwordless future,” he said. “Passkeys provide a seamless and secure authentication experience, eliminating the risks and frustrations associated with traditional passwords.”

Amen.

Other times Davey has got angry about this kind of day

Avatar photo
Davey Winder

With four decades of experience, Davey is one of the UK's most respected cybersecurity writers and a contributing editor to PC Pro magazine. He is also a senior contributor at Forbes. You can find him at TechFinitive covering all things cybersecurity.