The news that 16 billion leaked credentials had been leaked spread from online to mainstream media last week, and I have to put my hands up for being partly responsible for that, having written an article that went viral as the news broke.
โCybercriminals are systematically collecting login data and leveraging it for mass exploitation,โ warned Tim Eades, CEO & Co-Founder at Anetac, adding that โat this scale, stolen credentials become a commodity that is bought, sold, and weaponised in countless attacksโ.
Although word of such aggregated databases of compromised credentials is never welcome, the fallout can have a positive impact. That appears to be the case here. I have never seen so much interest in the topic of passkeys as I have in the past eight days.
The latest to spread the good word about replacing passwords with passkeys, whether you are a public sector organisation, self-employed or an SME, comes from no less an authority than the National Cyber Security Centre (NCSC).
โPasskeys are rolling out fast,โ said the enigmatically named Amy B, with the equally obscure job description of Head of Citizen Resilience at the NCSC. โTheyโre easy to use, hard to compromise and eliminate password fatigue.โ
Passkeys vs passwords: why passkeys are so much better
Amy B’s stance is supported by Greg Wetmore, Vice President of Product Development at Entrust. He told me that the reason this could be a game-changer is that we have seen how difficult it is to remain secure online when relying upon passwords and nothing else.
โPerhaps the most important security attribute of passkeys is that they are phishing resistant,โ said Wetmore, echoing what Iโve been telling people for the longest time.
Passkeys comprise a cryptographic key pair; the public key is stored on the application server, and the private key on your device and accessed by way of biometric authentication. The keys are randomly generated and never shared during the sign-in process. Unless an attacker has physical access to the device on which the passkey public key is stored and the means to authenticate as the user, they are out of luck when it comes to using the credential.
Passkeys โcan’t be intercepted or stolen by remote attackers,โ confirmed Niall McConachie, Regional Director (UK & Ireland) at Yubico, โmeaning only the key holder can gain access to their accounts.โ
McConachie, who has skin in the game, of course, agrees with the NCSC position and recommends organisations โopt for the highest-assurance authentication method to ensure their data is fully protected and not at risk of being accessed by cyber criminals”.
Related articles