New technology may be the beginning of the end for passwords.
Between email, banking, streaming services, and work logins, the average person has to keep track of over 100 passwords.
But new login technology hopes to make it easier and safer to store personal information online.
Caitlin Sarian is a cybersecurity expert. She’s a content creator best known for her cybersecuritygirl account. There she shares technology content and tips on how to secure personal information online.
“We all know that passwords are … annoying, but they are the number one way hackers break into accounts, unfortunately, because we continue to make our passwords weaker every time we recycle the same password across a lot of sites,” she said.
That’s why some companies are rolling out a new login technology called “passkeys.” It’s an authentication method that replaces the usual combination of username and password.
“We want to think of a passkey as, like, a digital key that stays on your phone,” explained Sarian.
It can be a biometric device like a fingerprint or facial ID on a phone or even a PIN.
“And then behind the scenes, the encryption kind of connects your device to that site without ever handing over credentials or anything like that,” said Sarian.
The magic behind these passkeys is thanks to public key cryptography. This ensures that the secret element of the credential — like the password — isn’t shared with the website, and that no secrets are transferred between the user’s device and the server. This method makes it harder for criminals to steal information.
“Passkeys really can’t be phished. If you click on a fake login page, the passkey just won’t work there because it’s not connected to that site, that passkey is not correlated with that site whatsoever,” Sarian said. “They also aren’t stored in some giant database.”
Passkeys are different from using two-factor authentication. They remove the need for users to enter a password, while two-factor authentication enhances the security of an account by requiring another method of authentication to gain access to that account.
Sarian says passkeys allow for users to enable multifactor authentication, as well.
“The top two things that are the most important would actually be covered by a passkey. And then the third is to update software,” said Sarian. “Just turn on auto updates and it’ll be fine. A lot of our cybersecurity privacy type of headaches would be resolved with a passkey because passkeys do solve the password problem and a multi-factor authentication problem, as well.”
Because the technology is new and slowly growing, passkeys may not be accessible on all computers or devices. Users who lose access to a device or lose a phone that is connected to the account may have difficulty gaining access to that account.