Passwords are a traditional technology that create security vulnerabilities through reuse, breaches, and phishing attacks. Passwords remain a weak point in your security chain.
Passkeys represent the next evolution in authentication, providing phishing-resistant, seamless integration with biometric technology, and passwordless security that's both more secure and more convenient than traditional methods.
Watch a more deep dive video about Passkeys: Passkeys SUCK (here’s why + how I use them) (10 min).
❌ Figure: Bad example - Traditional password vulnerable to phishing, are often used across many accounts, and you may forget it over time
✅ Figure: Good example - Passkey authentication is phishing-resistant and convenient (in this example using Windows PIN)
While passkeys have been around for many years, it's taken longer than we'd like for companies and services to adopt them. And even when they are adopted, passkeys are often treated as second-class citizens, and sites still default users to less secure authentication methods.
Some cybersecurity professionals are taking it upon themselves to drive an increase in the adoption rate of passkeys, by way of social pressure and public education on the topic.
One of the most prolific cybersecurity professionals - Troy Hunt - creator of haveibeenpwned.com, publishes a "list of shame" of businesses and services that don't yet support passkeys as a form of authentication. This is the same tactic Troy used many years ago to pressure businesses to implement secure transport layer encryption (HTTPS) on their sites, to great effect. Go Troy!
Figure: Passkey created successfully
Pro tip: Set up passkeys on multiple devices (phone, laptop, tablet) to ensure you always have access to your accounts even if one device is unavailable.
Note: These steps are for a work or school Microsoft account (Microsoft Entra ID). For a personal Microsoft account, please visit your security dashboard.
Many companies, including SSW, are moving toward a passwordless future. By starting with passkeys today, you’re making logins safer and easier while getting ready for a time when passwords are no longer needed.