Passwords have always been a necessary evil — and generally, a royal pain in the rear — for most people who use IT, especially those with multiple protected accounts. The promised nirvana of a passwordless yet highly secure method of access has been on various drawing boards for decades.
The problem is we've long since become used to wasting valuable time on the password struggle. Changing or updating passwords to the liking of apps and websites and remembering them has been a nagging chore. Don't you hate it when an app tells you: "That password is too similar to one you used recently"?
That's where Passkeys come in. Passkeys are cryptographic tokens that use your face, fingerprint or device PIN to sign into accounts. They are stored on a user's device and can be used to authenticate to websites and apps without the need for a password. Passkeys are more secure than passwords because they are not vulnerable to phishing attacks or data breaches. They are also more convenient because users do not need to remember or type in long and complex passwords.
If you lose your device or find it disabled, you also lose the passkey, but you can create a new one for your next device.
Google, Microsoft, Amazon and Apple lead the passkey adoptionLarge tech companies are playing a leading role in the adoption of passkeys and their passwordless authentication. In May 2022, Apple, Amazon, Google and Microsoft announced a partnership to develop a new standard for passkeys, which are inherently stronger and more convenient than passwords.
Passkeys are the result of more than 10 years of effort from cyber industry leaders and organizations such as the Fast Identity Online (FIDO) Alliance. These IT giants have since been working diligently to make passkeys a reality. Apple rolled out its passkey option with the release of iOS 16, allowing people to use the technology across apps, including Apple Wallet. For Apple users, passkeys are encrypted/stored in their iCloud Keychains, where they aren't visible to anyone, including Apple. To use passkeys, iOS 16, iPadOS 16, macOS 13, or tvOS 16 (or later) is required.
Passkey support was first rolled out on Chrome and Android devices in October 2022, and Microsoft and AWS have made passkeys available for their platforms since that same year.
Tech giants push for passwordlessIn addition to implementing passkeys for devices, these companies are also working to make it easier for other websites and apps to adopt passkeys.
Google Password Manager stores, serves and synchronizes passkeys on Android and Chrome. Passkeys from Google Password Manager are available to all Android apps, including Chrome and other browsers.
Microsoft's latest Windows 11 update (September 2023) introduced public support for passkeys.
Just last month, Amazon announced that it is rolling out passkey support on browsers and mobile shopping apps, offering customers an easier and safer way to sign in to their Amazon accounts. Customers can now set up passkeys in their Amazon settings, allowing them to use the same face, fingerprint, or PIN used to unlock their device. Passkey support is available now for all Amazon customers using browsers and is gradually rolling out on the iOS Amazon Shopping app with support coming soon on the Android Amazon Shopping app, the company said in a blog post.
AWS has made passwordless authentication tools available to developers for the last couple of years, enabling physical security keys or platform authenticators (such as finger-print scanners) to be used as the authentication factor to web or mobile applications that use WebAuthn and Amazon Cognito user pools for authentication. The problem is that only a small percentage of web or mobile apps use these tools at this early date.
WebAuthn is a standard web API built into some browsers that enables users to authenticate with passkeys. The API was standardized by the FIDO Alliance and the World Wide Web Consortium. Amazon Cognito provides an identity store that scales to millions of users, supports social and enterprise identity federation and offers advanced security features to protect consumers and businesses. Built on open identity standards, Amazon Cognito supports various compliance regulations and integrates with front-end and back-end development resources.
Additionally, Apple has announced that it will provide a new iCloud Keychain API that will allow developers to integrate passkeys into their apps. Apple's Keychain Services API allows developers to store sensitive user data such as passwords, credit card information or certificates in an encrypted database. More similar APIs are expected to become available in the coming months.
Apple Passkeys can now be synced using external providers, and developers can create groups to share passwords and passkeys. In managed environments, passkeys support Managed Apple IDs, including syncing via iCloud Keychain, and access controls let users restrict how passkeys are shared and synced.
Google is now providing a new Chrome extension that will allow users to deploy passkeys on any website, even if the website does not yet support passkeys itself. "To use Google passkeys, people just use a fingerprint, face scan or pin to unlock a device – and they are 40% faster than passwords," Google product managers Sriram Karra and Christiaan Brand wrote in a recent blog.
How do digital passkeys work?Digital passkeys work by using a combination of cryptography and public key infrastructure (PKI) to authenticate users to websites and apps without the need for passwords. When a user creates a passkey for a website or app, their device generates a unique cryptographic key pair. The public key is stored on the website or app's server, while the private key is stored securely on the user's device.
To authenticate to the website or app, the user's device sends their public key to the server. The server then generates a challenge and sends it back to the user's device. The user's device uses its private key to sign the challenge and send it back to the server. The server then verifies the signature using the user's public key. If the signature is valid, the user is authenticated and granted access to the website or app. Under the hood, this is complicated, but it moves quickly, and users barely notice the time lapse.
Here are some examples of how digital passkeys can be used:
- A user can create a digital passkey for their favorite online store. When they want to make a purchase, they simply scan a QR code with their phone or enter a passcode. The passkey will automatically authenticate them to the store and allow them to make the purchase.
- A user can create a digital passkey for a work email account. When they want to check their email on a new device, they simply scan a QR code or enter a passcode. The passkey will automatically authenticate them to their email account and allow them to access their messages.
- A user can create a digital passkey for their social media accounts. When they want to log in to their social media accounts on a new device, they simply scan a QR code or enter a passcode. The passkey will automatically authenticate them to their social media accounts and allow them to access their profiles.
Passkeys are relatively new, thus the majority of authentication is still conducted using traditional methods, such as passwords. According to a report by MarketsandMarkets, the passwordless authentication market, which includes passkeys, is expected to grow at a CAGR of 26.2% by 2030 to reach $21.2 billion from an estimated $6.6 billion in 2022. However, even with this rapid growth, most industry experts believe it is unlikely that passkeys will constitute a majority of the authentication market in the next few years.
There are a few reasons for this. First, passkeys are still not widely supported by websites and online services. Second, many people are still not aware of passkeys or how to use them. However, as passkeys become more widely adopted and supported, they are likely to become a more popular authentication method.
Thus, passwords are holding on, mainly because knowing how they work is practically embedded in our DNA. At the same time, some forms of passwordless authentication can be difficult to set up, and with a dozen different methods available, there's no reason for users to make the switch until one or two formats emerge as the dominant passwordless standards.
"Identity and access management (IAM) leaders seeking to eliminate passwords are often uncertain of what passwordless authentication should actually look like and are discouraged by the lack of a universal approach," Gartner researcher Ant Allan wrote in the company's Guide to Passwordless Authentication.
The same can be said of users, who can choose from eye, face and fingerprint scans; push notifications; authenticator apps; QR codes, USB security keys, phone-based security keys and others. Inside each device, authentication programs use FIDO, FIDO2, Windows Hello, Touch ID, Face ID, time-based one-time passwords (TOTP), WebAuthn and other methodologies.
Why industry analysts are bullish on passkeysEven with all that ostensible complexity, industry analysts generally are bullish on the future of passkeys. Of course, most analysts are bullish on most forms of IT innovation.
"Passkeys are the future of authentication. They are more secure, more convenient, and more user-friendly than passwords. We expect that passkeys will be widely adopted in the next few years, and that they will make the internet a more secure and convenient place for everyone," Gartner Research reported in "The Future of Authentication: Passkeys".
"Passkeys are a game-changer for security and convenience. They are the first truly passwordless authentication solution that is both secure and easy to use. We expect that passkeys will be widely adopted by consumers and enterprises alike, and that they will help to reduce the risk of cyberattacks and data breaches," Forrester wrote in "The Passkey Revolution: How Passkeys Will Change the Way We Authenticate".
The FIDO Alliance has stated that passkeys have the potential to significantly reduce the risk of cyberattacks and data breaches. This is because passkeys are resistant to phishing attacks and other types of password theft.
Alliance members also believe that old challenges need to be addressed before passkeys can be widely adopted, such as the lack of awareness of passkeys and the lack of support for passkeys from websites and apps. However, they conclude that passkeys are the most promising new authentication technology in years.
Comments