
Passkeys are more secure than traditional ways to log in
Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices.
The NCSC recommends users opt for passkeys over passwords wherever they are available.
A passkey is a secure, passwordless authentication method that allows you to log into an app and website using your existing device biometrics (like Face ID or fingerprints) or lock screen PIN. Built on the FIDO2 standard, passkeys are a complete alternative to traditional passwords.
Passkeys are a more secure alternative to passwords and traditional 2SV or MFA.
They are easier to use since they're created and managed for you by your device(s), meaning you don't have to create and remember lots of individual passkeys.
The NCSC supports the public adoption of passkeys and recommends using passkeys over passwords wherever available.
Passkeys are a better alternative for the following reasons:
There is substantial evidence of malicious cyber actors taking advantage of password authentication via effective phishing and spear-phishing attacks – from cyber criminals and hacktivists to nation-state actors linked to China, North Korea, Russia and Iran. But implementing and adopting passkeys reduces the effectiveness of this activity. When combined with keeping your devices and apps up to date, passkeys significantly reduce the likelihood of phishing attacks, making this common technique far less effective for cyber criminals and nation-state actors. This means the more UK citizens choose to adopt passkeys, the greater our national resilience to phishing attacks.
Passkeys are created, saved, stored and managed for you on your trusted device(s) – such as your smartphone, tablet or computer – by your chosen credential manager (the more accurate term for ‘password manager’). This will most likely be the default one built in to your device – such as Apple Passwords, Google Password Manager or Samsung Pass – unless you have specifically chosen to install and use a third-party one, for example, to synchronise passwords across different browsers and devices.
The credential manager:
Use a credential manager to start setting up a passkey:
Passwords have been the cornerstone of online security for decades, helping to protect our digital identities and sensitive information from unauthorised access. Users shouldn’t simply forget all their passwords or attempt to set up accounts without any form of security.
Where passkeys are not an available option, you should continue to use strong passwords, for example generated by a password manager and enable 2SV. This remains a resilient defence against online attackers.
Find more related content below from the NCSC website.
Passkeys offer a more usable, secure replacement for passwords and are already supported by most modern devices.
How today’s secure tools simplify your digital life, and reduce login stress and password fatigue
The merits of choosing passkeys over passwords to help keep your online accounts more secure, and explaining how the technology promises to do this
Passkeys are the more secure and user-friendly login method and should be the default authentication option for consumers.



