A year after announcing support for passkeys for personal accounts, Microsoft is making a significant change: new accounts will use passkeys, for greater protection against phishing attacks.
Passkeys allow users to access websites and services without typing usernames and passwords . They use biometric authentication, such as fingerprints and facial recognition, and provide a more secure and convenient alternative to traditional passwords. The technology creates a cryptographic key pair (one public and one private) that is associated with a user's account. Apps and services that support passkeys use the public key to verify a person's identity by matching it with the private key, which is stored on the user's device.
See also: Windows 11: Microsoft is testing support for third-party passkeys

When the user attempts to log in, the online platform sends a cryptographic challenge to the user's device. The user will then be asked to authenticate with their PIN or a biometric method, which will cause the private key to sort out the cryptographic challenge and send it back to the online service. The online service will use the user's public key to verify the challenge and connect the user to their account.
As Microsoft's Joy Chik and Vasu Jakkal stated , all new accounts will be passwordless by default. Users will have alternative ways to sign in to their accounts and won't have to create or remember passwords. Existing users can also choose to remove their passwords from their account settings.
See also: FIDO allows secure movement of passkeys across platforms

The company has improved the login experience, emphasizing passwordless methods. The platform also automatically recognizes and selects the most secure method available for each user. For example, if someone has the ability to log in with a traditional password and a one-time password, they will be asked to use the one-time password. After logging in, they will be asked to activate a passkey for greater protection.
This move by Microsoft, combined with similar initiatives from companies like Apple, Google , and Amazon, shows the tech industry's intent to move toward a future without traditional passwords. Password-based attacks remain widespread and dangerous, which is why the move to passkeys is considered crucial for user security.
See also: Windows 11: How to create, use and delete passkeys?
In September 2023, Microsoft added support for passkeys to Windows 11, around the same time that Google made passkeys the default sign-in method worldwide. Windows Hello was subsequently upgraded to support this new technology.
Passkeys are a relatively new authentication system that replaces traditional passwords . Efforts towards a secure password-free have been underway for the past few years, but are now bearing fruit as more and more companies are now supporting their use.
Source: thehackernews.com
🔑 Secure your passwords with Proton Pass
Password manager from Proton — end-to-end encryption, passkeys, built-in 2FA, and monitoring for leaks of your credentials.
- ✔ Encrypted storage of passwords & passkeys
- ✔ Notification if any of your passwords are leaked (Dark Web Monitoring)
- ✔ Free version — on all devices
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
