Passkeys poised to replace passwords in 2026

The era of cumbersome passwords may end in 2026, as passkeys emerge as a more secure alternative using biometrics. Cybersecurity experts predict widespread adoption, driven by major companies like Microsoft. This shift promises easier logins and reduced hacking risks.

Passwords have long been a weak link in online security, with hackers routinely trading stolen credentials on dark web markets. An analysis by Verizon reveals that only 3 percent of passwords are sufficiently complex to resist attacks, leaving most users vulnerable.

Enter passkeys, a biometric-based system that authenticates users without requiring memorable strings of characters. Devices generate a public key sent to services like banks and a private key stored securely on the device. During login, the service issues a cryptographic challenge, which the user confirms via fingerprint or face scan. The device's secure chip signs the challenge with the private key and returns it for verification, ensuring biometric data stays local.

"Passkeys offer ease of use, security and, above all, convenience," says Jake Moore, a cybersecurity specialist at ESET. This approach thwarts phishing and brute-force attacks more effectively than traditional passwords.

Microsoft led the charge in May 2025, announcing that new accounts would default to passwordless setups. "Although passwords have been around for centuries, we hope their reign over our online world is ending," the company stated. Adoption is accelerating: Roblox saw an 856 percent surge in passkey authentications in the second quarter of 2025, while Germany's Federal Employment Agency ranks among the top adopters.

The FIDO Alliance, which promotes passkeys, reports that organizations using them experience 81 percent fewer helpdesk calls for login problems. "It is in every company's strategic interest to reduce reliance on passwords," says Andrew Shikiar, executive director of the alliance. He forecasts that over half of the top 1,000 websites will implement passkeys by 2026, signaling a broad industry pivot toward seamless, secure access.

Relaterte artikler

New research from ETH Zurich and USI Lugano reveals vulnerabilities in popular password managers, challenging their assurances that servers cannot access user vaults. The study analyzed Bitwarden, Dashlane, and LastPass, identifying ways attackers with server control could steal or modify data, particularly when features like account recovery or sharing are enabled. Companies have begun patching the issues while defending their overall security practices.

Rapportert av AI

A 2022 data breach at password manager LastPass has resulted in prolonged cryptocurrency thefts, according to blockchain intelligence firm TRM Labs. The incident involved stolen user vaults that facilitated around $35 million in losses extending into 2025.

Microsoft has introduced a policy involving BitLocker keys that is prompting users to consider switching to Linux. The move is seen as a significant drawback for Windows users concerned about data security and privacy.

Rapportert av AI

A new report warns that adversaries are harvesting encrypted data today for future decryption using quantum computers, posing trillions in economic risks to banks. The Citi Institute estimates a single such attack could jeopardize $2 trillion to $3.3 trillion of U.S. GDP. Financial institutions must accelerate post-quantum preparations amid rising cyberattacks.

 

 

 

Dette nettstedet bruker informasjonskapsler

Vi bruker informasjonskapsler for analyse for å forbedre nettstedet vårt. Les vår personvernerklæring for mer informasjon.
Avvis