Security News UK.gov begins killing off passwords for 23 million users

Brownie2019

Level 23
Thread author
Verified
Well-known
Forum Veteran
Mar 9, 2019
1,120
6,121
2,168
Germany
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
The UK government is giving more than 23 million people the chance to ditch passwords for passkeys – and could save itself a tidy sum on authentication texts in the process.

Passkeys are being rolled out more widely across GOV.UK One Login following a trial involving more than 300,000 users, allowing people to sign in using a fingerprint, Face ID, or device PIN instead of entering a password and waiting for a two-factor authentication (2FA) code.
The government says nearly one in ten daily One Login sign-ins are already being made using passkeys, which it claims are up to eight times faster than logging in with a username, password and 2FA code.

There is also a less glamorous incentive for Whitehall: text messages cost money. The switch is already saving taxpayers nearly £600 a day in SMS costs, according to the government.
Passkeys are designed to resist phishing. Rather than relying on a password that can be stolen, reused, or handed over to a convincing fake login page, a passkey uses cryptographic credentials tied to the website or app for which it was created.

The biometric data or PIN used to unlock it remains on the user's device and isn't seen or stored by GOV.UK One Login.
"Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC). "But passkeys offer a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time."
The NCSC is encouraging users to switch, although passwords aren't disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so.
GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems. It is already used for services including checking State Pension details, managing tax services, and accessing childcare support.

Digital Government Minister Stephanie Peacock said the rollout was intended to make government services both easier to access and harder for fraudsters to exploit.
"Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said.
Whether Britain's 23 million One Login users share Whitehall's enthusiasm for replacing passwords is unclear. But with passkeys already accounting for almost 10 percent of daily logins – and every authentication text adding to the government's phone bill – there are at least a couple of reasons to keep nudging them in that direction. ®
 


Hi, this is a sensible move: passkeys should materially reduce phishing risk for GOV.UK One Login users, while also making routine sign-ins quicker. The headline slightly overstates matters, though—passwords are not being “killed off” yet because passkeys remain optional.

Why passkeys are safer​

A passkey uses a cryptographic credential associated with the genuine website. A counterfeit GOV.UK sign-in page cannot simply collect and replay it as it could a password or SMS code. That directly tackles the familiar fake-login-page attack.

The fingerprint, face scan or device PIN is normally just the local unlock method for using the passkey. It is not the passkey itself, and GOV.UK does not need to receive the biometric data.

Passkeys are highly phishing-resistant, but they are not magic armour. Users can still be deceived into disclosing personal information, approving unrelated actions, installing remote-access software or using a weak account-recovery route.

The practical catch is recovery​

The important question is what happens after somebody loses or replaces a phone. Users should understand whether their passkey is synchronised through their platform account, stored on another device, or recoverable through a separate GOV.UK process.

Good practice would be to:

  • register more than one suitable device or passkey where the service permits it;
  • keep the device account itself protected with a strong PIN and MFA;
  • review old devices and remove access after selling or losing one;
  • store recovery information securely rather than waiting for a broken phone to explain the plan.

For people using shared devices, managed work equipment or older hardware, retaining the existing sign-in route for now is reasonable. Optional adoption is preferable to forcing users into a recovery system they do not understand.

What the rollout does—and does not—show​

The reported trial and early login share indicate that the system is usable for a meaningful number of people. They do not establish how many of all 23 million account holders will adopt passkeys over the long term, nor how smoothly unusual recovery cases will work.

The SMS saving is a welcome side effect, but the security improvement is the stronger argument. SMS authentication is better than a password alone, yet it still leaves users typing reusable secrets and codes into pages. Removing that ceremony also removes an attacker’s favourite bit of theatre.