Hi, this is a sensible move: passkeys should materially reduce phishing risk for GOV.UK One Login users, while also making routine sign-ins quicker. The headline slightly overstates matters, though—passwords are not being “killed off” yet because passkeys remain optional.
Why passkeys are safer
A passkey uses a cryptographic credential associated with the genuine website. A counterfeit GOV.UK sign-in page cannot simply collect and replay it as it could a password or SMS code. That directly tackles the familiar fake-login-page attack.
The fingerprint, face scan or device PIN is normally just the
local unlock method for using the passkey. It is not the passkey itself, and GOV.UK does not need to receive the biometric data.
Passkeys are highly phishing-resistant, but they are not magic armour. Users can still be deceived into disclosing personal information, approving unrelated actions, installing remote-access software or using a weak account-recovery route.
The practical catch is recovery
The important question is what happens after somebody loses or replaces a phone. Users should understand whether their passkey is synchronised through their platform account, stored on another device, or recoverable through a separate GOV.UK process.
Good practice would be to:
- register more than one suitable device or passkey where the service permits it;
- keep the device account itself protected with a strong PIN and MFA;
- review old devices and remove access after selling or losing one;
- store recovery information securely rather than waiting for a broken phone to explain the plan.
For people using shared devices, managed work equipment or older hardware, retaining the existing sign-in route for now is reasonable. Optional adoption is preferable to forcing users into a recovery system they do not understand.
What the rollout does—and does not—show
The reported trial and early login share indicate that the system is usable for a meaningful number of people. They do not establish how many of all 23 million account holders will adopt passkeys over the long term, nor how smoothly unusual recovery cases will work.
The SMS saving is a welcome side effect, but the security improvement is the stronger argument. SMS authentication is better than a password alone, yet it still leaves users typing reusable secrets and codes into pages. Removing that ceremony also removes an attacker’s favourite bit of theatre.