ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

Navigating the passwordless future

Passwords are being replaced by more secure passkeys, but there are still challenges for both consumers and enterprises when it comes to embracing them

 

While passwords won’t simply disappear anytime soon, significant strides have been made towards a passwordless future in recent years.

 

The prevalence of phishing attacks, often involved in high-profile data breaches, has led to greater awareness of the inadequacy of the traditional username and password combination as a sole means of authentication. As a result, many organisations now supplement passwords with multi-factor authentication (MFA), if they haven’t opted to go passwordless altogether.

 

And the shift away from passwords has received government backing, with GCHQ’s National Cyber Security Centre (NCSC) recently announcing that they should be a thing of the past, and that passkeys should be adopted en masse to decrease security risks.

 

In its accompanying report, the NCSC found that FIDO2 credentials, including passkeys, are as secure or more secure than traditional MFA for individuals. This followed a 2025 announcement from the UK government that it would roll out passkey technology for its digital services as an alternative to the current SMS-based verification system.

 

The NCSC’s recommendation to use passkeys “wherever a service supports them” is to be welcomed from both security and usability perspectives. Passkeys have been specifically designed to overcome our primary problems with passwords.

 

However, the “wherever supported” aspect is a potential challenge, because many users won’t be able to follow the guidance uniformly or consistently across the services they use. Many sites and services still don’t offer passkey support, so users will find themselves with a mixed login experience.

 

Another likely challenge is that many individuals won’t know what passkeys are, or why they’re now the standard. We told people for years to use better passwords, then we told them to use two-step verification or MFA, and now there’s something else. It’s still the correct advice, but no matter how good passkeys are, we need to recognise that this is going to be a long game rather than flipping a switch.

 

In fact, the authentication end-user experience may end up involving multiple approaches, with some systems and services using traditional passwords, some using MFA and others offering passkey support and passwordless options. What’s more, the experiences within the categories could also vary – for example, with MFA being applied differently across different systems. Such inconsistencies have the potential to confuse users.

 

Where passwords are still in use, it’s far too easy to find sites that fail to support the user in two significant and fundamental ways: by asking them to create new passwords while providing little or no tangible guidance on how to do so securely, and/or allowing them to get away with making choices that would generally be regarded as weak. 

 

While some might argue that it’s the user’s responsibility to protect themselves properly, they need to know how to do it. Where are they supposed to get this knowledge if the sites don’t offer it? Why would the user even suspect there’s a problem if the site lets them choose a poor password without complaint? 

 

The main message ought not to be to the users, who often have no choice but to use passwords anyway, but to the sites and providers that require them to do so. The adoption of any approach beyond traditional passwords requires effort and investment, which goes some way to explaining why all too many organisations haven’t advanced beyond these. Indeed, some still fail to follow the recommended best practice in using basic passwords, such as continuing to enforce password complexity, in line with longstanding advice from the NCSC and National Institute of Standards and Technology.

 

The authentication landscape has evolved, and we now have better options available across many devices and services, with password managers, passkeys and biometrics all playing their part in reducing the burden on users and improving protection. At the same time, these solutions are far from ubiquitous. Many leading websites still use passwords as the basis for sign-up, and it varies as to whether other options are available or clearly signposted once accounts are set up.

 

What’s more, many organisations may have only recently moved to MFA, and so will have less desire or incentive to change again, even though the resulting user experience could undoubtedly be improved with passkey support. Meanwhile, some may be stuck with traditional passwords if, for example, they are simply not in a position to update their in-house, bespoke and legacy systems.

 

The transition to a passwordless future is well underway, but it will likely take some time before we can realise the promised security and usability benefits.


 

Steven Furnell, senior IEEE member and Professor of Cybersecurity, University of Nottingham
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543