Technology

Google Introduces Passkeys: A More Secure and User-Friendly Alternative to Passwords

Google is introducing "passkeys" to its services, which will provide a more simple and secure method of logging in without the use of passwords. Passkeys are a more secure option than passwords and text-message confirmation codes. Instead of seeing them directly, an online service like Gmail will use them to communicate directly with a trusted

Google Introduces Passkeys: A More Secure and User-Friendly Alternative to Passwords

Google Introduces Passkeys: A More Secure and User-Friendly Alternative to Passwords

Share
Main Image: Threatpost
Advertisement

Google is introducing “passkeys” to its services, which will provide a more simple and secure method of logging in without the use of passwords. Passkeys are a more secure option than passwords and text-message confirmation codes. Instead of seeing them directly, an online service like Gmail will use them to communicate directly with a trusted device like your phone or computer to log you in. All you have to do is verify your identity on the device using a PIN unlock code, biometrics such as a fingerprint or face scan, or a more sophisticated physical security dongle.

For years, passwords have been vulnerable to hackers and human error, and they are far too easy to steal or defeat. Many people choose passwords that are easy to remember; however, passwords that are easy to remember are also easy to hack. According to an examination of hacked password caches, the most commonly used password was “password123.” According to a recent study conducted by the password manager NordPass, it is now just a “password.” In security breaches, passwords are frequently compromised. Stronger passwords are more secure, but only if they are unique, complex, and difficult to guess. Even if you choose a complex password, remembering it may be difficult. Password managers can generate and store complex passwords for you, but even they have a master password that you must safeguard.

Passkeys have one significant advantage over passwords. Because they are specific to specific websites, scammers cannot steal a passkey from a dating site and use it to raid your bank account. The first step in using passkeys is to enable them for your Google account. Open the browser on any trusted phone or computer and sign in to your Google account. Then go to g.co/passkeys and select the “start using passkeys” option.

If you’re using an Apple device, you’ll be prompted to instal the Keychain app if you don’t already have it. The next step is to generate the passkeys that will be used to connect your trusted device. If you’re using an Android phone that’s already logged into your Google account, you’re almost there; Android phones are pre-programmed to use passkeys, though you must enable the feature first. Look for the “Create a Passkey” button on the same Google account page. By pressing it, you will be able to create a passkey on either your current device or another device. There is no such thing as a bad choice; the system will simply notify you if that passkey already exists.

If you’re using a computer that can’t generate a passkey, it will display a QR code that you can scan with regular cameras on iPhones and Android devices. You may need to move the phone closer until the message “Set up passkey” appears on the image. Signing into Google after that will only require you to enter your email address. If you’ve properly configured your passkeys, you’ll simply receive a message on your phone or other device asking for your fingerprint, face, or PIN.

Passkeys are welcome news for those who despise passwords. But why are passwords still so common, and why are they such a problem? The answer is that passwords are simple to understand and apply. They are a simple and effective method of authenticating users. They do, however, have significant security flaws, as we have seen. One of the most serious issues with passwords is that they can be easily guessed or cracked by attackers. Attackers can use automated tools to guess passwords, as well as social engineering techniques to trick users into revealing their passwords.

There are numerous methods for increasing password security. Organisations, for example, can require users to create longer and more complex passwords or use two-factor authentication (2FA). However, even these precautions are not without flaws.

Reporting for Business Tech Africa on the funding, tools and strategy shaping the continent's founders and SMEs.

Was this useful?0 reactions
Huawei apostará por el internet de las cosas para sus dispositivos
Read nextTechnology

Huawei Considers 4,000MWh Battery Storage Project in Egypt

Roy Mulenga · readContinue reading