A tech commentator argues that while Big Tech companies like Google and Microsoft are aggressively pushing users toward passkeys, the technology trades one security risk for another. Passkeys eliminate phishing by binding logins to a specific site, but because they can't be backed up or transferred between hardware keys, users face a higher chance of losing access entirely if devices are lost or accounts are banned.
hawksley.dev
· 2026-09-18
A Hacker News user described being locked out of Google, banking, email and Drive accounts after their phone was stolen, since 2FA and account recovery relied on that device and an old email they could no longer access. The poster noted Google's automated recovery flow offers only options tied to the lost phone or an outdated backup email, leaving no clear path to a human for help.
news.ycombinator.com
· 2026-09-17
Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.
bleepingcomputer.com
· 2026-09-09
A joint alert from the US State Department, Japan, Canada and the UK warns that North Korean operatives are using falsified identity documents to get hired as remote IT workers at foreign companies, letting them enter corporate networks with legitimate-looking access. Separately, groups like Scattered Spider have used social engineering against help desks to trick staff into resetting passwords or MFA for accounts they don't own, bypassing strong authentication entirely.
bleepingcomputer.com
· 2026-08-25