Passkeys replace a secret you know with a key your device holds. That single change removes most of what makes phishing work, and it changes how account recovery should be set up.
gokawiil.com
· 2026-09-22
A review of Safari's privacy and security features on iPhone finds that tools like cross-site tracking prevention, Private Browsing, passkeys, and Apple Pay integration meaningfully reduce tracking and phishing risk. However, these protections have clear limits: Safari cannot verify every website's legitimacy, doesn't stop phishing sites from harvesting credentials you enter, and Private Browsing doesn't hide activity from ISPs or sites you're already logged into.
engadget.com
· 2026-09-21
Microsoft has told IT administrators to move Entra ID users off SMS and voice-based first-factor sign-in before it shuts the option down in February 2027. Alternatives include passkeys, QR code authentication, and FIDO2 security keys, and the change applies even to organizations using their own telephony providers for multifactor authentication. The retirement covers only workforce tenant scenarios, not customer identity products like Entra External ID.
bleepingcomputer.com
· 2026-09-21
A tech commentator argues that while Big Tech companies like Google and Microsoft are aggressively pushing users toward passkeys, the technology trades one security risk for another. Passkeys eliminate phishing by binding logins to a specific site, but because they can't be backed up or transferred between hardware keys, users face a higher chance of losing access entirely if devices are lost or accounts are banned.
hawksley.dev
· 2026-09-18
Android now lets users move saved passwords and passkeys directly between password managers through a built-in OS process, without exporting unencrypted files. The system automatically detects compatible managers installed on the device and lets users review data before approving the transfer. Google confirmed support for Google Password Manager, 1Password, Bitwarden, and Dashlane, with more apps expected to add compatibility.
techspot.com
· 2026-09-11
Google is rolling out a built-in Android feature that lets users securely transfer both passwords and passkeys directly between credential manager apps, replacing the old method of exporting unencrypted text files or manually recreating passkeys. At launch, the tool supports Google Password Manager, 1Password, Bitwarden, and Dashlane, with other providers able to add support via Android's Credentials Transfer API. Users initiate the process from their new password manager, and Android handles detection, review, and authorization before completing the transfer in seconds.
yro.slashdot.org
· 2026-09-10
Google rolled out a new Android feature that lets users transfer passwords and passkeys directly between password manager apps without exporting CSV files. The system works by having the new app request an import from the old one, with Android coordinating the transfer so users can review and approve the data before it moves. The feature currently supports Google's own password manager along with Bitwarden, 1Password, and Dashlane, and works on devices running Android 8 or later.
techcrunch.com
· 2026-09-10
Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.
bleepingcomputer.com
· 2026-09-09
Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.
bleepingcomputer.com
· 2026-09-04
Microsoft Entra now fully supports passkeys as a passwordless authentication method, with both device-bound and synced passkey options reaching general availability. The guide explains how passkeys work using the WebAuthn standard, where a private key stays on the user's device or synced service while a public key is stored in Entra ID.
emsroute.com
· 2026-09-02
Apple is adding an agentic AI feature to its Passwords app in iOS 27 that can automatically update weak or compromised passwords instead of requiring users to change them manually. The feature is part of a broader Apple Intelligence push and is currently in beta, with rollout timing uncertain between iOS 27.0 and a later 27.1 update.
9to5mac.com
· 2026-08-27
WhatsApp is rolling out stronger account-security options, letting users replace their six-digit PIN with a full password containing letters, numbers and symbols, and allowing multiple passkeys across Android and iOS devices. The Meta-owned app is also giving users more context on unknown callers, such as whether a number originates from another country.
cnet.com
· 2026-08-25