Tech News
← Home  ·  All topics

Passkeys

16 GoKawiil briefs on this topic

GoKawiil Original Passkeys vs Passwords: What Actually Changes for You

Passkeys replace a secret you know with a key your device holds. That single change removes most of what makes phishing work, and it changes how account recovery should be set up.

Apple's Safari privacy tools help but don't fully shield iPhone users, analysis finds

A review of Safari's privacy and security features on iPhone finds that tools like cross-site tracking prevention, Private Browsing, passkeys, and Apple Pay integration meaningfully reduce tracking and phishing risk. However, these protections have clear limits: Safari cannot verify every website's legitimacy, doesn't stop phishing sites from harvesting credentials you enter, and Private Browsing doesn't hide activity from ISPs or sites you're already logged into.

Microsoft sets February 2027 deadline to retire SMS sign-in for Entra ID

Microsoft has told IT administrators to move Entra ID users off SMS and voice-based first-factor sign-in before it shuts the option down in February 2027. Alternatives include passkeys, QR code authentication, and FIDO2 security keys, and the change applies even to organizations using their own telephony providers for multifactor authentication. The retirement covers only workforce tenant scenarios, not customer identity products like Entra External ID.

Opinion: Passkeys solve phishing but raise the risk of permanent account lockout

A tech commentator argues that while Big Tech companies like Google and Microsoft are aggressively pushing users toward passkeys, the technology trades one security risk for another. Passkeys eliminate phishing by binding logins to a specific site, but because they can't be backed up or transferred between hardware keys, users face a higher chance of losing access entirely if devices are lost or accounts are banned.

Google adds direct password-manager transfer tool on Android, skipping file exports

Android now lets users move saved passwords and passkeys directly between password managers through a built-in OS process, without exporting unencrypted files. The system automatically detects compatible managers installed on the device and lets users review data before approving the transfer. Google confirmed support for Google Password Manager, 1Password, Bitwarden, and Dashlane, with more apps expected to add compatibility.

Android adds system-level tool to move passkeys between password managers

Google is rolling out a built-in Android feature that lets users securely transfer both passwords and passkeys directly between credential manager apps, replacing the old method of exporting unencrypted text files or manually recreating passkeys. At launch, the tool supports Google Password Manager, 1Password, Bitwarden, and Dashlane, with other providers able to add support via Android's Credentials Transfer API. Users initiate the process from their new password manager, and Android handles detection, review, and authorization before completing the transfer in seconds.

Google adds direct in-app password manager migration for Android

Google rolled out a new Android feature that lets users transfer passwords and passkeys directly between password manager apps without exporting CSV files. The system works by having the new app request an import from the old one, with Android coordinating the transfer so users can review and approve the data before it moves. The feature currently supports Google's own password manager along with Bitwarden, 1Password, and Dashlane, and works on devices running Android 8 or later.

Attackers Bypass MFA by Targeting Help Desk Account Recovery Processes

Security researchers note that as MFA, conditional access and device trust make direct credential theft harder, attackers are shifting focus to account recovery workflows. Instead of stealing a user's second authentication factor, criminals are tricking service desk staff into resetting or reassigning it on their behalf.

Researchers Catalog 39 Attack Techniques Targeting Passkey Systems

Security researchers, including work from SpecterOps, have documented at least 39 distinct methods that can undermine passkey authentication despite the underlying FIDO2 cryptography remaining secure. These techniques target the surrounding infrastructure rather than the cryptographic keys themselves, including browsers, operating systems, password managers, sync services, Bluetooth transport, and account recovery workflows. Many have working proof-of-concept tools, and some techniques are already surfacing in real-world attack activity.

Microsoft Entra brings device-bound and synced passkeys to general availability

Microsoft Entra now fully supports passkeys as a passwordless authentication method, with both device-bound and synced passkey options reaching general availability. The guide explains how passkeys work using the WebAuthn standard, where a private key stays on the user's device or synced service while a public key is stored in Entra ID.

Apple's iOS 27 Passwords app can auto-fix weak or leaked logins

Apple is adding an agentic AI feature to its Passwords app in iOS 27 that can automatically update weak or compromised passwords instead of requiring users to change them manually. The feature is part of a broader Apple Intelligence push and is currently in beta, with rollout timing uncertain between iOS 27.0 and a later 27.1 update.

WhatsApp lets users swap PINs for passwords, adds multiple passkeys

WhatsApp is rolling out stronger account-security options, letting users replace their six-digit PIN with a full password containing letters, numbers and symbols, and allowing multiple passkeys across Android and iOS devices. The Meta-owned app is also giving users more context on unknown callers, such as whether a number originates from another country.