2025-05-08
UK Government Turning to Passkeys for Digital Services
The UK government plans to roll out passkeys for digital services later this year. The technology will replace SMS-based verification. As described by the National Cyber Security Centre, "Passkeys are unique digital keys that are today tied to specific devices, such as a phone or a laptop, that help users log in safely without needing an additional text message or other code. When a user logs in to a website or app, their device uses this digital key to prove the user's identity without needing to send a code to a secondary device or to receive user input." The shift to passkeys will not only be cost effective, but also expected to improve security.
Editor's Note
The plan is not only to move away from SMS-based 2FA to passkeys, removing the risks around SMS, but also to remove passwords altogether. Further, the UK NCSC has joined the FIDO Alliance, providing a path for UK agencies to collaborate with alliance members on the development and deployment of needed technologies to keep the bar high.

Lee Neely
The tech industry, primarily companies that provide digital services, has been moving to passkeys for the last few years (see recent reporting in SANS NewsBites Vol. 27, No. 35). Glad to see a government organization adopting passkeys. Additional kudos for mandating the authentication standard, FIDO, for the solution. Hopefully the USG will follow the UK in the use of passkeys for its digital services.

Curtis Dukes
2025 is proving to be the year of Passkeys, the use of asymmetric key cryptography to authenticate clients to servers. For single user devices, they serve to authenticate the single user. However, for shared devices, they depend upon the ability of the device to associate a private key with an individual and to limit the use of that key to just that user. As we increase the use of this convenient mechanism, we must account for this limitation.

William Hugh Murray
Read more in
NCSC: UK pioneering global move away from passwords
SC Magazine UK: UK Government Plans Passkey Rollout
Gov Infosecurity: UK Government to Roll Out Passkeys Late This Year
Biometric Update: UK govt commits to passkeys in another big step to a passwordless world
Infosecurity Magazine: Passkeys Set to Protect GOV.UK Accounts Against Cyber-Attacks