UK Rolls Out Passkeys for Millions of Citizens

UK Rolls Out Passkeys for Millions of Citizens

The UK is rolling out passkeys across GOV.UK One Login to provide more than 23 million people with a more secure way to log in.

Passkeys are secure digital credentials that are meant to replace passwords. They are securely generated and stored on your device, so they're always random and secure since you don't have to come up with them yourself.

They operate using public key cryptography, similar to PGP or TLS. Your private key is never stored by the website you're logging in to, so your login credentials can't be leaked in a data leak like passwords can.

They're also phishing-resistant: if you try to log in to a fake website with your real credentials, it won't work, since the credentials are tied to that specific website.

The UK says that more than 300,000 users have switched to passkeys already during the initial trial phase, and they are now rolling them out to millions of users.

Nearly one in 10 daily GOV.UK One Login sign-ins are now made using passkeys, helping to save the British taxpayer nearly £600 a day in SMS costs.

SMS is a common way services try to secure user accounts, but it's clearly costly to send the codes out and SMS is horribly insecure. It has no encryption, so anyone can see your sensitive login code in transit. It's also vulnerable to SS7 attacks that allow attackers to intercept and send your login codes wherever they want.

For now, there's no option to sign up with a passkey, you have to add one later after you create your GOV.UK account with a password. There's also no way to remove your password after you make a passkey, which negates many of the benefits of passkeys in the first place: an attacker could still pretend to be GOV.UK and simply ask for the password instead, and every user would still be in danger of getting phished.

The account also requires an email address, and you can simply bypass the passkey and password by clicking on "forgot my password." This leaves a big gaping security hole where any attacker that has access to your email account, or intercepts the password reset email which is not end-to-end encrypted, can get access to your government account.

Still, it's good to see governments offering more secure login methods even if there's still room for improvement.

Community Discussion