Welcome to the First Column IT Tech Blog

HomeBlog
There’s Been Another Step Towards Passwordless Authentication

There’s Been Another Step Towards Passwordless Authentication

January 27, 2023

While at the moment, passwords are an important part of your security stack, it is important to acknowledge that the concept of the password was always a flawed system and is overdue to be replaced. This may become a widespread reality sooner than you may expect, too, especially with the buy-in that the big names in tech are demonstrating.

Let’s consider a recent step that one of these big names recently took that shows particular promise for a passwordless future.

Enter the Passkey, and Google’s Embrace of It

The concept of a passkey is a simple one—basically, it’s another stored credential, but in this case, it is stored on the device and is exchanged with the website directly. This way, all obligations for the user to remember any credentials is eliminated.

The passkey is, on almost all counts, a superior means of authentication—and it’s all because it eliminates the need for a password text box at all. Instead of relying on the user to provide a form of authentication, passkeys are automatically generated and are inherently more secure than any user-generated form of authentication.

The trouble is, in order for passkeys to work, support for them will need to become standard. As in, every website, every browser, and every password manager will need to implement them. In addition to this, passkeys will require the user to have their phone handy and to use a Bluetooth connection to allow the phone to talk to the device in use. This localization, while helping protect your accounts, will also eliminate the capability of most desktops to utilize it.

Google, and Many Others, are Enthusiastic about Passkeys

Apple, Google, the FIDO Alliance, and Microsoft have all put their support behind the idea, with Google launching betas on both Chrome and Android, and iOS version 16 implementing it.

Google’s beta—which you can sign up for through Play Services—allows you to create passkeys on your Android devices, and passkeys are now supported in Chrome Canary, with more stable versions promised soon.

Google’s plan is to utilize its Password Manager to store these passkeys. The mobile device will have the user pick the correct account, then use a biometric proof to authenticate their identity. The phone will send over the authentication via Bluetooth, the browser sends the passkey to the website, and you’re in. Of course, if you’re actively logging in to something on your phone, the Bluetooth step is skipped.

We look forward to seeing how this technology develops and the prospect of using it as a means of potentially simplifying user authentication, without shortchanging security as a result. While there’s still some work to be done, the promise is there. In the meantime, reach out to us at (571) 470-5594 to find out how we can help you manage your current cybersecurity and user authentication needs.

Previous Post
May 2, 2025
Dark Web Monitoring Shouldn’t Be an Afterthought
There are a lot of sketchy parts of the Internet, but the sketchiest of all might be the Dark Web. Located on a part of the Internet that search engines don’t index and inaccessible to most web browsers, the Dark Web is a place where cybercriminals thrive. It’s a place where stolen data is put up for sale, and if you’re not careful, your business could be next.
April 30, 2025
How to Break the “Who Cares” Mindset
More often than not, you have an employee on staff who rolls their eyes whenever you have to send out another cybersecurity email or reminder. This “who cares” mindset is dangerous and can infect your business in a profoundly disturbing way. Today, we want to get into why this “who cares” mindset is so dangerous and what’s really at stake when you have an employee who can’t get on board with your security policies.
April 28, 2025
Learn How Resilience is Reshaping the Cybersecurity Landscape
While the goal of cybersecurity is always to prevent threats from taking advantage of your infrastructure, this is becoming more and more challenging as time wears on and threats evolve to changes in cybersecurity discourse. A recent podcast episode from Illumio, “Trust & Resilience: The New Frontlines of Cybersecurity,” explores how trust has become a vulnerability that attackers exploit in new and creative ways. How can cybersecurity as an industry pivot in response to this trend?

Have a project in mind?

Start with our free consultation. We will provide a detailed proposal and firm quote based on your specific IT support needs. All at a predictable monthly cost per seat.
Free Consultation - Sign Up Here