PCMag Analysis: Advantages and Security Risks of Adopting Passkeys
This article from PCMag advocates for transitioning from traditional passwords to passkeys, highlighting their superior security and convenience. Developed by the Fast Identity Online (FIDO) Alliance, passkeys utilize public-private key cryptography, making them resistant to phishing and server-side data breaches since credentials are not stored on company databases. However, the report includes critical insights from security researcher Trevor Hilligoss of SpyCloud, who warns that passkeys do not protect against cookie hijacking. Criminals can steal validated browser cookies via malware to bypass authentication entirely, rendering the login method irrelevant once a session is established. To mitigate this risk, users are advised to minimize cookie session durations through privacy settings. The piece also acknowledges common user complaints, such as confusing terminology and growing pains during widespread adoption. While passkeys represent a significant upgrade in account protection, the article emphasizes that they are not a silver bullet. Website owners must address broader security vulnerabilities, and users should remain vigilant about session management. The overall message encourages adopting passkeys while maintaining awareness of remaining threats like malware and cookie theft.
Wire timeline
PCMag Analysis: Advantages and Security Risks of Adopting Passkeys
This article from PCMag advocates for transitioning from traditional passwords to passkeys, highlighting their superior security and convenience. Developed by the Fast Identity Online (FIDO) Alliance, passkeys utilize public-private key cryptography, making them resistant to phishing and server-side data breaches since credentials are not stored on company databases. However, the report includes critical insights from security researcher Trevor Hilligoss of SpyCloud, who warns that passkeys do not protect against cookie hijacking. Criminals can steal validated browser cookies via malware to bypass authentication entirely, rendering the login method irrelevant once a session is established. To mitigate this risk, users are advised to minimize cookie session durations through privacy settings. The piece also acknowledges common user complaints, such as confusing terminology and growing pains during widespread adoption. While passkeys represent a significant upgrade in account protection, the article emphasizes that they are not a silver bullet. Website owners must address broader security vulnerabilities, and users should remain vigilant about session management. The overall message encourages adopting passkeys while maintaining awareness of remaining threats like malware and cookie theft.
PCMag.com - Technology Product Reviews, News, Prices & Tips