The Times Australia
The Times World News

.

Apple's PassKeys update could make traditional passwords obsolete

  • Written by Paul Haskell-Dowland, Professor of Cyber Security Practice, Edith Cowan University
Apple's PassKeys update could make traditional passwords obsolete

Sometimes it seems like passwords have been with us forever, and yet every year we’re reminded how we still don’t[1] use them properly!

The annual publication of the “worst passwords” list[2] shows we haven’t become much more password savvy over the decade. And while several replacements for the humble password have been proposed, none have come close to the ease of using the traditional method.

But this changes today with the introduction of Passkeys – an update in Apple’s latest iOS 16 operating system. Passkeys could be the long-awaited solution to password malpractice, and the near-constant problem of compromised credentials.

Read more: This New Year, why not resolve to ditch your dodgy old passwords?[3]

What’s wrong with passwords?

The problem with passwords has been well documented. We choose weak ones, write them down (for others to see), share them, and re-use them on multiple websites.

The last of these is particularly problematic. Once your details are breached (and subsequently leaked), they’re vulnerable to “credential stuffing” – where cybercriminals take a set of login credentials and try them on multiple websites.

A yellow sticky note with a password is stuck to a computer monitor.
People still stick passwords to their monitors! Author provided

“But I use a password manager,” you might say.

Well, that’s good. The standard advice for years has been to use password managers such as 1Password or LastPass. These let you create unique passwords for each website or service you use. So even if a website is compromised, only one password is revealed.

But this approach requires the ability to synchronise across all your devices – a feature not all password managers provide.

And even with a password manager, our passwords are still stored on the remote website we’re accessing. Although most websites store passwords in a secure (hashed) format, they are still routinely compromised[4]. It’s estimated more than two billion sets of credentials[5] (including passwords) were leaked online[6] in 2021.

Along come Passkeys

Apple devices using the newest operating system release (iOS 16 or MacOS Ventura) will integrate a new password mechanism called Passkeys. Unfortunately iPad users will need to wait a little longer[7] for the feature.

It’s worth noting you won’t be forced to use Passkeys, but your Apple device will prompt you with the opportunity to do so. Also, most websites will continue to support password access for people without the latest devices.

You’ll also have the option to use Apple’s secure cloud storage, iCloud, to back up your keys and share them across your Apple devices.

How do they work?

The concept behind Passkeys is relatively simple[8]. Every website you elect to use Passkeys on will securely generate a unique pair of secret codes (referred to as “keys”).

One of these is a public key, stored on the website you’re registered on. The other is a private key stored on your device. Both keys are related, but one can’t be used to get the other.

When you attempt to log in to the website, instead of entering a password, your device will ask you to verify your login using your device’s biometric unlocking mechanism. So you’ll either scan your face or your finger.

This deliberately limits Passkeys’ functionality to devices with biometric support (iPhones have offered Touch ID since 2013 and Face ID since 2017).

Read more: The iPhone turns 15: a look at the past (and future) of one of the 21st century's most influential devices[9]

Once your biometrics are verified, your device will use your private key to prove your identity to the website by tackling a complex mathematical “challenge” issued by the site. At no point is your private key sent across the internet to the website.

The response from your device can only be verified by the website, using the public key generated when you registered. And nobody can pretend to be you without your private key, which is safely stored on your device.

If a website is compromised, the public key alone is useless to cybercriminals.

A diagram of the four steps involved in passwordless web authentication, which happens between a user's device and the online site or service being accessed.
Passwordless web authentication uses a combination of two keys, one public and one private. Paul Haskell-Dowland

Moreover, while biometric technology can be compromised, this is relatively[10] difficult[11]. To exploit a biometrics/PassKeys combination, a criminal would first need to obtain your device and then do a great job faking your face or fingerprint (or force one from you) – unlikely circumstances for most users.

Usability barriers

Passkeys will initially launch on Apple, but others are close behind. Microsoft will likely launch its own equivalent soon, although it may not initially be compatible[12] with Apple’s implementation. This could be an issue for people wanting to use both an iPhone and Windows laptop.

Moving forward, it’s important Apple, Google and Microsoft work together to ensure maximum compatibility across devices.

Until then, there are some workarounds. If you need to access an Apple Passkeys-protected service on your Windows laptop (or any other device), you can scan a QR code with your iPhone and provide your biometric login verification that way.

QRCodes allow for the use of Passkeys on non-supported devices (or when using a friends computer).
QR codes will allow for the use of Passkeys on non-supported devices (or when using a friend’s computer). Apple

This means users will always need to have their phone on them when they want to authenticate to a remote service – whereas currently they can just type out their password, or use a password manager synced across their devices.

For some users, needing to have their phone all the time could be enough to give Passkeys a pass altogether.

The long tail of adoption

The Passkeys approach has the potential to make passwords obsolete, but this will require organisations around the world to invest time, effort and money into it.

Big players like social media companies are well positioned to adopt Passkeys early on, but there will be millions of websites that may take years to do so – or may never.

Indeed, looking at the state of play today, many leading sites still fall short[13] of applying existing good practice around passwords. So it’s hard to say exactly how quickly, and how widely, Passkeys will be implemented.

Read more: Four ways to make sure your passwords are safe and easy to remember[14]

References

  1. ^ still don’t (theconversation.com)
  2. ^ list (en.wikipedia.org)
  3. ^ This New Year, why not resolve to ditch your dodgy old passwords? (theconversation.com)
  4. ^ routinely compromised (theconversation.com)
  5. ^ sets of credentials (www.forgerock.com)
  6. ^ leaked online (haveibeenpwned.com)
  7. ^ little longer (9to5mac.com)
  8. ^ relatively simple (support.apple.com)
  9. ^ The iPhone turns 15: a look at the past (and future) of one of the 21st century's most influential devices (theconversation.com)
  10. ^ relatively (www.macrumors.com)
  11. ^ difficult (www.ccc.de)
  12. ^ be compatible (www.fastcompanyme.com)
  13. ^ fall short (doi.org)
  14. ^ Four ways to make sure your passwords are safe and easy to remember (theconversation.com)

Read more https://theconversation.com/apples-passkeys-update-could-make-traditional-passwords-obsolete-188300

Times Magazine

Headless CMS in Digital Twins and 3D Product Experiences

Image by freepik As the metaverse becomes more advanced and accessible, it's clear that multiple sectors will use digital twins and 3D product experiences to visualize, connect, and streamline efforts better. A digital twin is a virtual replica of ...

The Decline of Hyper-Casual: How Mid-Core Mobile Games Took Over in 2025

In recent years, the mobile gaming landscape has undergone a significant transformation, with mid-core mobile games emerging as the dominant force in app stores by 2025. This shift is underpinned by changing user habits and evolving monetization tr...

Understanding ITIL 4 and PRINCE2 Project Management Synergy

Key Highlights ITIL 4 focuses on IT service management, emphasising continual improvement and value creation through modern digital transformation approaches. PRINCE2 project management supports systematic planning and execution of projects wit...

What AI Adoption Means for the Future of Workplace Risk Management

Image by freepik As industrial operations become more complex and fast-paced, the risks faced by workers and employers alike continue to grow. Traditional safety models—reliant on manual oversight, reactive investigations, and standardised checklist...

From Beach Bops to Alpine Anthems: Your Sonos Survival Guide for a Long Weekend Escape

Alright, fellow adventurers and relaxation enthusiasts! So, you've packed your bags, charged your devices, and mentally prepared for that glorious King's Birthday long weekend. But hold on, are you really ready? Because a true long weekend warrior kn...

Effective Commercial Pest Control Solutions for a Safer Workplace

Keeping a workplace clean, safe, and free from pests is essential for maintaining productivity, protecting employee health, and upholding a company's reputation. Pests pose health risks, can cause structural damage, and can lead to serious legal an...

The Times Features

Prefab’s Second Life: Why Australia’s Backyard Boom Needs a Circular Makeover

The humble granny flat is being reimagined not just as a fix for housing shortages, but as a cornerstone of circular, factory-built architecture. But are our systems ready to s...

Melbourne’s Burglary Boom: Break-Ins Surge Nearly 25%

Victorian homeowners are being warned to act now, as rising break-ins and falling arrest rates paint a worrying picture for suburban safety. Melbourne residents are facing an ...

Exploring the Curriculum at a Modern Junior School in Melbourne

Key Highlights The curriculum at junior schools emphasises whole-person development, catering to children’s physical, emotional, and intellectual needs. It ensures early year...

Distressed by all the bad news? Here’s how to stay informed but still look after yourself

If you’re feeling like the news is particularly bad at the moment, you’re not alone. But many of us can’t look away – and don’t want to. Engaging with news can help us make ...

The Role of Your GP in Creating a Chronic Disease Management Plan That Works

Living with a long-term condition, whether that is diabetes, asthma, arthritis or heart disease, means making hundreds of small decisions every day. You plan your diet against m...

Troubleshooting Flickering Lights: A Comprehensive Guide for Homeowners

Image by rawpixel.com on Freepik Effectively addressing flickering lights in your home is more than just a matter of convenience; it's a pivotal aspect of both home safety and en...