Passkeys are digital keys that replace passwords, using your device's biometric or PIN verification to securely sign in without transmitting passwords. Each service gets a unique passkey based on public key cryptography, protecting against password reuse, theft, and phishing attacks.
Microsoft is retiring SMS and voice as first-factor authentication methods for Entra ID starting February 2027, requiring administrators to migrate users to phishing-resistant alternatives like passkeys, FIDO2 security keys, or QR code authentication. The company has already ended SMS sign-in for free tenants and is rolling out passkeys as the default authentication method. Organizations must complete migration before the deadline to avoid sign-in disruptions.
Seal is an app that lets users create encrypted letters, passwords, and secrets for family members to access after death. The app stores sealed envelopes on iCloud with keys split among trusted people, requiring multiple key holders to open them after a set period of inactivity.
A company reflects on their four-year-old article advocating for WebAuthn-based two-factor authentication, which they claim has proven prescient. They highlight additional positions on transactional email privacy, email independence from major tech companies, European SaaS viability, and AI's limited scope.
The author argues that while passkeys offer strong security against phishing and breaches, they present practical challenges for personal use, including risks of permanent account lockout, device loss, expensive hardware key requirements, and fragmented cross-platform support. Passkeys work better in corporate environments but create false security by still relying on weak recovery methods.
Android now enables secure, seamless switching between password managers by allowing direct transfer of passwords and passkeys between apps without requiring unencrypted file downloads. The feature is available on Google Password Manager, 1Password, Bitwarden, and Dashlane, with more partners planned.