Security News

UK Government Rolls Out Passkeys to 23 Million Users, Ditching Passwords for Good

The Register · 14 Sept 2026
Key Takeaway Australian small businesses should consider offering or adopting passkey login options where available, as they reduce phishing risk and cut reliance on vulnerable SMS-based authentication.

The UK government is offering more than 23 million users of its GOV.UK One Login service the option to log in using passkeys instead of passwords. Passkeys let people sign in with a fingerprint, Face ID, or device PIN, removing the need to remember a password or wait for a text message code. The rollout follows a trial involving over 300,000 users, and officials say nearly one in ten daily sign-ins are now made using passkeys, which are reportedly up to eight times faster than traditional password and two-factor authentication logins.

Unlike passwords, which can be stolen, reused, or entered into fake login pages, passkeys rely on cryptographic credentials unique to the site or app they were created for. The biometric data or PIN used to unlock a passkey stays on the user's own device and is never seen or stored by the government service. The National Cyber Security Centre says this makes passkeys highly resistant to phishing attacks, a common method criminals use to steal login credentials.

The move also has a practical cost benefit: the government says it is already saving close to £600 a day in SMS charges as fewer people rely on text-based authentication codes. Passkeys remain optional for now, and existing password-based logins are still supported for those who prefer them. GOV.UK One Login is used to access a range of services, including State Pension details, tax accounts, and childcare support.

Summarised by CISO AI from The Register. We link back to every original so you can read it yourself.