tech
Apple, Google, and Microsoft are phasing out passwords in favor of a new login method backed by the FIDO Alliance.
A passkey works through public-key cryptography, where your device generates a matching pair of keys: a private key that stays locked on your phone or computer, and a public key that the website stores. When you log in, the website sends a challenge that only your private key can answer correctly, so there is never a shared password traveling over the internet for hackers to intercept or a database of passwords for them to steal.
A password manager simply stores and autofills traditional passwords, meaning a stealable secret still exists somewhere; it is a helpful tool but not the passwordless credential the FIDO Alliance is standardizing. A one-time PIN is a temporary code sent by text or app, useful for extra verification but still a shared secret that can be phished or intercepted.
Because a passkey never leaves your device, even if a website you use gets hacked, attackers only get a useless public key, which is why major companies are racing to replace decades of insecure password habits with this approach.
tech
What is this security model called?What is this branch of cryptography commonly called?What is this type of attack, which reaches its target through a trusted supplier or dependency, called?What term describes this scam that uses AI to clone a real person's face or voice?Which kind of file is being phased out here?What is this emerging approach called?What is this Apple feature called?What is this social-engineering trick commonly called?What is this quiet, continuous form of authentication called?What does an AI coding assistant like Copilot mainly do?What everyday task do these AI 'live translation' tools aim to handle?What does a text-to-video AI like Sora generate?Quration — Quration Play