Skip to main content
  1. Home
  2. Computing
  3. News

This website publicly shames popular sites like Instagram, Netflix, and Spotify for being too lazy to add passkeys

Apple, Google, and Microsoft fully support passkeys, while companies like Netflix and Spotify have offered no explanation for the gap.

Add as a preferred source on Google
passkey
Whatsapp

A new website is doing something many frustrated security experts have wanted for years. It is publicly naming big companies that still refuse to support passkeys. Called Why No Passkeys, the site tracks major platforms that continue to rely on old-school passwords even as passkeys become the safer option. If you use apps like Instagram, Netflix, or Spotify, you might be surprised to see them on the list.

The website was created by security researcher Scott Helme, who previously teamed up with Troy Hunt in 2017 to launch WhyNoHTTPS, a site that helped push much of the internet toward encrypted browsing.

A surprising number of tech giants are stuck in the past

Passkeys are designed to replace passwords with device-based logins like Face ID or fingerprint scans. They are harder to steal, phishing-resistant, and far easier to use. Big names like Google, Apple, and Amazon have already embraced them, but many popular consumer platforms have not.

Recommended Videos

7 of the top 25 most visited sites globally still lack native passkey support, including Instagram, Netflix, Spotify, Samsung, Roblox, and Baidu. These are not small businesses without engineering resources; they are platforms with hundreds of millions, sometimes billions, of users still protected by nothing more than a password.

Interestingly, Meta already offers passkeys on Facebook and WhatsApp, yet Instagram users can only access the feature if they link their account to a Facebook login with passkeys enabled (via TechCrunch).

Why it matters?

The site works like a public leaderboard, separating companies that support passkeys from those that do not. Their goal is to create public pressure and make it harder for companies to ignore better security.

This matters because passwords remain one of the weakest links online. Data breaches, reused logins, and phishing scams still hit users every day, and passkeys eliminate many of those risks. For you, it’s a reminder that even the apps you trust most may still be behind on security. And now, there is a website making sure everyone knows it.

Manisha Priyadarshini
Manisha Priyadarshini is a tech and entertainment writer with over nine years of editorial experience.
South Korea wants to give every citizen free, unlimited access to its own AI chatbot
The government-backed service could turn generative AI into public infrastructure instead of another monthly subscription
Electronics, Mobile Phone, Phone

South Korea wants to give every citizen free access to an AI chatbot with no usage limits. That puts the technology closer to a public utility than another premium service demanding a monthly subscription.

The Ministry of Science and ICT announced the AI for Everyone project on July 13. Private companies will build the platform around locally developed models, while a separate AI agent will help people navigate government services. It’s a more practical job than generating emails or settling arguments nobody wanted to research themselves.

Read more
Falling in love with a chatbot is now off limits for kids in China
The crackdown targets emotional AI relationships as regulators worry about the country's record low birthrate.
Replika AI companion app on an iPhone in hand

Ever since AI chatbots arrived on the scene, there has been one aspect that has worried lawmakers and experts a lot: humans forming emotional connections with chatbots. There have been plenty of cases where over-reliance on these AI companions or partners has resulted in medical emergencies, lost lives, and triggered multiple lawsuits against the likes of OpenAI and Meta.

China cracks down on AI companion apps

Read more
Russian hackers keep finding their way into critical networks through neglected routers
A multinational warning says outdated firmware, weak passwords, and insecure settings are giving state-backed attackers an easy opening
A Wi-Fi router next to a laptop.

Russian state-backed hackers have spent more than a decade exploiting a stubborn weakness in critical infrastructure networks. Organizations are still leaving poorly configured and outdated routers exposed to the internet.

In a joint cybersecurity advisory, the NSA, CISA, FBI, and international partners warn that hackers linked to Center 16 of Russia’s Federal Security Service are continuing to target vulnerable networking equipment. Energy, healthcare, and government networks are among the sectors facing the highest risk.

Read more