Skip to main content
  1. Home
  2. Phones
  3. Mobile
  4. News

Google is killing your passwords, and security experts are (mostly) happy

Add as a preferred source on Google
Google account prompt explaining passkeys.
Digital Trends
Promotional image for Tech For Change. Person standing on solar panel looking at sunset.
This story is part of Tech for Change: an ongoing series in which we shine a spotlight on positive uses of technology, and showcase how they're helping to make the world a better place.

Google is inching closer to making passwords obsolete. The solution is called “Passkeys,” a unique form of password that is stored locally on your phone or PC, just the way a physical security key works. The passkeys are protected behind a layer of authentication, which can be your fingerprint or face scan — or just an on-screen pattern or PIN.

Passkeys are faster, linked across platforms, and save you the hassle of remembering passwords for websites or services that you have subscribed to. There is a smaller scope for human error, and the risks of 2-factor authentication code interception are also reduced.

Recommended Videos

Developed in collaboration with Microsoft and Apple, Google is now taking the next steps to take passkeys mainstream by making them the default log-in option. You won’t be forced to ditch your usual log-in methods, but if you haven’t already enabled passkeys, you will be nudged the next time your Google account is used for a sign-in request.

Why passkeys are better than passwords

Prompt for creating a passkey for a Google account.
Digital Trends

Passkeys employ what you would call a digital handshake, which involves creating a pair of passwords using cryptographic methods. One is stored with the app or web service, while the other one remains with the user, protected by an on-device password or biometric authentication. There is no two-factor code involved, and all you need to do is tap on a prompt on your device to allow the identity verification.

Trevor Hilligoss, who has previously worked as a security expert with the FBI and currently handles security research at SpyCloud, tells Digital Trends that passkeys are “strong by nature, and it’s why many security teams prefer this mode of defense.” The biggest advantage here is that they are not dumped like your average alphanumeric password in data breaches. That’s a problem for multiple reasons because an alarmingly high number of digital citizens reuse the same password, or a predictably modified form of it, across different services.

Passkeys are faster (up to 40%, according to Google), safer, and more convenient. But Hilligoss warns that they’re not exactly a silver bullet of digital safety. “Cybercriminals are rapidly adapting to this technology by shifting their focus from stealing account credentials to account recovery methods, developing tactics to steal passkeys and launching attacks such as session hijacking.”

Passkeys are good, but they aren’t perfect

Security expert Trevor Hilligoss.
Security expert Trevor Hilligoss SpyCloud

Hilligoss points to a technique called session hijacking — also known as cookie hijacking – where a hacker tries to take control of your online browsing session to steal sensitive data. Essentially, the bad actors fool a website into thinking that it’s a legitimate user. When a person visits a website, a session ID is created that often remains active for days.

This session data is stored in the form of numbers and letters in temporary session cookies, and it remains in the browser until the user is logged out. Hackers can steal session IDs by injecting scripts into web pages, intercepting the network traffic, deceptively installing malware on the victim’s device, or simply using pattern prediction.

“Once the attacker has hijacked a web session, they can do anything the original user can, including purchasing items, stealing confidential personal information, or accessing bank accounts,” Hilligoss adds. In such attacks, it doesn’t matter if the sign-in was allowed using a traditional password or passkeys.

What this all means for you

Logging into a Google account with passkeys on an iPhone.
Digital Trends

Passkeys are tied to Google Password Manager, while Apple brings the iCloud Keychain into the picture, which means passkeys are also synced across devices. By default, Google also automatically creates a passkey for freshly activated Android devices. However, as we leave behind passwords, hackers are also moving ahead with more sophisticated techniques.

Passkeys also won’t block other forms of cyberattacks, like malware deployment in varied forms, a scammer impersonating a bank official on a phone call (hello, generative AI hell), social engineering attacks, and more. Passkeys only solve one side of the security flaw, but they’re from being a cure-all trick.

Digital literacy is still going to be of paramount importance in the years ahead as third-party services slowly embrace passkey. Hilligoss suggests one should prefer app-based 2-factor authentication, keep changing passwords at regular intervals, double-check the URLs and links they receive, and stay vigilant about phone calls from unknown numbers.

“Proper cyber hygiene and exercising visibility into your online accounts will go a long way in staying ahead of cybercriminals,” he concludes.

Nadeem Sarwar
Nadeem is the Managing Editor at Digital Trends.
Google just made switching from iPhone to Android much easier with Android 17
Android 17 can now transfer your passwords, passkeys, eSIM, and even your home screen.
Android-17-switch-ios-to-android

Moving from an iPhone to an Android phone has never been an easy process, but Google is trying to change that. With Android 17, the company has introduced a rebuilt Android Switch that can move far more of your data than any past version ever could.

Google worked with Apple to create the new transfer system from the ground up, allowing far more information to move wirelessly than before. The upgraded experience is already rolling out to eligible Pixel devices and is also available on Samsung's new Galaxy Z Fold 8 and Galaxy Z Flip 8 through Smart Switch.

Read more
WhatsApp’s new in-car experience is built around hands-free control
CarPlay and Android Auto users can now hear and reply to messages, view call history, and reach favorite contacts without touching their phone.
WhatsApp new CarPlay experience featured

Meta is overhauling how WhatsApp works in the car, giving CarPlay and Android Auto users a lot more to do than just sending texts and making calls. The company announced the change in a newsroom post today, alongside several other updates rolling out to the messaging app.

WhatsApp finally works hands-free in the car

Read more
I tried the Samsung Galaxy Z Fold 8 and I am totally in love with this unique foldable
Samsung's Galaxy Z Fold 8 trades bulk for a genuinely pocketable design, and after holding one next to an iPhone 17 Pro, I'm convinced it's the foldable to beat this year.
Symbol, Electronics, Mobile Phone

Samsung is trying to jazz things up once again in the foldable space, and the mantra this time around is going smaller and lighter. The result of those efforts is the Galaxy Z Fold 8, and it’s the first time in years that I vocally said “wow” the moment I picked it up. It’s pocketable, light, sleek, and most importantly, oozes functional charm. 

Just take a look at how petite it is when held alongside a modern-age iPhone. In an age when smartphones are getting thicker and bulkier, the Galaxy Z Fold 8 wants to stand out in a rather unique fashion. Even in the unfolded state, it’s less than a millimeter thicker than an iPhone 17 Pro (9.7 vs 8.75 mm). If you compare the weight, the comparison flips in its favor. The Galaxy Z Fold 8 is lighter than even the smaller iPhone 17 Pro (201 grams vs 204 grams).

Read more