23M Brits can now skip passwords for GOV.UK services
Passkeys may be easier for users, but they’re not a silver bullet.

Image by Chris Dorney | Shutterstock
- More than 23 million Brits can use passkeys to access GOV.UK services.
- Passkeys use a face scan, fingerprint, or PIN instead of a traditional password.
- The UK government says passkeys are faster and can reduce SMS verification costs.
- Experts warn weak account recovery can still let attackers bypass passkey protections.
Key Takeaways by nexos.ai, reviewed by Cybernews staff.
The UK government is offering more than 23 million Brits the chance to ditch their passwords and use their face, fingerprint or PIN to access public services.
Passkeys are being rolled out to users of GOV.UK’s government services login including tax, childcare support and checking the state pension, as the government attempts to kill the traditional password.
Passkeys allow the user to sign into apps and websites using device-level authentication with biometric data such as facial recognition, fingerprints or a PIN number.
The government isn’t ditching passwords just yet but the roll out has followed a successful trial with more than 300,000 people switching to passkeys.
Almost one in ten daily GOV.UK login sign-ins are already being made using them.
In a statement issued Monday the government claimed that the technology was more secure than passwords and considerably faster than having to enter a username, a password and then a two-step verification code.
Passkeys mean people can access the services they rely on in seconds, using the same fingerprint or face scan they already use to unlock their phone.– Digital Government Minister Stephanie Peacock
It is thought that reducing the number of security codes sent by text will also save taxpayers almost £600 a day in SMS costs.
Passkeys phishing resistant
The UK's National Cyber Security Center director for national resilience Jonathon Ellison called passkeys a "highly phishing-resistant alternative" to passwords because they work only with the legitimate website they were created for.
If a person is tricked into clicking a link and lands on a fake site, the passkey won't authenticate the login attempt, stopping the attacker cold.
Are passkeys really unhackable?
However, experts warn that no authentication system is invulnerable.
In August, researchers from Palo Alto Networks’ Unit 42 disclosed attacks on Google’s passkey sync system, showing that malware which is already on a victim’s Windows computer – such as via ClickFix – could exploit weaknesses in device trust, setup, and account recovery.
The security firm demonstrated one version of this technique against eBay, which the online retailer has subsequently fixed.
Stay updated with our latest stories and follow us on social media
Be the first to discover new stories, ideas, and updates from our team.
Other attacks went further, demonstrating techniques that could allow malware to extract the cryptographic material protecting Google's synchronized passkeys.
Shane Barney, CISO at Keeper Security tells Cybernews: “The research into Google’s passkey architecture illustrates why these supporting processes deserve the same scrutiny as the authentication mechanism itself.”
A compromised passkey-provider account or poorly secured recovery process can create a new route into an otherwise phishing-resistant system.– Shane Barney, CISO, Keeper Security
The recovery problem
Another challenge is how a user recovers their account if they lose their device.
Dray Agha, senior manager of security operations at Huntress told Cybernews:
“Passkeys are highly resistant to phishing because they bind to a specific piece of hardware.
“A poorly designed recovery process could allow an attacker to bypass this protection by exploiting weaker backup methods like email or SMS verification.
He advised government departments to ensure their account recovery procedures were “just as rigorous as the passkeys themselves.”