Govt databases tend to have a poor history on security, with hacking, employees trading or downloading data etc. But the One Login system rolled out recently to anyone at Companies House registered as a director/person with control. plus extension to Landlords and Self-Employed, might buck the trend. Here’s some comment from Yubico;
Following today’s announcement that passkeys are being rolled out to more than 23 million GOV.UK One Login users*, the UK Government is accelerating the shift towards simpler, more secure authentication for public services. The move marks a major milestone in modernising cybersecurity for the general public. As threat actors use increasingly sophisticated social engineering and AI-driven tactics to target account credentials, the transition to phishing-resistant authentication provides greater long-term security and resilience for organisations and consumers alike.
Passkeys also deliver tangible time and cost savings: passkey logins are up to eight times faster than signing in with a username, password and two-step verification code, while nearly one in 10 daily GOV.UK sign-ins are now made using passkeys – helping to save nearly £600 a day in SMS costs.
Nic Sarginson, principal product manager at Yubico, discusses the Government’s transition and why the shift to passkeys is essential for modern security:
“We are currently witnessing a global transition where both enterprises and users are moving away from passwords towards stronger, more resilient authentication technologies. The Government’s passkey rollout across its digital services comes at a critical time as organised crime groups are increasingly turning to AI to supercharge their scams, enabling highly sophisticated and convincing forms of fraud.
“With 81 percent of hacking-related breaches stemming from weak or reused passwords, it is clear that passwords are an out-of-date and fundamentally flawed method of security designed for an Internet not prepared for the cyber attacks of today. The UK Government’s endorsement of passkeys – citing them as the recommended method for enhanced security** – helps cement their place in providing the future of secure authentication.
“Physical passkeys are rapidly emerging as the new standard for secure authentication. In its most secure form, a passkey is device-bound – meaning it is stored on a local device like a physical hardware security key instead of on a remote server like passwords. These cryptographic keys are bound to the device and pair a public key with an unguessable private key which is never shared, meaning remote attackers are unable to intercept them.
Rather than depending on something a user has to remember – which can easily be forgotten, stolen or phished – a passkey relies on something they have (the physical key), something they know (a PIN), and something that proves the identity of the user who is supposed to gain access (a physical touch of the key). Crucially, if a user is tricked into clicking a link and lands on a fraudulent website, the passkey simply won’t authenticate the login attempt, stopping the attacker in their tracks.”
**https://www.ncsc.gov.uk/news/government-adopt-passkey-technology-digital-services

Be the first to comment