ESPN DeportesCR7 pide suspender a fans por burlas a Diogo JotaRTP DesportoEuroVolley 2026. Portugal soma quarta derrota consecutiva frente à UcrâniaESPN'I'm willing to do whatever it takes': Inside the 274 days that rebuilt Patrick MahomesThe Jerusalem PostUS President Donald Trump shares his music taste with reporters in odd exchange on Air Force OnePunchNASEMA distributes relief materials to disaster, banditry victimsInquirerSenate approves on 3rd reading 5-year term of barangay, SK officials3DNewsИлон Маск помирился с Apple — но X Corp и SpaceXAI продолжат судиться с OpenAIBusiness AMDenemarken en VS streven naar diplomatieke oplossing voor geschil over GroenlandRapplerLIVE UPDATES: First BARMM parliamentary electionsAntara NewsChinese hiker injured on Indonesia's Mount Rinjani, SAR team deployedBillboardMacklemore Dropped From Ed Sheeran Tour Over His ‘Free Palestine’ CommentsCNN بالعربية"لكن أنا الذي أستحقها".. لامين يامال يسمّى منافسه الوحيد في سباق الكرة الذهبية 2026
The Daily Newsstand · Free, Always
Monday, September 14, 2026

UK.gov begins killing off passwords for 23 million users

Translate

Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill

The UK government is giving more than 23 million people the chance to ditch passwords for passkeys – and could save itself a tidy sum on authentication texts in the process.

Passkeys are being rolled out more widely across GOV.UK One Login following a trial involving more than 300,000 users, allowing people to sign in using a fingerprint, Face ID, or device PIN instead of entering a password and waiting for a two-factor authentication (2FA) code.

The government says nearly one in ten daily One Login sign-ins are already being made using passkeys, which it claims are up to eight times faster than logging in with a username, password and 2FA code.

REG AD

There is also a less glamorous incentive for Whitehall: text messages cost money. The switch is already saving taxpayers nearly £600 a day in SMS costs, according to the government.

REG AD

Passkeys are designed to resist phishing. Rather than relying on a password that can be stolen, reused, or handed over to a convincing fake login page, a passkey uses cryptographic credentials tied to the website or app for which it was created.

The biometric data or PIN used to unlock it remains on the user's device and isn't seen or stored by GOV.UK One Login.

"Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre (NCSC). "But passkeys offer a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time."

The NCSC is encouraging users to switch, although passwords aren't disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so.

GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems. It is already used for services including checking State Pension details, managing tax services, and accessing childcare support.

Digital Government Minister Stephanie Peacock said the rollout was intended to make government services both easier to access and harder for fraudsters to exploit.

"Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said.

Whether Britain's 23 million One Login users share Whitehall's enthusiasm for replacing passwords is unclear. But with passkeys already accounting for almost 10 percent of daily logins – and every authentication text adding to the government's phone bill – there are at least a couple of reasons to keep nudging them in that direction. ®

View the original on The Register

KioskNews shows a cleaned-up reading view extracted from the publisher’s page — the original always lives on their site, not ours.