New website names and shames companies that still don’t offer passkeys to users

New Website Shines a Light on Companies Yet to Embrace Passkeys

A new online platform has emerged with a clear mission: to openly identify and critique companies that have not yet integrated passkey authentication for their users. The website, whose creators remain anonymous, aims to accelerate the adoption of this advanced security feature by publicly listing major online services that still rely solely on traditional passwords, effectively naming and shaming those perceived as lagging in digital security innovation.

Passkeys represent a significant leap forward in online authentication, offering a phishing-resistant, more secure, and often more convenient alternative to passwords. Based on FIDO Alliance standards, passkeys allow users to log in to accounts using biometric verification like fingerprints or facial recognition, or a simple PIN on their devices, eliminating the need to remember complex passwords or contend with vulnerable two-factor authentication methods like SMS codes. Major tech players like Apple, Google, and Microsoft have been champions of passkeys, integrating them into their ecosystems and pushing for broader adoption across the web.

The new website meticulously compiles a list of prominent companies across various sectors, including banking, social media, e-commerce, and cloud services, explicitly stating whether they offer passkey support or not. Each entry serves as a direct report card, highlighting which organizations are prioritizing cutting-edge security for their customers and which are seemingly falling behind. The site's intention appears to be twofold: to empower users with information about their chosen services' security posture and to exert pressure on companies to upgrade their authentication protocols.

This public scrutiny comes at a time when cybersecurity threats are increasingly sophisticated. While some might view the "naming and shaming" tactic as aggressive, proponents argue it is a necessary measure to encourage enterprises to invest in better protection for user data. Companies that appear on the "no passkey" list may face reputational damage, potentially prompting users to reconsider their loyalty or even switch to services that offer superior security features. In today's competitive digital landscape, a company's commitment to security can be a significant differentiator.

However, adopting passkeys is not without its challenges for businesses. Integrating a new authentication standard requires significant development effort, infrastructure changes, and often a comprehensive rollout strategy to educate users. Legacy systems, complex existing user bases, and the cost associated with implementation can all be barriers, particularly for larger, older organizations. The website's creators, while not acknowledging these complexities directly, are betting that the threat of public criticism will outweigh these operational hurdles.

Ultimately, the launch of this new website underscores a growing industry expectation: passkeys are no longer a niche technology but a foundational element of modern, secure online interaction. While the method of public criticism might spark debate, its existence highlights the increasing demand for stronger, user-friendly security. It serves as a stark reminder to companies that in the ever-evolving world of cybersecurity, standing still is not an option, and users are becoming more informed and demanding about the protection of their digital lives.

Original reporting TechCrunch
Return to Homepage