UK Cyber Agency Urges Brits to Abandon Passwords for Passkeys

CryptoFrontier

The UK’s National Cyber Security Centre (NCSC), part of intelligence agency GCHQ, has advised the nation to stop relying on passwords and instead adopt passkeys such as face recognition or fingerprints, according to the agency’s statement on April 23, 2026. The shift is driven by hackers’ increasing success in breaking into accounts protected by traditional password combinations. Jonathon Ellison, director for national resilience at the NCSC, described the move as “overhauling decades of practice.”

NCSC Recommendation and Rationale

The NCSC stated that passwords “no longer need to be a part of logging in” where users migrate to passkeys, which the agency characterizes as “a user-friendly alternative which provide stronger overall resilience.” Ellison said: “As we aim to accelerate the UK’s cyber defences at scale, moving to passkeys is something all of us can do to improve the security of everyday digital services and be prepared for modern and future cyber threats.”

We're being warned to move away from passwords We’re being warned to move away from passwords (Image: Getty Images/iStockphoto)

UK Passkey Adoption Leadership

According to the NCSC, the UK is already the leading country for passkey adoption. Just over half of Google’s active users in the UK are registered with a passkey.

Expert Perspective on Security Advantages

Chris Hosking, from cybersecurity company SentinelOne, emphasized that passkeys transfer “the onus for security away from people.” He noted that managing dozens of strong, unique passwords across work and personal accounts is unrealistic, leading users to reuse passwords or retain the same ones for years. Hosking explained: “That’s why so many major breaches start the same way - a popular service with authenticated users gets breached, those passwords and emails land in data dumps on the dark web, triggering a domino effect that compromises multiple sites and systems.”

Passkeys like facial recognition could help stop hackers Passkeys like facial recognition could help stop hackers (Image: Getty Images)

According to Hosking, “Passkeys remove entire classes of attacks, as there’s no password to steal or reuse.”

Disclaimer: The information on this page may come from third parties and does not represent the views or opinions of Gate. The content displayed on this page is for reference only and does not constitute any financial, investment, or legal advice. Gate does not guarantee the accuracy or completeness of the information and shall not be liable for any losses arising from the use of this information. Virtual asset investments carry high risks and are subject to significant price volatility. You may lose all of your invested principal. Please fully understand the relevant risks and make prudent decisions based on your own financial situation and risk tolerance. For details, please refer to Disclaimer.
Comment
0/400
NotificationSoundInMistyValleyvip
· 5h ago
Once all platforms support FIDO2, combined with hardware security modules, overall security will be elevated to a new level.
View OriginalReply0
OnchainComplainervip
· 5h ago
I'm more worried that "default facial login" will become a new surveillance entry point; safety and privacy need to be balanced.
View OriginalReply0
CyberBridgeDeepPerspectivevip
· 5h ago
Is the era of passwords really coming to an end?
View OriginalReply0
PurpleMistLilyvip
· 5h ago
What if the device is lost? If the recovery mechanism reverts to SMS/email, wouldn't that be a circular route?
View OriginalReply0
AuroraStonevip
· 5h ago
Don't use a one-size-fits-all approach; critical systems should at least incorporate multi-factor authentication plus hardware keys, relying on facial recognition alone may not be reliable enough.
View OriginalReply0
GateUser-06596f3bvip
· 5h ago
What about elderly people and low-end device users? Practical issues like dissemination costs and compatibility are significant.
View OriginalReply0
BluePeonyInTheDarkvip
· 5h ago
Actually, many hackers make a living through social engineering and phishing, but passkeys cut off a large part of that route directly.
View OriginalReply0
GateUser-af0710bavip
· 5h ago
From a Web3 perspective, it's quite interesting: private key = you keep it yourself, passkey = hardware-bound, providing a experience more like a smart account.
View OriginalReply0