ZeroHour
Cyber Security Newspublished ()ingested Guru Baran

UK Government Begins Moving 23 Million Users Away From Passwords

infoPolicy & legalimportance 25
AI summary · glm-5.3

UK government rolls out passkeys for GOV.UK One Login, giving 23 million users phishing-resistant passwordless access to public services.

The UK government has begun deploying passkeys across GOV.UK One Login for more than 23 million users, replacing passwords and SMS one-time codes with FIDO2 cryptographic credentials. A trial saw over 300,000 people adopt passkeys, and nearly one in ten daily authentications already use them, cutting SMS verification costs by almost £600 per day. Passkeys remain optional, with password-based sign-in retained as a fallback, and the NCSC endorses the approach as phishing-resistant.

  • Passkeys offered to 23 million GOV.UK One Login users
  • Over 300,000 trial adopters; 1 in 10 daily logins already passkey-based
  • Saves almost £600 per day in SMS verification costs
  • FIDO2-based credentials resist credential phishing; passwords remain as fallback
Full article512 words · extracted from cybersecuritynews.com · click to collapse

The UK government has begun rolling out passkeys across GOV.UK One Login, offering more than 23 million users a passwordless way to access public services.

The deployment covers everything from childcare support and driving license renewals to State Pension checks and tax management, significantly changing how citizens authenticate to government systems.

Instead of entering a password and a one-time code sent by text message, users can sign in with the same fingerprint, facial recognition scan, device PIN or pattern used to unlock a phone, tablet or computer.

UK Government Passwordless

Officials say passkey authentication is up to eight times faster than the existing username, password and two-step verification process.

The rollout follows an initial trial in which more than 300,000 people successfully adopted passkeys, according to the official announcement published by GOV.UK.

Nearly one in ten daily GOV.UK One Login authentications are already completed this way, reducing SMS verification costs by almost £600 per day.

From a security perspective, passkeys address several weaknesses associated with password-based authentication. Built on the FIDO2 standard, they use cryptographic credentials linked to the legitimate website and managed by a trusted device or credential manager.

This design makes passkeys resistant to conventional credential-phishing attacks because users have no reusable password to disclose through a fraudulent login page.

The National Cyber Security Center says passkeys cannot be intercepted, reused, or stolen in the same manner as passwords and recommends choosing them wherever supported.

A fingerprint, facial template, or PIN is used locally to authorize the credential; GOV.UK One Login does not receive or store that biometric information.

A passkey may be synchronized through a device’s credential manager, while users can also authenticate on another device by scanning a QR code with a nearby device holding the passkey.

The change does not immediately abolish passwords. Passkeys remain optional, and users can continue signing in with a password and security code or use that route as a fallback if a passkey becomes unavailable.

GOV.UK also warns against setting one up on a shared device, since anyone who can unlock it could potentially use the stored credential.

Digital Government Minister Stephanie Peacock said the technology would let people reach essential services in seconds while strengthening protection against fraudsters targeting passwords.

NCSC Director for National Resilience Jonathon Ellison similarly described passkeys as a “highly phishing-resistant alternative,” urging citizens to enable them on GOV.UK One Login and other services supporting the technology.

For the government, the migration combines measurable operational savings with reduced authentication friction. For users, it removes password fatigue and dependence on SMS codes.

However, because password-based recovery remains available, overall account security will continue to depend partly on how securely those fallback mechanisms are implemented and protected as passkey adoption expands.

Learn 7 Metric-Gated AI SOC Deployment Phases – Download Free AI SOC Deployment Playbook 2026.

Guru Baranhttps://cybersecuritynews.com

Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.

Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/uk-government-passwordless/