UK.gov begins killing off passwords for 23 million users
UK government rolls out passkeys to 23 million GOV.UK One Login users, saving £600 daily in SMS costs and resisting phishing.
The UK government is expanding passkey sign-in across GOV.UK One Login for more than 23 million users after a trial with over 300,000 people. Nearly one in ten daily One Login sign-ins already use passkeys, which the government says are up to eight times faster than password plus 2FA code. The switch saves taxpayers nearly £600 per day in SMS costs, and the NCSC is encouraging adoption while passwords remain optional.
- Passkeys rolling out to 23 million GOV.UK One Login users after 300,000-user trial
- Almost 10% of daily sign-ins already use passkeys; up to eight times faster
- Saves taxpayers nearly £600 per day in SMS authentication costs
- NCSC promotes passkeys as phishing-resistant; passwords remain optional
Full article462 words · extracted from theregister.com · click to collapse
Security
Passkeys promise fewer phishing headaches – and £600 a day off Whitehall's SMS bill
The UK government is giving more than 23 million people the chance to ditch passwords for passkeys – and could save itself a tidy sum on authentication texts in the process.
Passkeys are being rolled out more widely across GOV.UK One Login following a trial involving more than 300,000 users, allowing people to sign in using a fingerprint, Face ID or device PIN instead of entering a password and waiting for a two-factor authentication code.
The government says nearly one in 10 daily One Login sign-ins are already being made using passkeys, which it claims are up to eight times faster than logging in with a username, password and 2FA code.
REG AD
There is also a less glamorous incentive for Whitehall: text messages cost money. The switch is already saving taxpayers nearly £600 a day in SMS costs, according to the government.
REG AD
More importantly, passkeys are designed to make life considerably harder for phishers. Rather than relying on a password that can be stolen, reused or handed over to a convincing fake login page, a passkey uses cryptographic credentials tied to the website or app for which it was created.
The fingerprint, face scan or PIN used to unlock it remains on the user's device and isn't seen or stored by GOV.UK One Login.
"Cyber criminals often look for the easiest route to access important accounts, which means login details remain a common target," said Jonathon Ellison, director for national resilience at the UK's National Cyber Security Centre. "But passkeys offer a highly phishing-resistant alternative to passwords, frustrating attackers and saving the public time."
The NCSC is encouraging users to switch, although passwords aren't disappearing just yet. Passkeys remain optional, and anyone who would rather continue signing in the old-fashioned way can do so.
GOV.UK One Login is intended to provide a single account for accessing government services rather than requiring users to navigate a collection of separate sign-in systems. It is already used for services including checking State Pension details, managing tax services and accessing childcare support.
Digital Government Minister Stephanie Peacock said the rollout was intended to make government services both easier to access and harder for fraudsters to exploit.
"Nobody enjoys hunting for a forgotten password or waiting for a text message code just to check their tax return or renew a document," she said.
Whether Britain's 23 million One Login users share Whitehall's enthusiasm for replacing passwords is unclear. But with passkeys already accounting for almost 10 percent of daily logins – and every authentication text adding to the government's phone bill – there are at least a couple of reasons to keep nudging them in that direction. ®
Text extracted automatically; images, tables and formatting may be missing. Original: https://www.theregister.com/security/2026/09/14/ukgov-begins-killing-off-passwords-for-23-million-users/5296088