ZeroHour
GBHackerspublished ()ingested Divya

UK Government Enables Passkey Login for 23 Million Users to Fight Phishing Attacks

infoPolicy & legalimportance 28
AI summary · glm-5.3

UK Government enables optional passkey login for GOV.UK One Login, offering 23 million users phishing-resistant FIDO authentication.

The UK government has rolled out passkey authentication for GOV.UK One Login, the single sign-on for services like tax, State Pension, and driver's license renewals, available to over 23 million users. Passkeys are device-bound, unlocked via fingerprint, Face ID, or device PIN, and the government reports they are up to eight times faster than password plus two-step verification. During the initial trial over 300,000 users adopted passkeys, with nearly one in ten daily sign-ins already using them, saving roughly £600 per day in SMS costs. The NCSC endorses passkeys as phishing-resistant credentials that cannot be intercepted or reused, and biometric data never leaves the user's device.

  • 23 million GOV.UK One Login users can opt into device-bound passkeys
  • Over 300,000 adopted passkeys in trial; ~1 in 10 daily sign-ins already use them
  • Government reports passkeys are up to 8x faster and save ~£600/day in SMS costs
  • NCSC endorses passkeys as phishing-resistant; biometrics stay on user devices
Full article560 words · extracted from gbhackers.com · click to collapse

The UK government has started implementing passkey authentication for GOV. UK One Login,UK One Login, providing over 23 million users with a faster and more secure way to access public services.

This initiative aims to reduce reliance on passwords and SMS-based verification codes, which are common targets for fraud and credential theft.

UK Enables Passkey Login

GOV.UK One Login is a single sign-in solution for a variety of government services, such as childcare support, tax management, State Pension checks, and driver’s license renewals.

Users who opt in can authenticate using a device-bound passkey, unlocked through existing local security measures like fingerprints, Face ID, or a device PIN.

Unlike traditional password-based sign-in processes, passkeys eliminate the need for users to remember, type, reuse, or reset passwords.

The government reports that passkey authentication can be up to eight times faster than using a username, password, and two-step verification code. This technology also reduces delays and operational costs associated with sending SMS one-time passcodes.

During the initial trial, over 300,000 users of GOV.UK One Login adopted passkeys. The government indicated that nearly one in ten daily sign-ins already uses passkeys, saving taxpayers nearly £600 per day in SMS costs.

Passkeys offer security benefits because of their cryptographic, device-bound design. Each passkey links to a specific website or application and cannot be copied, guessed, or reused across services. During authentication, the user’s device verifies it is communicating with the legitimate service before allowing the login.

This design directly combats common phishing attacks. In traditional credential-harvesting scenarios, victims may inadvertently enter their password on a fake login page, allowing attackers to reuse it.

Passkeys do not expose reusable passwords to websites, significantly diminishing the effectiveness of cloned login portals and deceptive phishing emails.

The biometric data used to unlock a passkey is stored only on the user’s device. GOV.UK One Login does not receive or store users’ fingerprints or facial-recognition data. Instead, the biometric check or PIN acts as a local authorization method for using the passkey stored on the device.

Digital Government Minister Stephanie Peacock said the rollout would simplify access to essential government services while strengthening protection against password-related fraud. She emphasized that users can log in with the same fingerprint or facial scan they use to unlock their phones.

The National Cyber Security Center (NCSC) has endorsed passkeys as a more secure alternative to passwords. The NCSC emphasizes that passkeys cannot be intercepted, stolen, or reused like traditional credentials.

Jonathon Ellison, NCSC Director for National Resilience, noted that this deployment would give the public a faster, more secure way to access government services, reducing “password headaches.”

For security professionals, this rollout exemplifies a broader trend toward phishing-resistant authentication based on FIDO-style public-key cryptography.

Such advancements can minimize an organization’s vulnerability to credential theft, password spraying, reused passwords, phishing attacks, and SMS interception risks.

Passkeys remain optional for GOV.UK One Login users, allowing individuals to continue using passwords if they prefer. However, the government and NCSC are encouraging users to enable passkeys where available, promoting this technology as a valuable security enhancement for public-sector digital identity services.

Keep your SOC up to date on active malware & phishing within 24h of their emergence. Try ANYRUN to prevent incidents with early detection

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Text extracted automatically; images, tables and formatting may be missing. Original: https://gbhackers.com/uk-government-enables-passkey-login-for-23-million-users/