{"id":48165,"date":"2025-06-20T16:40:05","date_gmt":"2025-06-20T20:40:05","guid":{"rendered":"https:\/\/mjtsai.com\/blog\/?p=48165"},"modified":"2025-06-20T17:45:01","modified_gmt":"2025-06-20T21:45:01","slug":"forcing-passkeys","status":"publish","type":"post","link":"https:\/\/mjtsai.com\/blog\/2025\/06\/20\/forcing-passkeys\/","title":{"rendered":"Forcing Passkeys"},"content":{"rendered":"<p><a href=\"https:\/\/lapcatsoftware.com\/articles\/2025\/4\/9.html\">Jeff Johnson<\/a>:<\/p>\n<blockquote cite=\"https:\/\/lapcatsoftware.com\/articles\/2025\/4\/9.html\"><p>The new setting is enabled by default; I&rsquo;ve seen this on multiple computers.<\/p><blockquote>Automatically create a passkey to sign in faster\n<br><\/br>Allow sites and apps to upgrade existing accounts to use passkeys<\/blockquote><p>This new setting is not actually included on the What&rsquo;s New in Chrome page (<code>chrome:\/\/whats-new\/<\/code>), which doesn&rsquo;t even mention passkeys.<\/p><p>It is mentioned by the <a href=\"https:\/\/developer.chrome.com\/blog\/new-in-chrome-136\/\">New  in Chrome 136<\/a> post on the Chrome for developers blog:<\/p><blockquote>You can now upgrade existing password credentials to a passkey.<\/blockquote><p>&ldquo;You&rdquo; here apparently refers to web developers, not to users, who aren&rsquo;t given a choice[&#8230;]<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.theregister.com\/2025\/05\/04\/security_news_in_brief\/\">Brandon Vigliarolo<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.theregister.com\/2025\/05\/04\/security_news_in_brief\/\"><p>Microsoft has decided to push its consumer customers to dump passwords in favor of passkeys.<\/p><p>The software giant <a href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2025\/05\/01\/pushing-passkeys-forward-microsofts-latest-updates-for-simpler-safer-sign-ins\/\">announced<\/a> the move Thursday, May 1, traditionally known as &ldquo;World Password Day,&rdquo; with a declaration it had joined forces with the Fast Identity Online (FIDO) Alliance to re-name the pseudo-holiday &ldquo;World <a href=\"https:\/\/fidoalliance.org\/fido-alliance-champions-widespread-passkey-adoption-and-a-passwordless-future-on-world-passkey-day-2025\/\">Passkey<\/a> Day.&rdquo;<\/p><p>Redmond&rsquo;s not just playing with words as the Windows giant has also decided that all new Microsoft accounts will use passkeys by default.<\/p><p>[&#8230;]<\/p><p>As we noted late last year, Microsoft isn&rsquo;t giving its customers an option to continue using passwords, saying that opting out of passkey invitations <a href=\"https:\/\/www.theregister.com\/2024\/12\/18\/microsoft_passkey_push\/\">wasn&rsquo;t possible<\/a>.<\/p><\/blockquote>\n\n<p><a href=\"https:\/\/www.troyhunt.com\/passkeys-for-normal-people\/\">Troy Hunt<\/a>:<\/p>\n<blockquote cite=\"https:\/\/www.troyhunt.com\/passkeys-for-normal-people\/\">\n<p>This is a good point to reflect on the paradox that securing your digital life presents: as we seek stronger forms of authentication, we create different risks. Losing all your forms of non-phishable 2FA, for example, creates the risk of losing access to your account. But we also have mitigating controls: your digital passkey is managed totally independently of your physical one so the chances of losing both are extremely low. Plus, best practice is usually to have <em>two<\/em> U2F keys and enrol them both (I always take one with me when I travel, and leave another one at home). New levels of security, new risks, new mitigations.<\/p>\n<\/blockquote>\n\n<p>Most people are not going to do this, so it seems like the end game is that either users will lose control of their logins or that passkeys will become mainly a convenience for quickly logging in, with passwords, SMS, and e-mail as a less secure fallback.<\/p>\n\n<p><a href=\"https:\/\/www.iinuwa.xyz\/blog\/linux-passkeys-update\/\">Isaiah Inuwa<\/a> (via <a href=\"https:\/\/hachyderm.io\/@rmondello\/114551093132479546\">Ricky Mondello<\/a>):<\/p>\n<blockquote cite=\"https:\/\/www.iinuwa.xyz\/blog\/linux-passkeys-update\/\">\n<p>With the announcements from big companies at World Password Day about passkeys, I thought I should share what I've been working on for passkey support on Linux.<\/p>\n<\/blockquote>\n\n<p>Previously:<\/p>\n<ul>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2025\/06\/20\/apple-previews-passkeys-credential-exchange\/\">Apple Previews Passkeys Credential Exchange<\/a><\/li>\n<li><a href=\"https:\/\/mjtsai.com\/blog\/2023\/05\/08\/passkeys-a-loss-of-user-control\/\">Passkeys: A Loss of User Control?<\/a><\/li>\n<\/ul>","protected":false},"excerpt":{"rendered":"<p>Jeff Johnson: The new setting is enabled by default; I&rsquo;ve seen this on multiple computers.Automatically create a passkey to sign in faster Allow sites and apps to upgrade existing accounts to use passkeysThis new setting is not actually included on the What&rsquo;s New in Chrome page (chrome:\/\/whats-new\/), which doesn&rsquo;t even mention passkeys.It is mentioned by [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"apple_news_api_created_at":"2025-06-20T20:40:07Z","apple_news_api_id":"243d85b4-2021-417e-83cd-c63f513a7cd5","apple_news_api_modified_at":"2025-06-20T20:40:29Z","apple_news_api_revision":"AAAAAAAAAAAAAAAAAAAAAA==","apple_news_api_share_url":"https:\/\/apple.news\/AJD2FtCAhQX6DzcY_UTp81Q","apple_news_coverimage":0,"apple_news_coverimage_caption":"","apple_news_is_hidden":false,"apple_news_is_paid":false,"apple_news_is_preview":false,"apple_news_is_sponsored":false,"apple_news_maturity_rating":"","apple_news_metadata":"\"\"","apple_news_pullquote":"","apple_news_pullquote_position":"","apple_news_slug":"","apple_news_sections":"\"\"","apple_news_suppress_video_url":false,"apple_news_use_image_component":false,"footnotes":""},"categories":[2],"tags":[284,456,448,37,103,2246,2090,96],"class_list":["post-48165","post","type-post","status-publish","format-standard","hentry","category-technology","tag-1password","tag-googlechrome","tag-linux","tag-microsoft","tag-safari","tag-safari-extensions","tag-two-factor-authentication-2fa","tag-web"],"apple_news_notices":[],"_links":{"self":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48165","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/comments?post=48165"}],"version-history":[{"count":2,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48165\/revisions"}],"predecessor-version":[{"id":48169,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/posts\/48165\/revisions\/48169"}],"wp:attachment":[{"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/media?parent=48165"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/categories?post=48165"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/mjtsai.com\/blog\/wp-json\/wp\/v2\/tags?post=48165"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}