Tech Industry Pushes to Replace Passwords with FIDO2 Passkeys Amid Rising Security Breaches

Close-up of a young woman’s face with an overlaid glowing red grid pattern, illustrating facial recognition or facial mapping technology used for biometric identification or analysis.

The technology industry is making a concerted push to replace traditional passwords with passkeys, a modern authentication method that leverages cryptographic credentials based on the FIDO2 standard. The transition comes in response to fundamental security limitations of passwords, including their vulnerability to leaks, reuse across services, and susceptibility to interception. The movement has gained significant momentum, with passkey adoption increasing by 550 percent in 2024.

Passkeys represent a significant advancement in authentication technology, storing credentials securely on users’ devices and protecting them through biometric verification or device PINs. The system uses public-key cryptography rather than shared secrets, making passkeys resistant to common attack vectors like phishing and credential stuffing. Major platforms have implemented synchronization capabilities through services like iCloud Keychain and Google Password Manager to enable seamless cross-device access. Google is currently developing enhanced passkey transfer capabilities to further improve the user experience.

Recent data indicates that 2.8 million passwords were compromised in 2024, with more than 50 percent of ransomware incidents directly linked to password breaches. Passkeys address these vulnerabilities by protecting the entire authentication lifecycle, from initial account creation through password resets and support interactions. The situation has led major providers like Google to urge its 2.5 billion Gmail users to transition to passkeys.

“With passkeys, you don’t have to remember anything, the authentication is cryptographically tied to you and protected by your device and biometrics,” said LastPass’s CEO. “Once you get the flow right, it allows the user to never have to remember a password.” The company has recently launched passkey support for Chrome desktop users, demonstrating its commitment to passwordless authentication.

Industry analyst firm Gartner has recommended organizations transition from legacy authentication methods to phishing-resistant multi-factor authentication solutions, specifically highlighting FIDO-based passkeys. The implementation landscape includes both device-bound passkeys for high-security enterprise environments and synced passkeys for consumer-facing applications. Yubico has advocated for device-bound passkeys in enterprise settings, citing enhanced security benefits.

The adoption of passkeys is occurring alongside broader changes in enterprise security. Organizations are addressing challenges related to shadow IT and shadow AI through new monitoring tools. Companies like 1Password are developing tools to assess user readiness for passkey adoption while integrating passkeys into comprehensive security platforms that incorporate AI-driven productivity features.

Bitwarden is spearheading efforts to standardize passkey portability across platforms, with developments such as iOS 26 enabling secure transfer of authentication credentials. Hardware security modules and mobile authenticator applications are being deployed to provide strong passwordless security in specific operational contexts. Microsoft has announced plans to remove password storage from its Authenticator app by August 2025, focusing exclusively on passkeys, biometrics, and PINs.

Sources: Security Brief, Thales, Authsignal, RSA, 1Password, Business Wire