Decoding the world of cybersecurity

· ·

GOV.UK passkeys reach 23 million users

GOV.UK One Login is extending passkeys to more than 23 million users, moving a major government identity service away from password-dependent authentication.

GOV.UK passkeys reach 23 million users
Summary
  • More than 23 million GOV.UK One Login users are being offered optional passkey authentication.
  • More than 300,000 users adopted passkeys during the trial, and nearly one in ten daily sign-ins now uses them.
  • The rollout moves phishing-resistant authentication into national-scale public-sector identity infrastructure.

Britain is extending passkey authentication across one of its largest public digital-identity systems, giving more than 23 million GOV.UK One Login users the option to sign in without entering a password.

GOV.UK One Login is making passkeys broadly available after an initial trial in which more than 300,000 users switched to the technology. Nearly one in ten daily One Login sign-ins is already completed using a passkey.

Passkeys use cryptographic credentials associated with a device or credential provider instead of a reusable shared secret. Users authenticate using a mechanism such as a device PIN, fingerprint, or facial recognition, while the biometric or PIN information used to unlock the credential remains on the device.

The National Cyber Security Centre recommends passkeys as a phishing-resistant alternative to passwords. Because the credential is tied to the legitimate service, a user cannot simply type it into a convincing phishing page in the way they can surrender a password or one-time verification code.

The model removes several weaknesses that have sustained account compromise for decades. There is no reusable password to share between services and no equivalent login secret for a phishing site to capture and replay.

That does not remove identity risk. Recovery processes become particularly important once stronger authentication is deployed because attackers can shift towards weaker routes for regaining account access. Device compromise, session theft, malicious software, and weaknesses elsewhere in the identity lifecycle also remain relevant.

For government services, the scale of the migration is significant. One Login provides a common authentication layer across a growing range of services, including State Pension checks, tax services, and childcare support. Improvements to that identity layer can therefore remove the same class of weakness across several public services at once.

The rollout also has an operational dimension. The government says passkey logins can be up to eight times faster than signing in with a username, password, and two-step verification code. Existing passkey use is also saving almost £600 a day in SMS costs.

Adoption will remain gradual because passkeys are optional. Users can continue signing in with passwords, meaning One Login must operate different authentication routes during the transition.

That makes the security of fallback and recovery mechanisms important. A service is not protected solely by its strongest available authentication option if an attacker can reach the same account through a weaker route.

The deployment nevertheless brings phishing-resistant authentication into public-sector infrastructure at national scale. Password elimination has spent years moving through consumer platforms and enterprise identity systems; One Login now provides a large test of how effectively the same model works across citizens using government services on a wide range of devices.

×