The UK’s National Cyber Security Centre has called time on the password – from now on, you should use a passkey. The NCSC said this week it would no longer recommend using passwords where passkeys were available. They should be consumers’ first choice of login across all digital services because passwords were not secure enough to stand up to modern cyber threats. What is a passkey? Security officials describe a passkey as a “digital stamp” that allows you to sign in to apps and websites and is stored on your device. It is a password-free form of login. Unlike a password, it cannot be stolen in a phishing attack, where people are fooled into handing over their credentials, which can later appear on the dark web. It just requires your smartphone or device to confirm that it is you trying to log in, by using biometric methods such as facial recognition or your phone’s pin. That triggers the “stamp” – or secure passkey – which confirms to the app or website that you are who you say you are. Each account you are registered with will have a different passkey. Even if an app or website using passkeys is breached, it is of no use to an assailant because the device holds the “private” passkey needed to complete a login. Passkeys can also be synced across devices. How do you set up a passkey? The NCSC says you can go to account security or privacy settings on apps and websites you already use, or look out for prompts from services asking you to upgrade to passkeys. You may also be offered to set one up when creating a new account for an app or website. Google says just over 50% of users of its services in the UK have a