Tech companies adopt passkey features for convenience, safety

2024. 8. 21. 10:48
글자크기 설정 파란원을 좌우로 움직이시면 글자크기가 변경 됩니다.

이 글자크기로 변경됩니다.

(예시) 가장 빠른 뉴스가 있고 다양한 정보, 쌍방향 소통이 숨쉬는 다음뉴스를 만나보세요. 다음뉴스는 국내외 주요이슈와 실시간 속보, 문화생활 및 다양한 분야의 뉴스를 입체적으로 전달하고 있습니다.

[Graphics by Kim Eo-jin]
Passkeys, an alternative to passwords that allow users to log in via biometric authentication such as fingerprints, facial recognition, or PINs, are gaining attention globally.

They have been adopted by major services like Google LLC, Microsoft Corp., Samsung Electronics Co., and Apple Inc., and are now used on platforms such as X, formerly Twitter. The trend points to an increasing number of services that make logging in convenient without needing to remember complex passwords.

According to sources from the information technology (IT) industry on Tuesday, X started supporting passkeys for iOS users in April 2024 and has expanded this to Android users since last week. The passkey method is a new digital identity verification standard established by the FIDO Alliance, an international standards organization in online authentication. The core of this method is using a passkey stored on the user’s device for login via biometric verification instead of using a password.

To create a passkey, users need to access the account management menu of a service that supports passkeys, such as Google. In the security menu under account management, selecting the passkey option activates the passkey after a one-time password verification. Users can then log in using biometric authentication or a PIN instead of a password. Galaxy smartphone users can store and manage the passkey in the Samsung Pass application, while iPhone users store theirs in iCloud Keychain.

In South Korea, KT Corp. is working on implementing passkey-based biometric authentication in its My KT app and has applied a similar biometric login method in its PASS app. LG Uplus Corp. is also considering adopting passkeys, while SK telecom Co. previously implemented the passkey authentication system in its PASS app in March 2023. Samsung Electronics began applying passkeys to its digital authentication service, Samsung Pass, starting in 2023.

Passkeys work by generating a pair of cryptographic keys instead of a traditional password. The public key is stored on the service’s server while the private key remains on the user’s device, and the server’s key is compared with the key on the user’s device to verify identity during login. The advantage of using passkeys is that users can log in using facial recognition, fingerprint recognition, or a PIN, making it possible to access accounts even if they forget their passwords.

According to a survey by the FIDO Alliance, which established the passkey standard, users around the world abandoned service logins nearly four times a month due to forgotten passwords. Passkeys offer improved security. Accounts can be easily stolen If a company’s server is hacked, and account IDs and passwords are leaked, when using passwords. But for passkeys, only the public key is exposed while the private key, which is necessary to decode it, remains on the user’s device even if the server is hacked, making it relatively safer.

Passkey adoption has been rapidly increasing among major companies since 2022. Dashlane, which provides password management solutions, said that the number of passkey-based authentications worldwide increased by about 400 percent from the beginning of 2024 to July.

While passkeys are not completely immune to security threats, adhering to basic security practices is crucial, according to experts.

“Users should download apps from official app stores and keep their device’s operating system and apps updated to the latest versions,” Park Tae-hwan, who heads AhnLab’s Cyber Security Center, said.

Copyright © 매일경제 & mk.co.kr. 무단 전재, 재배포 및 AI학습 이용 금지

이 기사에 대해 어떻게 생각하시나요?