Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Google and Microsoft warn passkeys alone are not enough

Both companies said accounts are only as secure as their weakest credential.

byAytun Çelebi
May 11, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Passkeys are designed to replace passwords and combat phishing attacks, but Google and Microsoft caution that they are insufficient if weaker recovery methods remain in use. “Each account is only as secure as its weakest credential,” Microsoft stated, noting that passwords and SMS recovery can create new vulnerabilities even after passkeys are deployed.

Google acknowledged that “passkeys are an easier and safer way to access online accounts compared to passwords and even traditional multi-factor methods,” but stressed that they are not entirely safe on their own. The company warned users that “even when you normally use a passkey, it’s important to secure your account with two-step verification (2SV).” This added layer of security is essential, particularly if someone attempts to impersonate the user and claims to have lost their passkey.

Automated recovery processes that exploit weaker credentials can bypass a passkey, making it essential to secure accounts further. Microsoft flagged account recovery as a new attack surface as passkey adoption increases and traditional attack methods decline. “Deploying passkeys improves sign-in,” Microsoft noted, “but most accounts still have a password or SMS method attached ‘just in case’ — and as long as those credentials exist, they’re an attack surface.”

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The recommended recovery method involves using the account’s passkey on a different device to complete any recovery steps. Microsoft also suggested high-assurance recovery methods that require government-issued ID and biometric verification, such as a face scan, saying, “As NIST recommends, high-assurance recovery requires government-issued ID and biometric verification.”

This guidance primarily targets enterprise users for Microsoft and home users for Google. Despite the different audience, both companies recognize the threats that persist. Google highlighted that high-value accounts like Gmail are under constant attack, urging users to implement 2SV to enhance security. Users should also select effective forms of 2SV, such as Google Prompts and an Authenticator app, while abandoning SMS one-time codes, which are regarded as weaker methods.

As passkey adoption accelerates, Microsoft reiterated that the protections will only work if users eliminate all phishable credentials. Google’s warning about the limitations of passkeys is particularly relevant as attackers begin focusing on recovery flows and fallback authentication methods. The ongoing evolution of threats necessitates a comprehensive security strategy that includes robust recovery methods beyond just implementing passkeys.


Featured image credit

Tags: FeaturedGoogleMicrosoft

Related Posts

Steam Next Fest sees one in five demos labeled for generative AI

Steam Next Fest sees one in five demos labeled for generative AI

June 17, 2026
Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

June 17, 2026
Roblox expands age-based account tiers worldwide with new parental controls

Roblox expands age-based account tiers worldwide with new parental controls

June 17, 2026
Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

June 17, 2026
Is Gemini down? Users report problems with Google Gemini

Is Gemini down? Users report problems with Google Gemini

June 17, 2026
Google releases Android 17

Google releases Android 17

June 17, 2026

LATEST NEWS

Steam Next Fest sees one in five demos labeled for generative AI

Qualcomm debuts Snapdragon Reality Elite chip for AR and VR devices

Roblox expands age-based account tiers worldwide with new parental controls

Anthropic adds multilingual and push-to-talk features to Claude Voice Mode

Is Gemini down? Users report problems with Google Gemini

Google releases Android 17

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Wiz Write

BoldVoice

Bith

Concisely

YourGPT

Sonoteller

RoomGPT

Rosie

LedgerUp

Call Annie

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.