Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
  • AI
  • Tech
  • Cybersecurity
  • Finance
  • DeFi & Blockchain
  • Startups
  • Gaming
Dataconomy
  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI toolsNEW
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
Subscribe
No Result
View All Result
Dataconomy
No Result
View All Result

Google and Microsoft warn passkeys alone are not enough

Both companies said accounts are only as secure as their weakest credential.

byAytun Çelebi
May 11, 2026
in Cybersecurity, News
Home News Cybersecurity
Share on FacebookShare on TwitterShare on LinkedInShare on WhatsAppShare on e-mail
Google Preferred Source

Passkeys are designed to replace passwords and combat phishing attacks, but Google and Microsoft caution that they are insufficient if weaker recovery methods remain in use. “Each account is only as secure as its weakest credential,” Microsoft stated, noting that passwords and SMS recovery can create new vulnerabilities even after passkeys are deployed.

Google acknowledged that “passkeys are an easier and safer way to access online accounts compared to passwords and even traditional multi-factor methods,” but stressed that they are not entirely safe on their own. The company warned users that “even when you normally use a passkey, it’s important to secure your account with two-step verification (2SV).” This added layer of security is essential, particularly if someone attempts to impersonate the user and claims to have lost their passkey.

Automated recovery processes that exploit weaker credentials can bypass a passkey, making it essential to secure accounts further. Microsoft flagged account recovery as a new attack surface as passkey adoption increases and traditional attack methods decline. “Deploying passkeys improves sign-in,” Microsoft noted, “but most accounts still have a password or SMS method attached ‘just in case’ — and as long as those credentials exist, they’re an attack surface.”

Stay Ahead of the Curve!

Don't miss out on the latest insights, trends, and analysis in the world of data, technology, and startups. Subscribe to our newsletter and get exclusive content delivered straight to your inbox.

The recommended recovery method involves using the account’s passkey on a different device to complete any recovery steps. Microsoft also suggested high-assurance recovery methods that require government-issued ID and biometric verification, such as a face scan, saying, “As NIST recommends, high-assurance recovery requires government-issued ID and biometric verification.”

This guidance primarily targets enterprise users for Microsoft and home users for Google. Despite the different audience, both companies recognize the threats that persist. Google highlighted that high-value accounts like Gmail are under constant attack, urging users to implement 2SV to enhance security. Users should also select effective forms of 2SV, such as Google Prompts and an Authenticator app, while abandoning SMS one-time codes, which are regarded as weaker methods.

As passkey adoption accelerates, Microsoft reiterated that the protections will only work if users eliminate all phishable credentials. Google’s warning about the limitations of passkeys is particularly relevant as attackers begin focusing on recovery flows and fallback authentication methods. The ongoing evolution of threats necessitates a comprehensive security strategy that includes robust recovery methods beyond just implementing passkeys.


Featured image credit

Tags: FeaturedGoogleMicrosoft

Related Posts

OpenAI improves health responses for free ChatGPT users

OpenAI improves health responses for free ChatGPT users

June 19, 2026
Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

June 19, 2026
Spotify launches Reserved to give superfans early ticket access

Spotify launches Reserved to give superfans early ticket access

June 19, 2026
Google discontinues Nest Home Mini and Nest Audio

Google discontinues Nest Home Mini and Nest Audio

June 19, 2026
Instagram adds unique captions for each carousel slide

Instagram adds unique captions for each carousel slide

June 19, 2026
Steam Next Fest sees one in five demos labeled for generative AI

Steam Next Fest sees one in five demos labeled for generative AI

June 17, 2026

LATEST NEWS

OpenAI improves health responses for free ChatGPT users

Adobe expands Firefly AI across Premiere, Illustrator, InDesign and Frame.io

Spotify launches Reserved to give superfans early ticket access

Google discontinues Nest Home Mini and Nest Audio

Instagram adds unique captions for each carousel slide

Steam Next Fest sees one in five demos labeled for generative AI

BEST AI MODELS LEADERBOARD

See the best AI models, ranked by intelligence, benchmark results, speed and token price. Find the most suitable LLMs, Text-to-Image, Image Editing, Text-to-Speech, Text-to-Video and Image-to-Video  artificial intelligence model for your tasks and business.

LATEST TOOLS

Novoresume

PolyAI

SeaArt

H2O.ai

Techpresso

Namecheap Free Logo Maker

Binaural Beats Factory

Lyricallabs

Jobscan

Vsub

Dataconomy

COPYRIGHT © DATACONOMY MEDIA GMBH, ALL RIGHTS RESERVED.

  • About
  • Imprint
  • Contact
  • Legal & Privacy

Follow Us

  • News
    • Artificial Intelligence
    • Cybersecurity
    • DeFi & Blockchain
    • Finance
    • Gaming
    • Startups
    • Tech
  • Industry
  • Research
  • Resources
    • Articles
    • Guides
    • Case Studies
    • Whitepapers
    • AI Models Leaderboard
  • AI tools
  • Newsletter
  • + More
    • Glossary
    • Conversations
    • Events
    • About
      • Who we are
      • Contact
      • Imprint
      • Legal & Privacy
      • Partner With Us
No Result
View All Result
Subscribe

This website uses cookies to improve your experience. You can choose to accept or reject them. Visit our Privacy Policy.