Website shames major platforms for lacking passkey support

Understand the growing industry push for passwordless security and how it impacts user authentication standards.
30-Second TL;DR
What Changed
WhyNoPasskeys.com tracks passkey adoption status across major web services.
Why It Matters
Increased public pressure may accelerate the industry-wide shift toward FIDO-based authentication, reducing reliance on vulnerable password systems.
What To Do Next
Audit your own authentication flows and prioritize implementing WebAuthn/Passkeys to improve user security posture.
Key Points
- •WhyNoPasskeys.com tracks passkey adoption status across major web services.
- •Instagram, Netflix, and Spotify are highlighted as laggards in security implementation.
- •The project serves as a public accountability tool for modern authentication standards.
Deep Insight
AI-generated analysis for this event — not the original article.
Enhanced Key Takeaways
- •WhyNoPasskeys.com is an open-source project hosted on GitHub, allowing community contributions to track the implementation status of FIDO2/WebAuthn standards across various services.
- •The website categorizes platforms based on their support level, distinguishing between those with full passkey support, partial support (e.g., only for specific devices), and those with no support at all.
- •Security researchers behind the initiative argue that password-based authentication remains the primary vector for credential stuffing and phishing attacks, which passkeys effectively neutralize.
- •The project maintains a 'Hall of Shame' and a 'Hall of Fame' to gamify the adoption process and provide clear incentives for companies to prioritize security updates.
- •Many platforms cited as laggards often cite legacy infrastructure constraints or the complexity of cross-platform synchronization as primary barriers to rapid passkey deployment.
Technical Deep Dive
- Passkeys utilize public-key cryptography where the private key is stored on the user's device (e.g., Secure Enclave or TPM) and never leaves the hardware.
- The authentication process relies on the WebAuthn API, which facilitates the exchange between the browser/OS and the relying party (the website).
- Implementation requires the server to store a public key associated with the user account, which is then used to verify the digital signature provided by the user's device during login.
- Unlike traditional passwords, passkeys are resistant to server-side breaches because the server only holds the public key, which cannot be used to authenticate as the user.
Future ImplicationsAI analysis grounded in cited sources
Timeline
- 2022-06Apple, Google, and Microsoft announce a joint commitment to expand support for FIDO passwordless sign-in standards.
- 2023-05Google begins rolling out passkeys as the default sign-in option for personal Google Accounts.
- 2024-02WhyNoPasskeys.com gains significant traction in developer communities as a centralized tracker for authentication standards.
- 2025-11Major industry update sees a surge in passkey adoption among financial institutions, highlighting the lag in social media and entertainment sectors.
Weekly AI Recap
Read this week's curated digest of top AI events →
AI-curated news aggregator. All content rights belong to original publishers.
Original source: Digital Trends ↗
This is a summary, not the original. Read the source, or get the weekly briefing.
The weekly digest
One email a week. Unsubscribe anytime.