Google has announced that passkeys will be the default sign-in method for all users, allowing for passwordless authentication using public-key cryptography. Passkeys eliminate the need for usernames and passwords and provide an additional layer of security against phishing attacks. This move follows Microsoft’s support for passkeys in Windows 11 and the adoption of passkey support by platforms like eBay and Uber. While passwords will still be an option, Google is encouraging users to adopt passkeys.
While I’m hitting security, Politically motivated hackers have started launching cyberattacks in response to the recent Hamas attack on Israel. News sites and emergency services applications have been targeted, causing fear and confusion. While most of the cyber activity appears to support Palestinians, researchers anticipate that pro-Israel groups will also emerge. State-backed hacking groups, particularly those in Iran, have a history of targeting Israel and are likely to be involved in this conflict.
And an update in CRN focuses on Cyber insurance trends to watch, including the increasing need for SMBs to obtain cyber insurance due to rising cyberattacks, the leveling-off of pricing but the potential for future increases, the lengthening and complexity of insurance questionnaires, the more detailed requirements for security measures, and the importance of reading the fine print in policies to understand exclusions and coverage limitations.
According to a survey by Synopsys, most IT professionals take up to one month to patch critical security flaws, leaving organizations at high risk for attacks. Poor patching is a popular cyber misconfiguration, and both cybercriminal organizations and nation-state hacking groups benefit from slow patching cadences. The modern internet’s reliance on insecure code and the prioritization of production deadlines over security contribute to this issue.
The tech industry has a long way to go before passwords are entirely phased out, but Google’s move is a significant step toward that goal. The number one thing you can do right now is demand passkeys from your vendors for products you use and that you use with customers. Investment here is critical. While passkeys offer enhanced security, they also necessitate updates in system configurations and policy documentation. MSPs can seize this opportunity to lead clients through this transition, ensuring a seamless and secure experience.

