The German Federal Office for Information Security (BSI) recommends adopting passkeys and two-factor authentication to protect digital accounts against rising threats like phishing, data breaches, and SIM swapping attacks.
Key Points
- Passwords are vulnerable to data leaks, phishing sites, and SIM swapping, which caused $26 million in losses during 2024 according to the FBI.
- Passkeys and hardware keys like YubiKey provide superior security because they are cryptographically tied to specific websites, rendering phishing attempts ineffective.
- Authenticator apps using TOTP codes are more secure than SMS or email verification but remain susceptible to sophisticated real-time phishing attacks.
- Major platforms including Google, Apple, Microsoft, and PayPal now support passkeys, with the FIDO Alliance projecting five billion active users by 2026.
- The BSI advises using a two-step recovery process, such as storing backup codes offline or keeping a secondary hardware key, to prevent account lockout.