Passkeys are widely regarded as the gold standard for account security, yet a surprising number of major online platforms still refuse to offer them. A new website, whynopasskeys.com, is publicly calling out these laggards, putting Instagram, Netflix, and Spotify on a list of companies that have yet to adopt the technology. The site, created by security researcher Scott Helme, aims to shame these industry giants into action by leveraging the power of public accountability.
Why Passkeys Are the Gold Standard for Account Security
Passkeys represent a fundamental shift away from traditional passwords. Instead of a string of characters a user must remember and type, a passkey is a cryptographic key pair generated by a user’s device. The private key is stored securely on the device and is tied to a specific website or app. Authentication is performed using biometrics like Face ID or Touch ID, a device PIN, or a physical security key. This design makes passkeys inherently resistant to phishing and credential theft because there is no secret to steal or trick a user into revealing. Even if a hacker compromises a server, they cannot extract a usable passkey.
Who Is on the Passkey Shame List?
The whynopasskeys.com website maintains a public list of major services that do not support passkey login. Among the most prominent names are Instagram, Netflix, and Spotify. The list also includes other well-known platforms, highlighting a significant gap in the adoption of this security standard across the consumer internet. The site’s creator, Scott Helme, stated in a blog post that the motivation is simple: “A list is a surprisingly effective motivator. Nobody wants to be on the list.”
Instagram’s Partial Passkey Support
It is worth noting that Instagram does offer a limited form of passkey support, but only under a specific condition. Users can enable passkeys on Instagram if their account is linked to a Facebook account that already has a passkey enabled. This workaround is not a native implementation and does not provide the same seamless, independent security experience that a direct passkey option would. Meta, Instagram’s parent company, has not commented on why its other products, such as Facebook and WhatsApp, offer direct passkey support while Instagram does not.
Which Major Companies Are Doing It Right?
The list of companies that have fully embraced passkeys includes some of the biggest names in technology. Apple, Google, and Microsoft all offer passkey support across their platforms and services. This leadership from the major operating system and browser vendors is critical, as it provides the underlying infrastructure that makes passkeys work across devices and websites. Their adoption sets a clear standard for the rest of the industry.
What Is a Passkey and How Does It Work?
A passkey is a digital credential that replaces a password. It is created by your device and consists of a public and private key pair. The public key is stored on the website’s server, while the private key remains on your device. When you log in, the website sends a challenge that your device signs with the private key. Your device uses biometric authentication or a PIN to authorize this signature. Because the private key never leaves your device and is never shared with the website, it cannot be stolen in a data breach or intercepted by a phishing attack.
What This Means for Your Online Security
The continued absence of passkeys on platforms like Instagram, Netflix, and Spotify leaves millions of users vulnerable to credential theft. While these services may offer other security measures like two-factor authentication (2FA), passkeys provide a more user-friendly and inherently more secure alternative. The public shaming approach of whynopasskeys.com applies pressure on these companies to prioritize user security. For users, the message is clear: demand passkey support from the services you use.
What Affected Users Should Do Now
Until these major platforms implement native passkey support, users should take proactive steps to secure their accounts. First, enable two-factor authentication (2FA) on every account that offers it, preferably using an authenticator app rather than SMS. Second, use a zero-knowledge password manager to generate and store strong, unique passwords for each service. This ensures that even if one account is compromised, others remain safe. Finally, monitor your accounts for any suspicious activity and report it immediately. By taking these steps, you can significantly reduce your risk while waiting for the industry to catch up to the security standard it should already be providing.