Password Security 2024: Passkeys, MFA, and the End of the Classic Password
Over 80% of all data breaches start with compromised credentials (Verizon DBIR 2024). Passwords are structurally insecure: they are reused, stolen, guessed, and phished. In 2024, there are mature alternatives – passkeys, MFA, and modern IAM systems – that companies should systematically introduce.
TL;DR
- 80% of attacks begin with credentials: Passwords alone are not enough.
- Passkeys are FIDO2-based: No password, no phishing possible – the private key never leaves the device.
- MFA reduces risk by 99%: According to a Microsoft study, 99.9% of accounts with MFA are not compromised.
- Password managers as a transitional solution: Until passkeys are widely available, centralized password managers help.
- Secure privileged accounts immediately: Admin accounts without MFA represent the most critical risk.
What Are Passkeys and Why Are They Better?
Passkeys are based on the FIDO2/WebAuthn standard. Instead of a password, a cryptographic key pair is created during registration: the public key is stored with the service, and the private key is securely stored on the user’s device (protected by biometrics or PIN). During login, the user only needs to confirm biometrically – no password is transmitted.
The result: phishing is structurally impossible because there is no password that could be stolen. Credential stuffing does not work because there are no credentials to stuff. Apple, Google, and Microsoft have natively supported passkeys since 2022/2023.
MFA Types Compared
FIDO2/Passkey: Phishing-resistant, highest security. Recommended for privileged accounts and high-value targets.
Hardware Token (YubiKey): Very secure, phishing-resistant. Good for IT admins and remote access. Cost: €30-€70 per key.
Authenticator App (TOTP): Well-suited for broad user groups. Not phishing-resistant (real-time phishing can intercept TOTP codes), but significantly better than no MFA.
SMS/E-Mail OTP: Better than no MFA, but vulnerable to SIM swapping and interception. Should no longer be used for critical systems.
Implementation Strategy for Companies
Phase 1 – Privileged Accounts: Admin accounts, service accounts, cloud management. Implement MFA (FIDO2 or hardware token) here immediately. This quickly eliminates the biggest risk.
Phase 2 – All Employees: Authenticator app for email, VPN, and SaaS applications. Set up SSPR (Self-Service Password Reset) with MFA to reduce helpdesk burden.
Phase 3 – Introduce Passkeys: Where services support passkeys (Microsoft, Google, GitHub, Okta), migrate to passkeys. User training is critical at this stage.
Key Facts at a Glance
Attacks through compromised credentials: 80%+ (Verizon DBIR 2024)
Risk reduction through MFA: 99.9% of accounts with MFA are not compromised (Microsoft)
Passkey support: Over 13 billion user accounts can now use passkeys (2024)
Cost of hardware tokens: From €25 (YubiKey Security Key) to €70 (YubiKey 5 NFC)
Password reuse rate: 65% of users reuse the same password (Google study)
Fact: According to the Verizon DBIR, 81% of all data breaches use weak or stolen passwords as an attack vector.
Fact: Credential-stuffing attacks rose 65% in 2024 compared to the previous year, per Okta.
Frequently Asked Questions
Every question is locked. A tap unlocks the answer.
What is the difference between passkeys and FIDO2?
FIDO2 is the open standard (developed by the FIDO Alliance) that provides the technical foundation. Passkeys are the user-friendly implementation of this standard by Apple, Google, and Microsoft – stored in the device keychain and available via cloud sync.
Can phishing bypass passkeys?
No. Passkeys are domain-bound – the private key only works on the genuine domain for which it was registered. A phishing site cannot misuse a passkey, even if the user falls for it.
Which password manager is recommended for companies?
For companies: 1Password Business, Bitwarden for Business, Dashlane Business, or Keeper Security. Key requirements: centralized admin dashboard, SSO integration, policy enforcement, and audit logs.
What to do if an employee loses their authenticator?
Define the recovery process in advance: securely store backup codes, provide an alternative recovery factor (e.g., hardware token for admins), and require identity verification by HR or a manager before resetting the account.
Is SMS-OTP still secure enough?
Acceptable as a transitional solution for non-critical applications. Not recommended for critical systems, administrators, or remote access. SIM-swapping attacks targeting SMS are well-documented and highly realistic.
Further Articles on the Topic
→ Better than Theory: Phishing Simulations in Practice
Further Reading in the Network
Identity Management Trends: mybusinessfuture.com
Securing Cloud Identities: cloudmagazin.com
Related Articles
- Passkeys 2025: The Practical Guide to Enterprise Introduction
- CrowdStrike Outage July 2024: Lessons for Business Continuity and Vendor Risk
- Patch Management 2023: Unpatched Systems as the Biggest Security Risk
Header Image Source: Pexels / Miguel Á. Padriñán