Security researcher Scott Helme has launched a public “name and shame” website, whynopasskeys.com, to pressure major digital platforms like Netflix, Spotify, and Instagram into adopting highly secure login passkeys.
Passkeys have rapidly become the gold standard for protecting online accounts against cybercriminals. Despite this, a staggering one in four major websites and mobile applications still fail to provide this security feature, leaving millions of users vulnerable. These statistics come from a new website that highlights companies failing to give users the option to secure their accounts with passkeys.
Why passkeys are the ultimate security upgrade
Unlike traditional passwords, passkeys are cryptographically generated by a user’s physical device and are uniquely bound to the specific website or app they were created for. By leveraging biometrics—such as Face ID, Touch ID, or physical security keys—they integrate seamlessly with password managers. This eliminates the need for users to memorise complex phrases, making credential harvesting and phishing attempts virtually impossible unless a hacker gains physical possession of the device.
The power of public pressure: whynopasskeys.com
Cyber security expert Scott Helme created whynopasskeys.com to accelerate the adoption of this technology. In a recent blog post, Helme explained that public accountability is a highly effective tool for corporate action, noting that “nobody wants to be on the list”. While industry giants like Apple, Google, and Microsoft have fully embraced the technology, others lag behind.
The curious case of Instagram and Meta
Interestingly, Instagram users can only activate passkeys if their profile is linked to a Facebook account that already has the feature enabled. Meta, which owns both platforms, has not yet clarified why WhatsApp and Facebook support standalone passkeys whilst Instagram does not. Netflix and Spotify have also failed to comment on when they plan to implement the secure login standard.
