For years, the security advice was simple: turn on multifactor authentication.
IT people repeated it endlessly. Microsoft pushed it. Insurance companies started requiring it. Cybersecurity audits looked for it. Eventually, most businesses got the message.
Users learned the routine. Enter the password. Wait for the text message. Type in the 6-digit code. Get back to work.
Now Microsoft is changing all of that. [Read more…]
You click a link. It takes you to a site that looks exactly right. The logo matches, the name checks out, and everything feels familiar. But something’s off. And before you realize what it is, you’ve handed over your login, your credit card, or worse, your network credentials. The trick wasn’t in the layout or the content. It was in the letters.
Microsoft is shifting new account signups away from passwords and toward passkeys. It’s part of a broader industry effort, with companies like Google and Apple also pushing for a future where stolen credentials are no longer a threat. This move sounds like progress, but there’s more going on beneath the surface.