search
passkeys
Trends
- 1Passwords Are a Nightmare. There Is a Better Way.βAnalysis | We donβt have to live with the nightmare of passwords. There is a better way.
A Washington Post analysis argues that the world no longer needs to depend on passwords, calling them a persistent security nightmare for users and companies alike. The piece points to alternatives such as passkeys and other passwordless authentication methods as a better path forward, renewing debate about whether the industry is ready to retire passwords for good.
- 2
Developer Duarte Santos has released openGym, a self-hosted fitness tracker written in JavaScript that lets users plan routines, log workouts including supersets, warm-ups and cardio, and monitor which muscles are trained, fatigued or detrained. The tool supports imports from popular apps FitNotes, Strong and Hevy, offers passkey login, and keeps all data on the user's own server β a privacy pitch that is drawing interest among self-hosting enthusiasts.
- 3High-severity flaw disclosed in Nginx UI login checksβπ CVE-2026-107808 - High (8.1) Nginx UI is a web user interface for the Nginx web server. From 2.0.0 until 2.5.0, POST /
A new high-severity vulnerability, CVE-2026-107808 with a CVSS score of 8.1, has been disclosed in Nginx UI, the web management interface for the Nginx web server. Versions 2.0.0 through 2.5.0 fail to properly enforce passkey authentication: the login endpoint checks whether OTP is enabled but does not require a WebAuthn assertion when passkeys are enabled and no TOTP secret is configured, potentially allowing passkey-only accounts to bypass authentication. Security teams are urged to update to version 2.5.0 or later.
- 4IBM Guardium vulnerability scores 8.4 in new advisoryβΌπ¨ EUVD-2026-95241 π Score: 8.4/10 (CVSS v3.1) π¦ Product: Guardium Data Protection π’ Vendor: IBM π Updated: 2026-10-08 π
A newly updated vulnerability advisory, EUVD-2026-95241, flags IBM Guardium Data Protection 12.2 with a high severity rating of 8.4 out of 10 under CVSS v3.1. The flaw stems from weak cryptographic protection and a hard-coded recovery key in the pkcrypto passkey component, exploitable by a local attacker. Administrators running Guardium are urged to review the advisory and apply vendor patches.
- 5Passkey adoption lags even among security professionalsβPasskey adoption lags as security pros still use passwords https:// fawkes.rocks/2026/10/08/passke y-adoption-lags-as-se
A new report finds that passkey adoption is falling short of expectations, with even security professionals continuing to rely on traditional passwords. The finding is raising questions about why the phishing-resistant technology has struggled to gain traction despite years of promotion from major platforms and industry groups.
- 6Okta says AI makes phishing-resistant authentication essentialβΌAI underscores singular importance of phishing-resistant authentication, Okta says
Identity security company Okta says the rise of AI has made phishing-resistant authentication more important than ever, arguing that AI tools make phishing attacks faster, more convincing and harder to detect. The company is pressing organisations to adopt authentication methods, such as passkeys and hardware keys, that cannot be stolen through deceptive messages, as AI-driven social engineering puts traditional defences under strain.
Repos
- DuarteSantos8/openGym Self-hosted gym & body-weight tracker β plan routines, log workouts (supersets, warm-ups, cardio), see which muscles