/
Navigation
Chronicles
Browse all articles
Explore
Semantic exploration
Research
Entity momentum
Nexus
Correlations & relationships
Story Arc
Topic evolution
Drift Map
Semantic trajectory animation
Posts
Analysis & commentary
Pulse API
Tech news intelligence API
Browse
Entities
Companies, people, products, technologies
Domains
Browse by publication source
Handles
Browse by social media handle
Detection
Concept Search
Semantic similarity search
High Impact Stories
Top coverage by position
Sentiment Analysis
Positive/negative coverage
Anomaly Detection
Unusual coverage patterns
Analysis
Rivalry Report
Compare two entities head-to-head
Semantic Pivots
Narrative discontinuities
Crisis Response
Event recovery patterns
Connected
Search: /
Command: ⌘K
Embeddings: large
TEXXR

Chronicles

The story behind the story

days · browse · Enter similar · o open

GitHub launches support for passkeys in public beta, letting users who opt in upgrade from security keys to passkeys, and use those in place of password and 2FA

GitHub announced today the introduction of passwordless authentication support in public beta, allowing users to upgrade from security keys to passkeys.

BleepingComputer Sergiu Gatlan

Context & Ripple Effects

This is the third act in a decade-long authentication arc at GitHub: the company added U2F security key support back in 2015, extended hardware-key auth to SSH Git operations in 2021 while planning to drop passwords for Git operations, and now lets opted-in users retire both the password and the second factor in favor of a passkey.

The move also lands on ground Google prepared: [[a:983743|Google began rolling out passkey sign-in on Android and Chrome to beta testers in late 2022]], so GitHub is adopting a credential format its users' devices already support rather than betting on new hardware.

First-order effects

  • Opted-in GitHub users can now sign in with a passkey alone, replacing the password-plus-2FA flow, while existing security-key holders get an explicit upgrade path off hardware tokens.

Second-order effects

  • Rival code-hosting and developer platforms face pressure to match passwordless sign-in or explain why their accounts remain phishable relative to GitHub's, since developer credentials are the keys to source code and release pipelines.

Third-order effects

  • If the pattern holds across platforms, account-takeover defense shifts from user-managed second factors to platform-issued cryptographic credentials, making phishing-resistant auth a baseline expectation for any service holding supply-chain access rather than a premium feature.

The trend: Developer platforms are converging on passkeys as the endpoint of a decade-long march away from passwords, following the device-level groundwork laid by Google and Apple.

Discussion

  • @film_girl Christina Warren on x
    Passkeys, the greatest thing ever (thanks @rmondello!) are now in public beta on @github! I've been using this for quite some time and I'm so psyched it's now available for everyone to try out! https://github.blog/...
  • @mg Matt Galligan on x
    Just turned on Passkeys for my @github account. Such a slick experience every time. Adoption of Passkeys can't happen fast enough! https://twitter.com/...
  • @rmondello Ricky Mondello on x
    A big deal. “Introducing passwordless authentication on https://github.com/ Passkeys are now available in public beta. Opting in lets you upgrade security keys to passkeys, and use those in place of both your password and your 2FA method.” https://github.blog/...
  • @github @github on x
    Moving past passwords is 🔑 for better account security. Today we're launching passkey support on https://github.com/ - you can enable passkeys today and ditch that password. https://github.blog/...
  • r/InfoSecNews r on reddit
    GitHub goes passwordless, announces passkeys beta preview