top of page

パスキーがOTPを駆逐する:2025年のセキュリティ標準

Passkeys Are Killing OTPs: The 2025 Security Standard

テキストメッセージの認証コードは十分に役立ちました。何年もの間、私たちはこの儀式を受け入れてきました。パスワードを入力し、バイブレーションを待ち、6桁の数字を暗記し、タイマーが切れる前にそれを入力する。しかし、2025年を終えるにあたり、その儀式は時代遅れになりました。「ワンタイムパスワード」(OTP)は、現代の脅威モデルに対して十分に安全ではなくなり、業界は先に進みました。

Passkeysがその代替です。これは単なる利便性の向上ではなく、インターネットがアイデンティティを扱う方法の根本的な変化を表しています。私たちは「共有シークレット」—あなたとサーバーの両方が知っている文字列—から、秘密鍵がデバイスから離れることのない非対称暗号化へと移行しています。

これは単なる理論的な技術論ではありません。With over 2 billion passkeys currently active across Apple, Google, and Microsoft ecosystems、これが新しい基準です。しかし、移行には摩擦が伴います。企業の採用率を見る前に、実際にそれらを使って生活することがどのようなものかを確認する必要があります。

実世界での体験: Passkeysの実装

Real-World Experience: Implementing Passkeys

The theory of passkeys is seamless: 顔をスキャンするか指紋センサーに触れるだけでログインできます。完璧な単一エコシステムの真空状態では、これは本当です。Appleの壁に囲まれた庭園に完全に住んでいる場合や、管理されたWindows環境のみを使用している場合、エクスペリエンスは目に見えません。You don't "log in" so much as you "arrive."

しかし、ユーザーレポートやコミュニティのフィードバックは、私たちが現在、混乱した移行期にあることを強調しています。技術は機能しますが、ワークフローはしばしば現実の習慣と衝突します。

The "Remote Help" Problem with Passkeys

早期採用から生まれる最も具体的な摩擦点の1つは、家族を支援することです。古い世界では、親が写真を整理したりアカウントにアクセスしたりするのを助ける必要がある場合、パスワードを共有し、テキストコードを転送できました。

Passkeysはこのワークフローを壊します。秘密鍵がハードウェア(「あなたが持っているもの」の要素)に結び付けられているため、リモート支援が困難になります。If you try to log into an account secured by a passkey from a different location, the protocol often demands a "proximity check."これは通常、Bluetoothを介して行われ、資格情報を保持している電話がログインしようとしているコンピュータの近くに物理的に存在することを確認します。passkeyを電話で伝えることはできません。このセキュリティ機能は、異なるタイムゾーンのハッカーを止めるには優れていますが、認可されたリモートヘルパーを効果的に締め出します。

Cross-Ecosystem Friction and Passkeys

「synced」と「device-bound」の混乱が2番目の大きなハードルです。 Passkeys stored in iCloud Keychain sync beautifully between an iPhone and a Mac.しかし、iPhoneを使ってWindows PCを操作するユーザーは壁にぶつかることがよくあります。FIDO2のような標準はクロスデバイス認証を可能にします—通常、PC画面のQRコードを電話のカメラでスキャンします—が、そのプロセスはパスワードを入力するよりも不便です。

Users have noted that relying on third-party managers like Bitwarden or 1Password bridges this gap better than relying on platform-native holders (like Apple or Google). These third-party tools treat passkeys more like portable credentials, allowing for smoother transition between a work PC and a personal iPhone.

When Apps Don't Let Go

パワーユーザーの間で頻繁に起こる不満は、「zombie」ログインの流れです。Some services support passkeys but haven't deprecated their old architecture.堅牢なFIDO2キーで認証したのに、アプリが混乱させることにレガシー2FAコードを要求してくるかもしれません。これは、フロントエンドの技術は到着したものの、多くのバックエンドシステムがまだ古いコードでつぎはぎされていることを示唆しています。

The Data: Why Passkeys Are Faster and Safer

The Data: Why Passkeys Are Faster and Safer

ユーザーインターフェースの癖にもかかわらず、この採用を推進する指標は否定できません。この移行は、テック企業が流行を追っているからではなく、OTPが失敗しており、passkeysがコストを削減するからです。

Comparing Speed and Failure Rates of Passkeys

2025年末のデータによると、passkeyでのログインには平均8.5秒かかります。対照的に、SMS、メールのマジックリンク、またはアプリベースのOTPを含むレガシーメソッドは平均31.2秒です。これは摩擦の73%削減です。

eコマースの観点から、速度は収益です。コードを見つけるためにアプリ間を行き来するのに費やす1秒ごとに、カートを放棄する可能性があります。さらに、成功率は大幅に高くなります。Passkeys simply fail less often than typo-prone manual codes or undelivered SMS messages.

Operational Costs and Passkeys

IT予算の静かな殺人者はパスワードリセットのチケットです。Early adopters in the enterprise space have reported an 81% reduction in help-desk tickets related to login issues after switching to passkeys.ユーザーが忘れるパスワードを持っていない場合、ITにリセットを依頼するのをやめます。

The Technology: How Passkeys Kill Phishing

The Technology: How Passkeys Kill Phishing

この移行が恒久的である理由を理解するには、攻撃ベクトルを見る必要があります。2020年代の主要な脅威はフィッシングとソーシャルエンジニアリングでした。

The Mechanics of Phishing-Resistant MFA

標準的な資格情報収集攻撃では、ハッカーは本物そっくりの偽のログインページを作成します。あなたはユーザー名とパスワードを入力します。ハッカーのスクリプトがそれをキャプチャします。偽のページは次にOTPを要求します。あなたは電話を見てコードを入力し、ハッカーはそれもキャプチャします。彼らは今、あなたとしてログインするために必要なすべてを持っています。

When you attempt to authenticate with a passkey, the browser and the operating system perform a handshake with the server. Crucially, this handshake is bound to the domain. Your passkey for google.com will simply refuse to sign a request coming from g00gle.com or any other lookalike phishing site. The protocol checks the origin before the user is even asked to verify their identity. It removes the human element of checking the URL bar.

Device-Bound vs. Synced Passkeys

セキュリティアナリストは2種類の実装を区別します。

  1. Synced Passkeys: These sync across your cloud provider (iCloud, Google Password Manager). If you lose your phone, you don't lose the account because the key restores from the cloud backup. This is the consumer standard.

  2. Device-Bound Keys: These live on a specific piece of hardware, like a YubiKey or a specific TPM chip on a laptop. They are not copyable.

While device-bound keys offer the highest theoretical security (intercepting 99% of unauthorized access attempts), the market is heavily favoring synced passkeys. The risk of a user getting locked out of their life because they lost a hardware stick is too high for general consumers. The industry has accepted that the slight risk of cloud syncing is worth the massive usability gain.

The Future of Authentication

The Future of Authentication

私たちは現在、インターネットの「Identity」レイヤーが書き換えられるのを目の当たりにしています。2012年に結成されたFIDO Allianceは、ついにその標準がWebAuthnに成熟し、事実上市場を席巻するのを見てきました。

Removing the Legacy Backup

The next battleground for passkeys is the removal of the fallback. Currently, most services allow you to use a passkey, but still offer a "forgot password" link or a "use password instead" button. Security-conscious users argue that as long as the password entry point exists, the account is vulnerable. If a hacker can bypass your fancy biometric lock by simply clicking "use password" and guessing your weak string, the security upgrade is moot.

The demand for 2026 is the ability to disable legacy login methods entirely—going "passwordless" in the literal sense.

Captchas and Bot Prevention

この移行の興味深い副作用は、CAPTCHAの潜在的な終焉です。Passkeys provide a high-trust signal that the entity logging in is a human on a legitimate device. Because the cryptographic signature verifies the origin and the device integrity, the need to identify traffic lights or crosswalks to prove you aren't a robot diminishes.

Conclusion

The death of the one-time text code isn't just about saving twenty seconds during login. It is about closing a security loop that has been open since the inception of the web. Passkeys shift the burden of security from the user's fallible memory to the device's cryptographic chip.

While the user experience still has rough edges—particularly for those managing accounts for others or straddling different operating systems—the efficiency and security gains are absolute. We are no longer authenticating what we know; we are authenticating who we are.

FAQ: Common Questions About Passkeys

What happens if I lose the phone that holds my passkeys?

If your passkeys are stored in a cloud-synced service like iCloud Keychain, Google Password Manager, or Bitwarden, you simply log into your account on a new device, and your keys will be there. If you used a device-bound key that does not sync, you must use a pre-generated recovery code or a backup hardware key to regain access.

Can I use passkeys across different devices, like an iPhone and a Windows PC?

Yes, but it requires an extra step. You can select "Cross-Device Authentication," which usually displays a QR code on the PC. You scan this code with your iPhone, which uses Bluetooth to verify the devices are close to each other, and then approves the login.

Why do some sites still ask for a code after I use my passkey?

This is often due to legacy backend systems. While the website has added a passkey "front door," the underlying security checks may still trigger old risk assessments that demand a second factor. This redundancy typically disappears as companies modernize their entire identity infrastructure.

Are passkeys safer than a strong password and an authenticator app?

Yes. Even a strong password and an authenticator app code can be phished if you are tricked into entering them on a fake website. Passkeys are phishing-resistant because the browser validates the website domain before the key is ever used, preventing the credential from being shared with a malicious site.

Do passkeys mean I can't share my Netflix or Amazon account anymore?

It becomes much harder. Since the passkey is a digital credential stored on a device or in a personal manager, you cannot verbally tell someone your password. You would have to securely share the credential through a password manager that supports passkey sharing, or the other person needs their own passkey registered to the account.

 
 

無料で始めましょう

ローカルファーストのパーソナル知識管理付きAIアシスタント

より良いAI体験のために、

remio は現在、 Windows 10+ (x64)M-Chip Mac のみをサポートしています。

脳内に検索バーを追加

ただremioに尋ねるだけ

すべてを思い出す

何も整理しない

bottom of page