Follow ZDNET: Add us as a preferred source on Google. Here on ZDNET, I've been writing a lot about passkeys -- the FIDO Alliance-backed passwordless replacement for traditional usernames and passwords. As far as I'm concerned, all organizations and users on the internet cannot make the move soon enough. However, I was reminded of how challenging and lengthy that transition will be (sadly, 10 years is my estimate) when I recently encountered warnings to change my password for ChatGPT. Also: How passkeys work: The complete guide to your inevitable passwordless future That ill-informed recommendation turned up in my article feed when the operator of ChatGPT -- OpenAI -- announced the day before Thanksgiving that some of its customer data had been breached by threat actors. Between watching my turkey bake and preparing my side dishes, I rushed to my computer to change my OpenAI password. Not a moment to lose when you get scared like that, right? There was only one major problem: While I have a login to OpenAI, I suddenly realized I didn't have an OpenAI password. Wait. What?! How is that possible? Now what do I do? And why do freaky technical emergencies like this always happen at the worst possible time? And what kind of hypocrite am I to be recommending passkeys to everyone while not using a passkey to log into ChatGPT? At that moment, I couldn't remember whether or not OpenAI was enabling users to authenticate to its generative AI services with a passkey. If it were, there'd b...
Should you stop logging in through Google and Facebook? Consider these SSO risks vs. benefits
ZDNet
·David Berlind
·Published Dec 11, 2025
·Updated
Affected Software
1 affected component
OpenAI ChatGPT
Frequently Asked Questions
1
What is the main topic of this article?
The article discusses the pros and cons of using single sign-on (SSO) solutions like Google and Facebook versus adopting passkeys for passwordless authentication.
2
What security implications are discussed?
The article highlights potential risks associated with SSO, such as account compromises and dependency on third-party services.
3
What benefits are mentioned regarding passkeys?
Passkeys provide stronger security by eliminating traditional passwords and reducing the risk of phishing and credential theft.
4
What products or software are affected by the discussed security methods?
The software involved includes various applications and services that integrate SSO with platforms like Google and Facebook.
5
Should users switch from SSO to passkeys?
The article suggests users carefully assess their security needs and consider the risks and benefits of both authentication methods before making a switch.