• News/
  • https://www.zdnet.com/article/passkeys-versus-consumer-ssos-replace-passwords-security/

Should you stop logging in through Google and Facebook? Consider these SSO risks vs. benefits

ZDNet
·
David Berlind
·
Published Dec 11, 2025
·
Updated

Follow ZDNET: Add us as a preferred source on Google. Here on ZDNET, I've been writing a lot about passkeys -- the FIDO Alliance-backed passwordless replacement for traditional usernames and passwords. As far as I'm concerned, all organizations and users on the internet cannot make the move soon enough. However, I was reminded of how challenging and lengthy that transition will be (sadly, 10 years is my estimate) when I recently encountered warnings to change my password for ChatGPT. Also: How passkeys work: The complete guide to your inevitable passwordless future That ill-informed recommendation turned up in my article feed when the operator of ChatGPT -- OpenAI -- announced the day before Thanksgiving that some of its customer data had been breached by threat actors. Between watching my turkey bake and preparing my side dishes, I rushed to my computer to change my OpenAI password. Not a moment to lose when you get scared like that, right? There was only one major problem: While I have a login to OpenAI, I suddenly realized I didn't have an OpenAI password. Wait. What?! How is that possible? Now what do I do? And why do freaky technical emergencies like this always happen at the worst possible time? And what kind of hypocrite am I to be recommending passkeys to everyone while not using a passkey to log into ChatGPT? At that moment, I couldn't remember whether or not OpenAI was enabling users to authenticate to its generative AI services with a passkey. If it were, there'd b...

Read full article

Affected Software

1 affected component
OpenAI ChatGPT
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the main topic of this article?

The article discusses the pros and cons of using single sign-on (SSO) solutions like Google and Facebook versus adopting passkeys for passwordless authentication.

2

What security implications are discussed?

The article highlights potential risks associated with SSO, such as account compromises and dependency on third-party services.

3

What benefits are mentioned regarding passkeys?

Passkeys provide stronger security by eliminating traditional passwords and reducing the risk of phishing and credential theft.

4

What products or software are affected by the discussed security methods?

The software involved includes various applications and services that integrate SSO with platforms like Google and Facebook.

5

Should users switch from SSO to passkeys?

The article suggests users carefully assess their security needs and consider the risks and benefits of both authentication methods before making a switch.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203