Singapore is expanding its use of passkeys for national digital authentication, with Singpass passkeys now being rolled out to Android users after first becoming available to iPhone users earlier this year. The move is designed to make online logins safer by reducing reliance on passwords, QR codes and other authentication methods that can be intercepted or copied by scammers.
The new system works differently from a traditional password. Instead of asking users to remember or enter a secret code, Singpass creates a unique pair of cryptographic keys for supported websites and services. One key remains securely on the user's device, while the other is held by Singpass. Because the two need to work together, the credential cannot simply be copied and entered into a fraudulent website.
Passkeys Are Designed to Make Phishing Much Harder
One of the biggest weaknesses of passwords is that users can be tricked into handing them over. A fake website can look almost identical to a legitimate login page, and once a victim enters their username and password, the attacker immediately has something they can reuse elsewhere.
Passkeys work differently because they are tied to the legitimate service they were created for. If a user is redirected to a fake Singpass page or another fraudulent website, the passkey should not authenticate there.
This makes the technology particularly useful against phishing, where the attacker's entire strategy depends on convincing the victim to enter reusable credentials into the wrong place.
Two Cryptographic Keys Work Together
The Singpass implementation uses a pair of encryption keys. One key stays on the user's phone, while the corresponding key remains on Singpass' backend systems.
The important part is that the private key on the device is not transmitted to the website during authentication. Instead, the phone proves that it possesses the correct key without revealing it.
That makes the credential much harder to steal through conventional phishing. Even if an attacker creates a convincing copy of a government or banking website, they do not receive a reusable password or authentication secret.
Fake Websites Should No Longer Be Able to Use the Credential
This is one of the strongest advantages of passkeys. They are generally bound to the legitimate website or application they were created for.
If a victim accidentally reaches a spoofed website, the passkey will not simply appear as something they can manually type in. The authentication system checks whether the request is coming from the correct service before allowing the credential to be used.
That creates an important layer of protection against lookalike login pages, QR-code scams and malicious links sent through messaging applications or email.
Android Users Will Begin Receiving Reminders
GovTech says Android users will start receiving notifications through the Singpass app from September 9, encouraging them to create a passkey.
The process should be relatively straightforward for users with supported devices. Once configured, future authentication can take advantage of the phone's existing security features, such as biometrics or the device unlock mechanism.
That also means users do not have to remember another complicated password purely for Singpass access.
iPhone Adoption Has Already Been Strong
The passkey rollout first reached iPhone users in July, and GovTech says around 800,000 iPhone users have already created one.
That level of adoption in only a few months suggests users are willing to move away from older authentication methods when the setup process is simple enough.
Extending the feature to Android significantly increases the potential reach, given how widely Android smartphones are used across Singapore.
Singpass Already Sits at the Centre of Singapore's Digital Services
The importance of stronger authentication becomes clearer when considering how much Singpass is used for. The national identity platform supports around 5.5 million users and connects with more than 1,400 government and private-sector services.
These include major platforms such as:
Because one national identity system provides access to so many important services, protecting that identity from phishing becomes especially important.
A stolen Singpass credential could potentially expose far more than one account.
Why Passwords and QR Codes Remain Attractive to Scammers
Passwords are vulnerable because they can be copied. QR codes can also be abused because users often cannot see where a code leads before scanning it.
A scammer may send a fraudulent QR code that opens a fake login page, or a phishing message may direct the victim to a site designed to capture credentials.
The problem is that both methods depend heavily on the user recognising whether a destination is legitimate. Passkeys shift more of that decision into the authentication technology itself.
Instead of asking the user to determine whether the website is genuine, the credential checks whether it belongs to that website.
Passkeys Reduce the Value of Stolen Login Information
Traditional phishing is profitable because credentials can usually be reused. Once attackers obtain a password, they can attempt to sign in themselves, sometimes from another device or country.
A passkey is much less useful to steal because the sensitive component remains protected on the user's device. There is no simple password string for the attacker to copy into another browser.
This does not make the entire account completely invulnerable. Attackers can still use social engineering, malware or device compromise. But it removes one of the easiest and most common ways of stealing authentication credentials.
The Phone Becomes Part of the Security Boundary
With passkeys, the smartphone itself becomes a more important part of authentication. Device security therefore matters.
Users should continue protecting their phones with a strong PIN, biometric authentication and up-to-date software. If the device is lost, the mechanisms used for recovering or revoking credentials become equally important.
The advantage is that modern smartphones already contain secure hardware and operating-system protections specifically designed to store cryptographic credentials safely.
This Is Part of a Wider Move Away From Passwords
Singpass is not alone in moving toward passkeys. Major technology companies and online services are increasingly adopting the same approach because passwords have become one of the weakest links in online security.
Users reuse them, attackers steal them, databases leak them and phishing sites collect them. Even complex passwords remain vulnerable if someone willingly enters them into a convincing fake website.
Passkeys address that problem by replacing shared secrets with cryptographic authentication that is tied to a specific service.
For everyday users, the experience can also be simpler because authentication often becomes little more than confirming access with a fingerprint, face scan or device unlock.
Security Still Depends on User Awareness
Passkeys greatly improve authentication security, but they do not eliminate every form of scam. Criminals may adapt by focusing on other parts of the process.
A scammer could still impersonate government officers, convince users to install malicious applications or trick them into approving transactions after login. Social engineering does not disappear simply because passwords become harder to steal.
Users should therefore remain cautious when receiving unexpected requests involving Singpass, banking or government services, especially when someone creates urgency or asks them to install software.
A Stronger Authentication Model for a High-Value Identity
Singpass is not simply another consumer account. It acts as a gateway to a large part of Singapore's government and private-sector digital ecosystem.
That makes it an especially attractive target for phishing groups. Strengthening authentication therefore has broader implications for digital banking, healthcare, taxation and government services.
Moving toward passkeys reduces the reliance on credentials that users can accidentally disclose and gives the authentication system a stronger way to verify that the login is happening through a legitimate service.
Final Thoughts
The expansion of Singpass passkeys to Android users represents an important step in Singapore's effort to reduce the impact of phishing scams and credential theft.
By using a unique cryptographic key pair rather than a reusable password, Singpass can make it much harder for attackers to trick users into handing over credentials through fake websites or fraudulent QR codes. The passkey simply should not work when the authentication request comes from the wrong destination.
With around 800,000 iPhone users already having created passkeys and Android users now joining the rollout, adoption could grow quickly across Singpass' 5.5 million users.
For a national authentication system connected to more than 1,400 services, that matters. The less users need to type, copy or scan reusable credentials, the fewer opportunities scammers have to steal them.


Comments 0