A new website launched in June 2026 is publicly listing major apps and services that do not yet offer passkeys as a login option — and roughly one in four of the world’s most popular websites are on that list.
The site, whynopasskeys.com, was created by security researcher Scott Helme to pressure companies into enabling passkey support. “A list is a surprisingly effective motivator. Nobody wants to be on the list,” Helme wrote in an accompanying blog post. Notable companies currently flagged include Instagram, Netflix, and Spotify.
Passkeys are widely considered more secure than traditional passwords. They are generated by a user’s device and tied to that device and the specific website they are created for. Authentication can rely on biometrics such as Face ID or Touch ID, or a physical security key, and passkeys can be stored in a password manager. Because users do not need to remember anything, and because passkeys are difficult to steal or phish without physical access to a target’s device, they are regarded as the current gold standard for account security.
Apple, Google, and Microsoft are among the companies on the compliant side of the list, already offering passkeys to their users. Instagram presents a partial case: users can enable passkeys on the platform, but only if their account is linked to a Facebook account that already has a passkey set up. Meta, which owns both Instagram and Facebook, had not responded to a request for comment at time of publication. WhatsApp, also owned by Meta, does support passkeys. Netflix and Spotify were also contacted for comment.
Helme’s site highlights that despite broad industry support from major technology platforms, passkey adoption remains incomplete across the wider app ecosystem.
Source: TechCrunch