Home / Articles / Literasi Digital
Literasi Digital

Passkeys Are Not Magic: How to Transition from Passwords Without Locking Yourself Out

Passkeys simplify login and are more resistant to phishing, but users still need to understand devices, account recovery, and the risks of losing access. Here’s how to start using them safely.

Passkey Bukan Sihir: Cara Beralih dari Password Tanpa Mengunci Diri Sendiri

Passwords are still the key to many important accounts, but their fundamental weaknesses remain: passwords can be guessed, reused, stolen through data breaches, or entered on fake sites. Passkeys emerge as an alternative that reduces reliance on secrets that must be remembered and typed.

However, switching to passkeys doesn’t mean you can just hit the “activate” button and forget everything. You still need to know on which devices the passkeys are stored, how to recover your account, and when it’s best not to create them.

What exactly is a passkey?

A passkey is a login method that replaces passwords with a pair of cryptographic keys. One part is stored by the service, while the other part resides on your device or password manager. When logging in, the device proves it has the correct key without sending a password to be typed again.

In everyday practice, you typically just unlock your phone or computer using a PIN, pattern, fingerprint, or facial recognition. These biometrics are not sent to the site as raw data; their function is to unlock access to the passkey locally.

According to the FIDO Alliance, passkeys are designed to be resistant to phishing because they are tied to the site or application where the passkey was created. This means that passkeys should not be usable for logging into fake domains that resemble the original service. CISA also places FIDO/WebAuthn-based authentication as a widely available form of phishing-resistant authentication.

Why are passkeys easier for some people?

Strong passwords are often long, unique, and different for each service. While this is good, it’s not always easy to do without the help of a password manager. Passkeys reduce that burden because users do not need to memorize different character strings.

  • No need to type passwords: login is done by unlocking the device.
  • Hard to be phished through fake sites: credentials are tied to the correct service address.
  • More difficult to reuse: each passkey is created for a specific account and service.
  • Can be used across devices: passkeys synchronized through a password manager can be available on other connected devices.

This does not mean passkeys are immune to all security issues. If someone can unlock your phone, they could potentially use the passkeys stored within it. Therefore, screen locks, device updates, and habits of keeping devices private remain important.

Difference between synchronized passkeys and device-bound passkeys

Simply put, there are two patterns for storing passkeys. Synchronized passkeys are backed up and synchronized through a password manager service, making them easier to use after switching devices. Device-bound passkeys reside only on one device or a physical security key. The second type can provide additional control, but recovery is more cumbersome if the device is lost or damaged.

For most users, synchronized passkeys are more practical. You don’t need to carry a specific device every time you log in. For highly sensitive accounts—such as company administrator accounts or digital asset wallets—physical security keys can be considered as an additional layer.

What to check before creating a passkey

  1. Ensure the device is your own. Do not create passkeys on shared computers, borrowed phones, or office devices that can be used by many people. Google specifically warns that anyone who can unlock the device could potentially access accounts that have passkeys stored there.
  2. Update your operating system and browser. Passkey support depends on the devices, browsers, and services used. Updates also help fix security vulnerabilities.
  3. Check recovery methods. Ensure that recovery email, phone number, backup codes, or alternative devices are still usable before deleting passwords.
  4. Know the name of your password manager. If passkeys are stored by a password manager, understand how to access, back up, and recover that manager.

Practical steps to start using passkeys

Start with the most important accounts, not all services at once. Your primary email is usually the first choice as it is often used to recover other accounts.

  1. Open the official app or website of the service you want to secure.
  2. Go to the Security, Login, Sign-in options, or similarly named section.
  3. Look for the Passkeys option, then choose to create a new passkey.
  4. Check the device or password manager that will store it.
  5. Confirm with a PIN, pattern, fingerprint, or device unlocking method.
  6. Test logging in again in a private window or another device, but do not log out of all sessions before ensuring the recovery method works.

Once successful, name the device if the service provides that option. Names like “personal iPhone” or “home laptop” help you recognize and delete passkeys that are no longer in use.

What if the phone is lost?

Lost phones do not automatically mean all accounts are lost, especially if passkeys are synchronized and you can still access the password manager from another device. However, take immediate actions: remove the lost device from the session list, delete associated passkeys if possible, change recovery methods, and re-enable protection on the replacement device.

For passkeys stored only on that device, the process depends on the service's policy. This is why one login method alone is not enough. Keep at least one secure recovery path, but do not store backup codes in easily accessible places for others.

Can passwords be deleted right away?

Not always. Some services still require passwords for recovery or provide passkeys as an additional option, not a full replacement. There are also sites that do not support passkeys at all.

A safer strategy is to create passkeys, test login and recovery, and then gradually review other options. If the service allows passwordless login and you have a strong recovery backup, then consider reducing reliance on passwords.

What does this mean for us?

Passkeys are not a reason to stop paying attention to account security. They are more like a seatbelt: reducing the risk of certain types of accidents, but not replacing good driving habits.

Start with your primary email, financial accounts, and accounts that store personal data. Use passkeys only on personal devices, maintain a strong screen lock, regularly review your device list, and ensure recovery paths are truly usable. With this approach, transitioning from passwords becomes a safer step—not just following a technology trend.

Sources & further reading

– Rio Yotto @rioyotto