Passwords are often the most troublesome weak point in account security. We are asked to create long combinations, not to reuse them across other services, and then remember them when logging in from a new device. The problem is, passwords can also be easily stolen through phishing—such as when someone enters credentials on a fake login page that looks like the original service.
Passkeys come as an alternative that reduces reliance on passwords. When logging in, users simply unlock their device with a fingerprint, face, PIN, or pattern. Behind the scenes, the service uses a pair of cryptographic keys specifically created for that account and site. Therefore, passkeys cannot simply be copied or typed into a fake page.
This technology is already supported by many devices, operating systems, browsers, and popular services. However, passkeys are not a magic button that solves all security problems. Users still need to protect their devices, set up account recovery, and understand when a login request should be treated with suspicion.
Passkeys work differently from passwords
When creating a passkey, the device generates two key parts: a public key and a private key. The public key is stored by the service, while the private key remains on the device or in the passkey manager chosen by the user.
During login, the service sends a digital challenge. The device proves that it has the private key without sending that key to the site. The user only needs to approve the process by unlocking the device.
An important detail is that passkeys are tied to the identity of the correct site or application. If someone creates a fake page with a different address, the device will not use the passkey for that site. This is why passkeys are categorized as phishing-resistant authentication methods, unlike OTP codes that can still be copied and entered on scam sites. This technical explanation aligns with the documentation from FIDO Alliance and the CISA guide on phishing-resistant authentication.
Why are passkeys more secure than passwords?
1. No passwords to be phished
Phishing usually succeeds because victims enter their username, password, or verification code on a page controlled by the scammer. Passkeys are not designed to be typed or read by users. The device only uses them when the site requesting login matches the site where the passkey was created.
2. Not easily reused across multiple services
Using the same password on several sites creates a domino effect. If one service experiences a data breach, attackers can try the same combination on email, social media, or marketplaces. Passkeys are created for specific services, so they cannot be used as universal passwords.
3. Login feels simpler
In everyday use, passkeys often feel like unlocking a phone. There’s no need to search for a password in notes, wait for an SMS, or copy a code from an authenticator app. Google explains that passkeys can be used with fingerprints, facial scans, or device lock screens, while biometric data remains processed on the device and is not sent to Google. ([support.google.com](https://support.google.com/accounts/answer/13548313?hl=en&utm_source=openai))
Are passkeys really risk-free?
No. Passkeys reduce certain classes of attacks, especially credential theft through phishing, but account security still depends on the surrounding ecosystem.
- Insecure devices: If a phone or laptop is infected with malware, attackers may be able to disrupt an active session or manipulate the login process.
- Weak lock screens: Easily guessable PINs or devices without locking make passkeys easier to misuse by someone who gains physical access.
- Account recovery: If a service still provides recovery options through weak email or SMS, those channels can become targets for attackers.
- User confusion: Scammers can still try to trick victims into installing malicious apps, granting remote access, or approving transactions after login.
The FIDO Alliance also distinguishes between passkeys synchronized through credential manager ecosystems and passkeys tied to specific devices or security keys. Synchronized passkeys are more convenient when users switch devices, while physical security keys offer tighter control for high-risk needs.
What you can do now
- Start with the most important accounts. Prioritize your main email, password manager accounts, cloud accounts, banking, and work accounts. If your main email is compromised, attackers can try to reset many other accounts.
- Check if the service supports passkeys. Usually, the settings are found under Security, Sign-in, Login, or Two-step verification. Do not create passkeys from links sent via suspicious messages; open the app or site directly.
- Create more than one secure access path. Add passkeys on backup devices that you fully control, or use physical security keys for high-value accounts. Store backup devices in a safe place.
- Ensure your device's screen is always locked. Use a hard-to-guess PIN and enable system updates. Passkeys protect the login process, but do not replace basic device protection.
- Review recovery methods. Remove old numbers, emails, or devices that are no longer in use. Make sure you understand how to revoke passkeys if your phone is lost.
- Do not approve login requests you did not initiate. Passkeys prevent many phishing attempts, but cannot stop social engineering when victims themselves grant access or follow scammers' instructions.
What does this mean for us?
Passkeys do not mean everyone should immediately delete all their passwords. The transition period still requires old methods because not all services support passkeys, and some accounts have different recovery processes.
A sensible approach is to use passkeys on accounts that already support them, use unique passwords and a password manager for other services, and then enable multi-factor authentication as an additional layer. If the only options available are SMS, authenticator apps, or passkeys, passkeys generally provide stronger phishing protection. However, any form of multi-factor authentication is still better than relying solely on passwords.
The biggest change with passkeys is not just a faster login method. This technology reduces the decisions users have to make when facing suspicious login pages: there’s no need to assess whether a form is safe to receive a password, as the device only responds to matching sites. This makes security not entirely dependent on human vigilance at all times.
Sources & further reading
- CISA — More than a Password
- FIDO Alliance — Passkeys FAQ
- Google Account Help — Sign in with a passkey instead of a password
- Google Android Help — Sign-in to your applications and websites with passkeys
– Rio Yotto @rioyotto
