Tech Explained Tuesday 011: What Are Passkeys—and Will They Replace Passwords?
A passkey is a digital credential that lets you sign in to a supported app or website without typing that account’s password. You approve the sign-in using a device unlock method, such as a fingerprint, face recognition, or PIN. Passkeys can replace passwords for supported sign-ins, but they have not eliminated passwords across all accounts.
If you have seen a “Create a passkey” prompt and wondered whether to accept it, the useful questions are simple: where will it be saved, which devices can use it, and how will you get back in if those devices are unavailable?
What is a passkey in plain English?
Think of a passkey as a sign-in credential your device or credential manager uses for you. You do not invent it, memorize it, or type it into a website. Your fingerprint or PIN authorizes its use; that fingerprint or PIN is not itself the passkey.
A passkey provider is the system that manages the credential. It might be built into your operating system or supplied by a password manager. Knowing which provider saved it makes later troubleshooting much easier.
FIDO Alliance explains that biometric processing stays on your device rather than sending your fingerprint or face data to the website.
Source: https://fidoalliance.org/passkeys/
How do passkeys work?
When a passkey is created, it establishes a pair of cryptographic keys for the account. The website keeps the public key. The private key stays protected by the authenticator or passkey provider and is not disclosed to that website.
During sign-in, the service sends a challenge. After you authorize use of the passkey, your device supplies a signed response that the service can verify with the public key. You prove access to the credential without sending a reusable password.
Apple’s security explanation describes this public/private-key model and how Face ID or Touch ID can authorize its use. The important distinction is between approving a sign-in locally and giving the website a secret it can store.
Source: https://support.apple.com/en-us/102195
Why are passkeys more resistant to phishing?
A phishing page may copy a real website’s appearance. Passkey authentication checks the service identity, rather than relying only on whether the page looks convincing. A credential scoped to the real service cannot simply be used by a lookalike domain.
That is different from a password you could accidentally type into the wrong page. It is also different from a padlock icon: a fraudulent website can use HTTPS too. An encrypted connection does not establish that the business behind a page is legitimate.
Passkeys strengthen authentication, not every possible route into an account. Device compromise, deceptive recovery requests, and weaker fallback sign-ins still deserve attention. Keep devices updated and treat unexpected account-recovery messages carefully.
Source: MDN, Passkeys
https://developer.mozilla.org/en-US/docs/Web/Security/Authentication/Passkeys
Will passkeys replace passwords completely?
They can replace passwords in supported sign-in flows. Whether an account still has a password, and whether you can remove it, depends on that service’s rules. There is no single switch that converts every account you own.
For example, Google states that adding a passkey does not remove existing authentication or recovery factors. For a work or school account, administrator settings can also affect how passkeys are used.
Check each account separately. A successful passkey sign-in is not proof that its password has been deleted or that every device you use supports the same experience.
Source: Google Account Help
https://support.google.com/accounts/answer/13548313?hl=en
Synced versus device-bound passkeys
Synced passkeys can become available on compatible devices through your passkey provider. Device-bound passkeys remain on the specific authenticator where they were created, such as a hardware security key. Neither category means that every device or application will automatically work with it.
For a personal account, ask where the credential lives and whether your other devices can access it. For a business account, also ask who controls the provider account and how access will be handled when someone changes roles or leaves. A convenient personal setup may not match an employer’s requirements.
FIDO’s enterprise guidance distinguishes these credential types and the deployment decisions around them.
Source: https://fidoalliance.org/white-paper-fido-deploying-passkeys-in-the-enterprise-introduction/
How to try a passkey on one account
Use this checklist as a cautious first-account trial rather than changing everything in one sitting:
1. Choose a service you already use and open its official app or a known website address. Find its current passkey instructions in account security settings.
2. Use a personal device you control, with its screen lock enabled. Avoid creating a personal passkey in a shared device’s credential store.
3. Notice which provider the save prompt identifies. Record the provider’s name in your own account inventory; do not record PINs or recovery secrets there.
4. Follow the service’s setup prompts. Keep your existing working access while checking the new method.
5. Test a fresh sign-in on the device you expect to use. If another device matters to you, test that specific combination too.
6. Review recovery instructions before removing an existing sign-in method. Check that the recovery contact details and any supported backup options are current.
Google’s setup guide supports the personal-device and screen-lock precautions and warns that someone able to unlock a device with a saved passkey may be able to access the account. Exact menus and requirements vary by service, browser, and operating system.
Source: https://support.google.com/accounts/answer/13548313?hl=en
What if you lose your phone or replace it?
Start with two separate questions: can you regain access to your passkey provider, and can you regain access to the individual website account? Those are related, but they are not always the same recovery process.
Before replacing a device, check your provider’s migration instructions and confirm that required credentials work on the replacement. Do not erase your only working device as an experiment. For a device-bound credential, plan an additional supported sign-in or recovery route in advance.
Prepare a short personal checklist: provider name, official recovery instructions, where securely stored recovery material can be found, and which alternate method you have actually tested. If a device is stolen, follow the device maker’s lost-device steps and the affected services’ guidance for revoking access.
Account recovery can remain a target even after passkeys improve sign-in security. The UK National Cyber Security Centre discusses why recovery and reset processes still need protection.
Source: https://www.ncsc.gov.uk/sites/default/files/pdfs/blog/passkeys-not-perfect-getting-better.pdf
Common questions
Is a passkey the same as my fingerprint?
No. The fingerprint can authorize use of the digital credential; it is not the credential itself. Your device may offer another unlock method, such as a PIN.
Should I delete all my passwords now?
No. Review the options for each account, test your passkey, and understand recovery first. Continue protecting any passwords that remain active.
Do passkeys make an account impossible to hack?
No. They provide phishing-resistant authentication. Other weaknesses, including recovery methods and compromised devices, can still matter.
Will a passkey work on my work account?
Check with the account administrator. Support and policy may differ from your personal account, even on the same device.
What should I do if a passkey does not appear?
Check that you are on the correct service and account, using the expected provider and a supported browser/device combination. Consult the service’s current instructions before deleting credentials or changing recovery settings.
A useful first step today
Pick one supported personal account. Create a passkey, note where it is saved, test it, and confirm the recovery path. That small trial gives you something concrete to evaluate before changing your other accounts.
Have questions about your everyday technology? Contact Digital Junkie at www.digitaljunkie.tech, info@digitaljunkie.tech, or 737-400-6482. Serving Austin and Surrounding Areas.