A password is a secret you share: you type it, the website checks it, and anyone who learns it can use it. A passkey works differently. There is no shared secret to steal, which is why the big platforms are pushing people towards them.
The FIDO Alliance, which writes the standards behind them, defines a passkey as a sign-in credential stored on your phone, computer or a hardware security key, which you use "with the same process that they use to unlock their device": your fingerprint, your face or your screen-lock PIN.
What actually happens when you sign in
When you create a passkey, your device generates a pair of keys. The website keeps the public key. The private key stays with you, on your device or in your password manager. As Apple's passkey security page puts it, "The server never learns what the private key is."
Signing in is a small challenge and answer:
- The website sends your device a random challenge.
- Your device asks you to unlock it with your fingerprint, face or PIN.
- The device signs the challenge with the private key and sends back the signature.
- The website checks the signature with the public key it stored.
Your fingerprint or face never goes to the website. It only unlocks the key on your own device. The mechanics are defined in the W3C's Web Authentication standard, which every major browser implements.
Why phishing doesn't work
Most stolen accounts start with a convincing fake login page. With a password, the fake page simply records what you type. A passkey is tied to the real website's domain when it is created, and your browser will only use it on that domain. A lookalike site at a different address can't ask for it, so there is nothing for you to be tricked into handing over.
That is the real advance. Passwords fail because people can be fooled; passkeys don't rely on you noticing that the address bar looks wrong.
Where your passkeys live
- Synced passkeys are stored in a password manager and copied to your other devices: iCloud Keychain on Apple devices, Google Password Manager on Android and Chrome, or a third-party manager that supports them. Apple says iCloud Keychain is end-to-end encrypted "with strong cryptographic keys not known to Apple".
- Device-bound passkeys live on one piece of hardware, such as a USB or NFC security key, and never leave it.
To sign in on a computer that doesn't have your passkey, you can usually scan a QR code with your phone and confirm on the phone. Google describes the steps in its passkey help page.
What if you lose your phone?
If your passkeys sync through an account, they come back when you sign in to that account on a new device, so protect that account well. If a device is lost or stolen, sign in from another one and remove the passkeys tied to the lost device. Google suggests also reviewing the devices with access to your account.
Two habits avoid most lockouts:
- Keep a second way in for important accounts: a second device with passkeys, a hardware key, or the account's recovery codes stored somewhere safe.
- Don't delete your password or recovery options the day you add a passkey. Many sites still fall back to them, and you'll want them while you get used to the new way.
Should you switch?
For your email, your Apple or Google account, and anything that holds money, yes, wherever passkeys are offered. They are easier to use than a password plus a code from a text message, and much harder to phish. For older sites that don't support them yet, a password manager with a unique password for each site is still the right answer. Our guide to passwords covers that.
For a deeper, vendor-neutral reference, passkeys.dev is maintained by people who work on the standards.
No comments yet