Passkeys: A Safer Step Beyond Passwords

Passkeys: A Safer Step Beyond Passwords
Aug 20, 2026 23:13

You may have already been prompted to use a ‘passkey’ to sign in to various accounts. While traditional passwords have long been associated with several limitations and security risks, passkeys have emerged as a significant solution. However, support for passkeys has not yet been introduced on every website.

Although passkeys are considerably more advanced than the traditional system, it is important to understand some of their specific features and how they work. They do not rely on information that users have to remember; rather, they are linked to a specific device or software. Therefore, users need to be careful not to lose access to the device or software where their passkeys are stored. Unlike passwords, passkeys also cannot be easily shared with friends.

However, for those who are not yet using a ‘password manager’ to protect their accounts, switching from conventional passwords to passkeys is arguably the most convenient and secure option.

Once users become familiar with how passkeys work, they can significantly reduce the hassle of everyday logins. The most important consideration is how and where the passkeys are stored. The good news is that almost all popular operating systems and password managers now offer passkey storage. Here is a closer look at the technology.

Technical Difference Between Passwords and Passkeys

• Password: A specific text or secret code. Websites encrypt these passwords and store them on their servers in the form of a ‘hash’. During login, the encrypted representation of the entered password is compared with the information stored on the server before access is granted.

• Passkey: A passkey does not require users to remember any text or code. Instead, it works using two cryptographic keys: a ‘public key’ and a ‘private key’. The public key is stored on the website or platform’s server, while the private key is encrypted and securely stored on the user’s own phone or computer. During login, the key is activated after verification through the device’s Face ID, fingerprint or PIN.

Password Problems Solved by Passkeys

• Phishing protection: A passkey is digitally and permanently associated with a specific domain or website. As a result, even if users accidentally open a fake or fraudulent website, the passkey will not disclose any information there.

• No risk of weak or reused passwords: Users often create weak passwords because they are easier to remember or use the same password across multiple websites. Since passkeys use cryptographic codes, they are inherently strong and cannot be reused across different services.

• Protection against data breaches: Even if hackers manage to breach a website’s database, they can only obtain the publicly available ‘public key’, which cannot be used to log into an account. The crucial ‘private key’ remains securely stored on the user’s own device.

• Automatic two-factor security (2FA): With a passkey, possession of the physical device and biometric or PIN verification take place together. This reduces the need for separate two-factor authentication in many cases.

Challenges of Using Passkeys and What to Do

• Ecosystem limitations: Apple Passwords, Google Password Manager and Windows all have their own systems for storing passkeys. However, if you use devices from different brands, such as an Android phone and a MacBook, using a reliable third-party ‘password manager’ or a physical security key, such as a YubiKey, may be the most convenient option.

• Difficult to share: Unlike an ordinary password, a passkey cannot simply be shared with someone verbally or in writing. Sharing requires a shared vault provided by a compatible password manager.

• Current availability: Passkeys are still not available on every website. However, on websites that support passkeys, enabling the feature through their security settings is a safer option. For services that do not yet support passkeys, using a strong password through a password manager remains the preferred approach.

//DBTech/BMT/OR//