Passkeys Are Replacing Passwords, and Here's the Catch
You’ve probably seen the prompt by now. A site asks if you’d like to “create a passkey instead,” maybe with a fingerprint icon and a promise that you’ll never have to remember a password again. It’s not hype. Passkeys are a real, substantial upgrade over passwords for the specific problem passwords are worst at: phishing and credential theft. But “replacing passwords” doesn’t mean “removing risk.” It moves the risk somewhere else, and that somewhere else is worth understanding before you switch everything over.
What a passkey actually is
A password is a shared secret. You know it, and the server knows it too (ideally as a hash), which means it can be typed into a fake login page, intercepted, or stolen from a breached database and reused.
A passkey is not a shared secret. It’s a key pair, generated using standard public-key cryptography under a specification called WebAuthn, part of the FIDO2 standard. When you create a passkey, your device generates two mathematically linked keys: a private key that never leaves your device (or your device’s secure hardware), and a public key that gets sent to the website and stored there.
When you log in, the site sends a challenge, a random piece of data. Your device signs that challenge with the private key and sends back the signature. The site checks the signature against the public key it already has. If it matches, you’re in. At no point does anything resembling a password cross the network, and at no point does the site ever hold a secret worth stealing. A breached database full of public keys is useless to an attacker, because a public key can’t be used to sign anything.
Why this actually beats passwords against phishing
The part of this that matters most in practice is that a passkey is bound to the origin it was created for. Your device won’t offer up your bank’s passkey to a lookalike site with a similar domain, because the cryptographic handshake is tied to the real site’s identity, not to what the page visually looks like. This is the exact attack that passwords, and even a lot of two-factor codes, remain vulnerable to: a convincing fake login page that captures whatever you type and relays it to the real site in real time. Passkeys don’t have anything typeable to capture in the first place.
That’s a genuine, structural fix. Most account takeovers still start with someone entering a password (or an OTP) into a page they shouldn’t have trusted. Remove the thing that can be typed into a fake page, and you remove that entire category of attack for that account.
What changes for you day to day
Practically, “logging in with a passkey” means unlocking access to the private key that’s already stored on your device or in your device’s secure enclave, using your fingerprint, face, or device PIN. That unlock step is local. Your fingerprint data isn’t sent to the website; it’s just what authorizes your device to use the key it’s already holding. This is why people describe passkeys as “phishing resistant” rather than “unhackable”: the weak point moves from “can someone trick me into typing my secret somewhere” to “can someone unlock my device.”
The catch: recovery is the new weak point
Here’s the part that doesn’t make it into the marketing screenshots. With a password, if you forget it, you reset it through an email link or a support process. With a passkey, if you lose the device that held the private key and you have no synced copy anywhere, there is no key to sign in with. The private key never left the device by design, which is exactly what made it secure, and exactly what makes losing it a real problem.
Every service has had to build a fallback for this, and those fallbacks vary in quality. Some fall back to email verification. Some fall back to SMS. Some fall back to a support agent who verifies your identity some other way. In a lot of cases, that fallback path is weaker than the passkey it’s backing up. An attacker who can’t phish your passkey may still be able to talk their way through, or SIM-swap through, an account recovery flow that was built as an afterthought. Replacing a strong primary login with a weak recovery path doesn’t raise your overall security, it just moves the target.
The catch: syncing and platform lock-in
Because losing a single device shouldn’t mean losing an account forever, most consumer passkeys are “synced” rather than strictly device-bound. Apple syncs them through iCloud Keychain, Google through Google Password Manager, and some password managers like Bitwarden or 1Password sync them across platforms directly. This solves the “I dropped my phone” problem, but it introduces a new one: your passkeys are now only as available as your access to that syncing account.
If your Apple ID or Google account gets locked, suspended, or you get logged out and can’t pass its own recovery checks, every passkey synced through it becomes unreachable at the same time, on every device, all at once. That’s a different failure mode than a stolen password, but it’s not a smaller one. It also means the provider you sync through becomes a meaningful part of your security posture, not just a convenience layer. Moving from Android to iPhone, or switching your primary password manager, can be more disruptive than it sounds if you haven’t checked how your passkeys carry across.
The catch: not every passkey implementation is the same
“Passkey support” on a given site can mean a few different things in practice. Some sites use it as a true password replacement. Others quietly treat it as an additional factor layered on top of a password that still technically exists in the background, meaning the old password-based attack surface hasn’t actually gone away, it’s just not what you use day to day. And because passkey rollouts are still uneven, plenty of sites let you set one up but still offer a “sign in with password instead” option that an attacker could target if they can get you, or a support rep, to use it. A passkey only protects you as strongly as the weakest login path that’s still turned on for that account.
What this does and doesn’t fix
It’s worth being specific about the boundaries of the threat model. Passkeys are a strong answer to phishing and to the giant pile of reused, breached passwords sitting in credential-stuffing lists. They don’t do anything about malware already running on your device that can act as you once you’ve unlocked it. They don’t help if someone has physical access to an unlocked phone or laptop. They don’t cover the huge number of smaller sites that haven’t implemented WebAuthn at all, which is most of the internet right now, so a password manager still earns its place for a while yet. And they’re not a privacy tool in the sense of hiding who you are from the services you log into; they authenticate you more securely, they don’t make you anonymous to the site itself.
Adopting passkeys sensibly
None of this is a reason to skip passkeys where they’re offered. The phishing resistance alone is worth it for anything tied to your finances, your primary email, or an account that gates other accounts. The sensible approach is to treat the switch as an upgrade to your login method, not a replacement for thinking about backups: know which syncing service holds your passkeys, keep at least one backup device or a compatible password manager in the loop, and actually read what a site’s account recovery flow looks like before you’re locked out and reading it under pressure. The technology genuinely closes a major hole. It just opens a smaller, different one, and that one is on you to manage.
If you want more breakdowns like this, of how the privacy and security tools you’re already using actually work under the hood, come find us at The Privacy Wire.