A strong password is a good answer to the wrong question. Passkeys change the question — from "what secret do you know?" to "what device can prove it's you?" — and phishing largely stops working.

Every password article — including good ones about length and entropy — is answering the question "how do I pick a secret that's hard to guess?" Passkeys make that question obsolete by getting rid of the shared secret entirely. Instead of you and the server both knowing a password that can be guessed, stolen from a breach, or phished out of you, a passkey proves your identity with cryptography that never sends anything secret across the wire. It's the biggest change to how we log in in decades, and it's worth understanding what actually moves.

The standard underneath

"Passkey" is the friendly name for credentials built on a web standard called WebAuthn:

"Web Authentication (WebAuthn) is a web standard published by the World Wide Web Consortium (W3C). It defines an API that websites use to authenticate with WebAuthn credentials (passkeys)..."

— Wikipedia, "WebAuthn" (CC BY-SA 4.0)

A W3C standard, supported across the major browsers and operating systems — not a single vendor's product. That matters, because it means passkeys work the same way everywhere rather than locking you to one company.

What a passkey actually is

A passkey is a public/private key pair. When you create one for a site, your device generates two mathematically linked keys: a private key that never leaves your device (guarded by your fingerprint, face, or device PIN) and a public key that the site stores. The public key is exactly what its name says — public. It's useless to a thief, because you can't derive the private key from it. There is no shared secret sitting in the site's database waiting to be breached. That single structural change is where most of the benefit comes from.

Why phishing stops working

Passwords are phishable because you can be tricked into typing your secret into a fake page — the secret is portable, so it can be stolen and replayed. A passkey can't be handed over this way. Signing in works by challenge-response: the site sends a random challenge, your device signs it with the private key, and the site verifies the signature with the stored public key. Nothing reusable crosses the network — just a one-time signature. And crucially, the passkey is bound to the real site's domain, so a lookalike phishing domain simply can't invoke it; the browser won't offer the passkey to the wrong origin. Even if a user wants to be fooled, there's no secret to surrender and no way to use the passkey on the fake site. That closes the single most common account-takeover route.

The honest trade-offs

Passkeys aren't free of friction, and pretending otherwise helps no one. The obvious worry is device loss: if the private key lives on your phone and the phone goes in a river, are you locked out? In practice, passkeys from the major platform providers sync securely across your devices through your account, so a new device restores them — but that reintroduces a dependency on that platform account's security, which becomes the thing you must protect above all. There's also the cross-ecosystem question: signing in on someone else's computer with a passkey stored on your phone typically uses a QR-code hand-off between the two devices, which works well but is a newer flow people are still learning. These are real considerations, not dealbreakers — the security gain is large — but they're the questions to answer before going all-in.

Where passwords still hang on

Passwords won't vanish overnight. Legacy systems that will never implement WebAuthn, account-recovery flows, and the long tail of services that haven't adopted passkeys all keep passwords alive for years yet. So the realistic posture for now is hybrid: use passkeys wherever a service offers them, and keep strong, unique passwords (in a manager) for everything that doesn't. The password isn't dead — it's being demoted from "the front door" to "the fallback."

Understand the pieces

You can build intuition for the moving parts with a few tools. While you're still maintaining passwords for the services that lack passkeys, a password generator keeps those strong and unique — the fallback still has to be solid. A hash generator helps you see the one-way-function idea that underpins how servers store credentials and verify signatures. And the cross-device passkey hand-off runs on QR codes, the same physical-to-digital bridge you can explore with a QR code generator. Passwords ask you to keep a secret. Passkeys prove who you are without one — and that's the shift worth understanding now, because it's already arriving.

← All articles