Skip to content
VaultPass

Authentication

Passkeys: what they are, how they work and whether to switch now

The VaultPass desk5 min read
Close-up detail of a fingerprint

More and more services let you sign in without typing anything, just with a fingerprint. It is not a convenience trick or a password stored under another name: underneath it is a different mechanism, and it is the first thing in twenty years to make phishing technically useless.

A password has a birth defect: it is a secret that two parties have to know. You and the service. If the service stores it badly, or if someone persuades you to tell them while pretending to be the service, it is over.

Passkeys remove that shared secret. And in removing it, they take out the two most profitable attacks against accounts: password leaks and phishing.

How they work, without the maths

When you create a passkey, your device generates two related keys:

  • A private key, which stays inside your phone or computer, in a protected area of the hardware. It never leaves.
  • A public key, which is sent to the service and stored on your account.

The public key is not a secret. It verifies signatures; it cannot make them. If the service’s database leaks tomorrow, what escapes is a list of public keys, which is worth precisely nothing.

At sign-in, the service sends a challenge: a random number. Your device signs it with the private key and returns the signature. The service verifies it with the public key it already had. If it matches, you are in.

Your fingerprint or face never travels anywhere. It only unlocks the use of the private key inside your own device.

The two problems it genuinely solves

Phishing stops working

This is the important part, and the one no other measure achieves.

When you register a passkey, it is bound to the service’s domain. Before signing, your device first checks which site you are on. If the address does not match the one from registration exactly, it does not sign. Full stop.

It does not matter how perfect the imitation is, that the padlock is there, or that you are convinced you are in the right place. The passkey is not fooled because it does not depend on your judgement. Against a six-digit code, which can be requested and relayed in real time, the difference is qualitative.

Breaches stop affecting you

There is no password to steal. An attacker who takes the entire database gets useless public keys. Credential stuffing, which lives on reusing leaked passwords, is left with nothing to reuse.

Where your passkeys live

This is the part that generates most doubt, and rightly so.

Synced with your platform account. Apple stores them in the iCloud keychain, Google in its manager. They sync encrypted between your devices. It is the most convenient option and what most people use: change phone and they appear on their own.

In a password manager. Serious managers already store passkeys. It is the most flexible option if you mix systems: iPhone with Windows, Android with Mac.

On the device only. They never leave it. This is the most secure and the most fragile: lose the device and you lose the passkey.

On a physical key. A USB or NFC security key can store passkeys. This is the maximum-resistance model.

The honest trade-off with syncing is that it moves the trust to your Apple, Google or manager account. If someone gets in there, they get in everywhere. Which is why that particular account needs the best protection you can give it.

What happens if you lose your phone

It is the right question and it has three answers depending on the case:

  1. If they are synced, you sign in on the new device with your platform account or manager and they are available again. You lose nothing.
  2. If they are local, you depend on each service’s fallback: another passkey on another device, a backup password, or recovery codes.
  3. In every case, the practical recommendation is to register at least two devices on the services you care about, or keep recovery codes on paper.

The rule is the same as always: a single point of failure is a bad design.

What is still unresolved

It is worth being honest about the current state:

Not every service offers them. Adoption is moving fast on the big platforms and slowly everywhere else. You will be living with passwords for years.

Almost no service has removed the password. Most add the passkey but keep the password as a fallback. While that remains true, your account is only as attackable as its weakest method: if the old password is bad and still active, the passkey does not save you.

Moving passkeys between ecosystems has improved, but it is still the most awkward point if you want to leave Apple or Google.

Recovery depends on each service, and some have designed it badly, leaving SMS back doors that reintroduce exactly the problem passkeys came to remove.

What to do today, in practice

  1. Turn them on wherever they are offered, starting with Google, Apple, Microsoft and your password manager.
  2. Register two devices on the important accounts.
  3. Do not delete the fallback password, but improve it. If it still exists, it has to be long and unique. A manager does that for you.
  4. Keep two-factor authentication where passkeys are not available yet.

In short

  • A passkey is a pair of cryptographic keys; the private one never leaves your device.
  • There is no shared secret, so a breach at the service does not expose you.
  • It checks the domain before signing: phishing stops working.
  • Syncing is convenient and moves the trust to your platform account.
  • Register two devices and do not leave a weak fallback password behind.

Frequently asked

The questions that keep coming up

What is a passkey?

It is a cryptographic credential stored on your device that replaces the password. When you sign in, the service poses a challenge only your device can answer, and you authorise it with your fingerprint, face or PIN.

Is it more secure than a password?

Yes, for two reasons. There is no shared secret the service could leak, and the passkey verifies the site's address before responding, so it does not work on a phishing page.

What happens if I lose my phone?

If your passkeys sync with your Apple, Google or password manager account, you get them back by signing in on the new device. If they are device-only, you need each service's fallback method — which is why registering more than one device matters.

Can I use passkeys between an iPhone and a Windows PC?

Yes. You can scan a QR code with your phone to authorise access on someone else's computer, or store your passkeys in a cross-platform password manager.

Keep reading