Passkeys explained: why your accounts are moving beyond passwords
Passkeys let you sign in with a fingerprint, face or PIN instead of a password, and they are far harder to phish.
By Luis Freitas
Illustration Illustration: CybersecurityNews.ca
Explainer
Key points
- A passkey replaces the password with a key pair
- Nothing to steal in a breach or type into a fake page
- Start with email, banking and admin accounts
A passkey lets you sign in with your device's screen lock (fingerprint, face or PIN) instead of a password. Behind the scenes it uses a pair of cryptographic keys: the private key stays on your device or in your password manager, and the website only stores the public key.
Why it matters
- There is no password to steal in a data breach or to type into a fake login page, so passkeys resist phishing.
- Each passkey works only on the site it was created for.
- Apple, Google and Microsoft platforms support them, and many popular services now offer them.
What to do
Turn on passkeys where your email, bank or work accounts offer them, and keep a recovery method set up. Businesses can start with administrator accounts, where a phishing-resistant sign-in matters most.