Passkeys explained: why your accounts are moving beyond passwords

Passkeys let you sign in with a fingerprint, face or PIN instead of a password, and they are far harder to phish.

By Luis Freitas

Illustration: Passkeys explained: why your accounts are moving beyond passwords

Illustration Illustration: CybersecurityNews.ca

Explainer

Key points

  • A passkey replaces the password with a key pair
  • Nothing to steal in a breach or type into a fake page
  • Start with email, banking and admin accounts

A passkey lets you sign in with your device's screen lock (fingerprint, face or PIN) instead of a password. Behind the scenes it uses a pair of cryptographic keys: the private key stays on your device or in your password manager, and the website only stores the public key.

Why it matters

  • There is no password to steal in a data breach or to type into a fake login page, so passkeys resist phishing.
  • Each passkey works only on the site it was created for.
  • Apple, Google and Microsoft platforms support them, and many popular services now offer them.

What to do

Turn on passkeys where your email, bank or work accounts offer them, and keep a recovery method set up. Businesses can start with administrator accounts, where a phishing-resistant sign-in matters most.

Editor's Picks

The best of The Rightup, delivered to you weekly.

On Display
Illustration: How to turn on multi-factor authentication in Microsoft 365

How to turn on multi-factor authentication in Microsoft 365

Illustration: How to report a phishing email or scam text in Canada

How to report a phishing email or scam text in Canada

AMD security advisory (AV26-1014)