What Are Passkeys? How They Work and How to Set One Up

What are passkeys? A passkey is a password replacement that lets you sign in to an app or website using the same method you use to unlock your phone or computer: a fingerprint, a face scan, or a device PIN. Behind the scenes, passkeys use public-key cryptography instead of a shared secret, which makes them resistant to phishing and useless to hackers who breach a company’s servers.

Major platforms including Apple, Google and Microsoft now support passkeys, and more sites offer them every month. This explainer covers how passkeys work, how they differ from passwords and traditional two-factor codes, and how to set one up.

What are passkeys, in plain terms?

The FIDO Alliance, the industry group that maintains the standard, defines a passkey as a FIDO-based credential that lets users sign in “with the same process that they use to unlock their device.” Each passkey is tied to one account on one website or app.

The key ideas:

  • Nothing to memorize or type. You approve the sign-in with your device’s lock.
  • Nothing reusable to steal. The website never stores a secret that could be replayed elsewhere.
  • Your biometrics stay on your device. The site only learns that the check succeeded, not your fingerprint or face data.

How passkeys work

When you create a passkey, your device generates a matched pair of cryptographic keys for that account:

  1. The private key stays on your device (or in your encrypted password manager). As Apple puts it, the server never learns what the private key is.
  2. The public key is sent to the website and stored with your account.
  3. At sign-in, the site sends a one-time challenge. Your device asks you to unlock it, then uses the private key to sign the challenge. The site checks the signature with your public key.

Because a public key can only verify signatures, not create them, a breach of the website’s database does not give attackers anything they can use to sign in as you.

Why passkeys resist phishing

A passkey is cryptographically bound to the real website’s domain. If a fake site that looks like your bank asks you to sign in, your device will not offer the bank’s passkey there, so there is no code or password for you to be tricked into handing over. U.S. agencies treat this property as central: the Cybersecurity and Infrastructure Security Agency (CISA) calls phishing-resistant MFA “the gold standard for MFA” and identifies FIDO/WebAuthn, the technology behind passkeys, as the only widely available form of it, in its October 2022 Implementing Phishing-Resistant MFA fact sheet.

Passkeys vs. passwords vs. two-factor codes

PasswordPassword + SMS/app codePasskey
Something to rememberYesYesNo
Can be phished on a fake siteYesYes, codes can be relayedNo, bound to the real domain
Exposed if the website is breachedYes (hashed password)Password yesOnly a public key, not usable to sign in
Reused across sitesOftenOftenNever; one key pair per account
Sign-in stepTypeType, then enter codeUnlock device

Synced vs. device-bound passkeys

There are two main kinds, according to the FIDO Alliance:

  • Synced passkeys are copied across your devices through a cloud service such as iCloud Keychain or Google Password Manager. If you replace your phone, your passkeys come with you. Apple says iCloud Keychain is end-to-end encrypted.
  • Device-bound passkeys never leave a single device, typically a hardware security key. FIDO describes these as offering the highest assurance, which is why they are common in workplaces and high-risk accounts.

The U.S. National Institute of Standards and Technology addressed synced passkeys for government use in an April 2024 supplement to its digital identity guidelines, Incorporating Syncable Authenticators into NIST SP 800-63B.

Signing in on someone else’s computer

If you need to sign in on a device that doesn’t hold your passkey, many sites show a QR code. You scan it with your phone, unlock the phone, and the sign-in completes. FIDO says this cross-device flow uses Bluetooth to confirm the phone is physically nearby, which helps stop remote attackers from abusing it.

How to set up a passkey

The steps vary by site, but the pattern is the same: sign in the usual way, go to security settings, and choose “create a passkey.”

Google Account

Per Google’s help page:

  1. Go to myaccount.google.com/signinoptions/passkeys.
  2. Select Create a passkey.
  3. Unlock your device when prompted.

Google lists support for Windows 10+, macOS Ventura+, ChromeOS 109+, Android 9+, iOS 16+ and current versions of Chrome, Safari, Edge and Firefox, plus FIDO2 security keys.

Apple devices

On iPhone, iPad and Mac, passkeys are saved to iCloud Keychain automatically when a site or app offers one. Apple requires two-factor authentication on accounts using iCloud Keychain. See Apple’s passkey security overview.

Any other site

  • Look under Security, Sign-in options or Login settings.
  • Choose where to save the passkey: your phone, your computer’s password manager, or a security key.
  • Keep at least one backup sign-in method (a second passkey on another device or a recovery option).

Common questions about passkeys

If someone steals my phone, can they use my passkeys?

They would also need to unlock the device with your fingerprint, face or PIN. That is why Google advises creating passkeys only on devices you personally own and use, and why a strong device PIN matters.

What happens if I lose my device?

Synced passkeys are restored when you sign in to your Apple or Google account on a new device. Device-bound passkeys on a lost security key are gone, so register a backup key or keep another sign-in method.

Do passkeys replace my password everywhere?

Not yet. Many sites still keep a password as a fallback, and some don’t support passkeys at all. Using a password manager for the rest is still good practice.

Are passkeys the same as “Sign in with Google”?

No. “Sign in with Google” lets one company vouch for you to another site. A passkey is a credential for the site itself, stored on your own device.

Key takeaways

  • Passkeys replace passwords with a key pair; only the public half ever leaves your device.
  • They are phishing-resistant because they only work on the real website.
  • Synced passkeys favor convenience; device-bound passkeys on security keys favor maximum assurance.
  • Setting one up takes about a minute on most major accounts.

Related cybersecurity coverage on Vanderbilt Report

Sources

Publisher Disclaimer: Vanderbiltreport.com publishes news and information for general informational and educational purposes. Information is compiled from sources believed to be reliable, but Vanderbiltreport.com does not guarantee the accuracy, completeness, or timeliness of all information presented. Readers should independently verify information and conduct their own research before making financial, investment, business, or other decisions.

WordPress Ads